IP Library Granted Patent US 11,349,868
Granted Patent B2
US 11,349,868 · App. 15/874,283 · Granted May 31, 2022

Detection of spoofed internally-addressed email using trusted third party's SPF records

Inventors: Tony G. Naccarato (Surrey, GB); James R. Gordon (Berkshire, GB)
Assignee: Forcepoint, LLC
H04L63/1483H04L51/12H04L63/1425H04L63/1466H04L51/28
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,349,868
App. No.
15/874,283
Granted
May 31, 2022
Kind
B2
Abstract

A method, system and computer-usable medium for performing a spoofed email detection operation, comprising: maintaining a list of allowed third party domains that are authorized to send an internally-addressed email, the list of allowed third party domains comprising a plurality of domains; receiving an email from a third party sender, the email comprising an email envelope, the email envelope storing a domain of a third party sender address of the third party sender; comparing the domain of the third party sender address stored in the email envelope with the list of allowed third party domains; identifying the domain of the third party sender address stored in the email envelope as an allowed domain when the domain of the third party sender address matches a third party domain stored within the list of allowed third party domains.

Claims (53)

1. A computer-implementable method for performing a spoofed email detection operation, comprising:

maintaining a list of allowed third party domains that are authorized to send an internally-addressed email, the list of allowed third party domains comprising a plurality of domains;

receiving an email from a third party sender, the email comprising an email envelope and email message content, the email envelope storing a domain of a third party sender address of the third party sender, the email message content comprising an email header, the email header comprising a sender address, the third party sender address being different from the sender address;

comparing the domain of the third party sender address stored in the email envelope with the list of allowed third party domains;

identifying the domain of the third party sender address stored in the email envelope as an allowed domain when the domain of the third party sender address matches a third party domain stored within the list of allowed third party domains; and,

querying a Sender Policy Framework (SPF) of the domain of the third party sender address to verify whether an email server is authorized, the querying the SPF of the domain performing an SPF record look-up operation, the SPF record look-up operation confirming the email server is authorized to send email messages, the SPF record look-up operation allowing an organization to authorize a third-party service provider to send email messages to certain email message recipients on behalf of the organization.

2. The method of claim 1 , further comprising:

determining whether the email server used to send the third party email is authorized to send on behalf of the domain corresponding to the third party sender address stored in the email envelope.

3. The method of claim 2 , wherein:

confirmation that the email service is authorized to send email messages is provided via an SPF record look-up result from a third party Domain Name System (DNS) server to a recipient email server.

4. The method of claim 2 , further comprising:

identifying the email message as unauthorized when the email server used to send the third party email is not authorized to send on behalf of the domain corresponding to the third party sender address stored in the email envelope.

5. The method of claim 1 , wherein:

the email message content comprises a message body.

6. The method of claim 1 , further comprising:

extending the list of allowed domains to include specific senders and respective domains of the specific senders.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

maintaining a list of allowed third party domains that are authorized to send an internally-addressed email, the list of allowed third party domains comprising a plurality of domains;

receiving an email from a third party sender, the email comprising an email envelope and email message content, the email envelope storing a domain of a third party sender address of the third party sender, the email message content comprising an email header, the email header comprising a sender address, the third party sender address being different from the sender address;

comparing the domain of the third party sender address stored in the email envelope with the list of allowed third party domains;

identifying the domain of the third party sender address stored in the email envelope as an allowed domain when the domain of the third party sender address matches a third party domain stored within the list of allowed third party domains; and,

querying a Sender Policy Framework (SPF) of the domain of the third party sender address to verify whether an email server is authorized, the querying the SPF of the domain performing an SPF record look-up operation, the SPF record look-up operation confirming the email server is authorized to send email messages, the SPF record look-up operation allowing an organization to authorize a third-party service provider to send email messages to certain email message recipients on behalf of the organization.

8. The system of claim 7 , wherein the instructions executable by the processor are further configured for:

determining whether the email server used to send the third party email is authorized to send on behalf of the domain corresponding to the third party sender address stored in the email envelope.

9. The system of claim 8 , wherein:

confirmation that the email service is authorized to send email messages is provided via an SPF record look-up result from a third party Domain Name System (DNS) server to a recipient email server.

10. The system of claim 8 , wherein the instructions executable by the processor are further configured for:

identifying the email message as unauthorized when the email server used to send the third party email is not authorized to send on behalf of the domain corresponding to the third party sender address stored in the email envelope.

11. The system of claim 7 , wherein:

the email message content comprises a message body.

12. The system of claim 7 , wherein the instructions executable by the processor are further configured for:

extending the list of allowed domains to include specific senders and respective domains of the specific senders.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

maintaining a list of allowed third party domains that are authorized to send an internally-addressed email, the list of allowed third party domains comprising a plurality of domains;

receiving an email from a third party sender, the email comprising an email envelope and email message content, the email envelope storing a domain of a third party sender address of the third party sender, the email message content comprising an email header, the email header comprising a sender address, the third party sender address being different from the sender address;

comparing the domain of the third party sender address stored in the email envelope with the list of allowed third party domains;

identifying the domain of the third party sender address stored in the email envelope as an allowed domain when the domain of the third party sender address matches a third party domain stored within the list of allowed third party domains; and,

querying a Sender Policy Framework (SPF) of the domain of the third party sender address to verify whether an email server is authorized, the querying the SPF of the domain performing an SPF record look-up operation, the SPF record look-up operation confirming the email server is authorized to send email messages, the SPF record look-up operation allowing an organization to authorize a third-party service provider to send email messages to certain email message recipients on behalf of the organization.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

determining whether the email server used to send the third party email is authorized to send on behalf of the domain corresponding to the third party sender address stored in the email envelope.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

confirmation that the email service is authorized to send email messages is provided via an SPF record look-up result from a third party Domain Name System (DNS) server to a recipient email server.

16. The non-transitory, computer-readable storage medium of claim 14 , wherein the computer executable instructions are further configured for:

identifying the email message as unauthorized when the email server used to send the third party email is not authorized to send on behalf of the domain corresponding to the third party sender address stored in the email envelope.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the email message content comprises a message body.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

extending the list of allowed domains to include specific senders and respective domains of the specific senders.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055492/0266 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Jul 6, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 046495/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2018
From: NACCARATO, TONY G.; GORDON, JAMES R.
To: FORCEPOINT, LLC
Reel/Frame 044656/0855 →