IP Library Granted Patent US 11,924,224
Granted Patent B2
US 11,924,224 · App. 17/306,524 · Granted Mar 5, 2024

Processing external messages using a secure email relay

Inventor: Ashley Harlow Valeski (Denver, CO)
Assignee: Proofpoint, Inc.
H04L63/126H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,224
App. No.
17/306,524
Granted
Mar 5, 2024
Kind
B2
Abstract

Aspects of the disclosure relate to processing external messages using a secure email relay. A computing platform may receive, from a message source server associated with a first domain, a first email message and a first set of authentication credentials. Based on validating the first set of authentication credentials, the computing platform may inject, into the first email message, a DomainKeys Identified Mail (DKIM) signature of a second domain different from the first domain, which may produce a signed message that identifies itself as originating from the second domain. Based on scanning and validating content of the signed message, the computing platform may send the signed message to a message recipient server, which may cause the message recipient server to validate the DKIM signature of the signed message and determine that the signed message passes Domain-based Message Authentication, Reporting and Conformance (DMARC) with respect to the second domain.

Claims (45)

1. A computing platform, comprising:

at least one processor;

a communication interface; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive, via the communication interface, from a message source server associated with a first domain, a first email message and a first set of authentication credentials;

validate the first set of authentication credentials;

based on validating the first set of authentication credentials, inject, into the first email message, a DomainKeys Identified Mail (DKIM) signature of a second domain different from the first domain, wherein injecting the DKIM signature of the second domain into the first email message produces a first signed message that identifies itself as originating from the second domain, wherein the first signed message is produced without modifying a Header From (RFC.5322) domain and an Envelop From (RFC.5321) domain;

scan content of the first signed message, wherein scanning the content of the first signed message produces first scan results;

validate the first scan results; and

based on validating the first scan results, send, via the communication interface, to a message recipient server, the first signed message, wherein sending the first signed message to the message recipient server causes the message recipient server to validate the DKIM signature of the first signed message and determine, based on validating the DKIM signature of the first signed message, that the first signed message passes Domain-based Message Authentication, Reporting and Conformance (DMARC) with respect to the second domain.

2. The computing platform of claim 1 , wherein the first domain is a domain name corresponding to a first entity, and the first email message comprises information identifying the first email message's Envelope From domain (RFC.5321) as the domain name corresponding to the first entity, and

wherein the second domain is a domain name corresponding to a second entity different from the first entity, and the first email message comprises information identifying the first email message's Header From domain (RFC.5322) as the domain name corresponding to the second entity.

3. The computing platform of claim 2 , wherein the second entity is an organization, and the first entity is a third-party service provider to the organization.

4. The computing platform of claim 1 , wherein validating the first set of authentication credentials comprises comparing the first set of authentication credentials received from the message source server associated with the first domain with pre-established credentials provided to one or more authorized users of a secure email relay service hosted on the computing platform.

5. The computing platform of claim 1 , wherein scanning the content of the first signed message comprises executing an antispam-antivirus scan on the content of the first signed message.

6. The computing platform of claim 1 , wherein sending the first signed message to the message recipient server causes the message recipient server to validate the DKIM signature of the first signed message by comparing the DKIM signature of the first signed message with a public key linked to the second domain and maintained on a domain name system (DNS) server.

7. The computing platform of claim 1 , wherein sending the first signed message to the message recipient server causes the message recipient server to provide a recipient user with access to the first signed message based on the first signed message passing DMARC with respect to the second domain.

8. The computing platform of claim 7 , wherein sending the first signed message to the message recipient server causes the message recipient server to provide the recipient user with access to the first signed message by adding the first signed message to a mail folder accessible to the recipient user without quarantining the message.

9. The computing platform of claim 7 , wherein sending the first signed message to the message recipient server causes the message recipient server to provide the recipient user with access to the first signed message by sending the first signed message to a recipient user device.

10. A method, comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

receiving, by the at least one processor, via the communication interface, from a message source server associated with a first domain, a first email message and a first set of authentication credentials;

validating, by the at least one processor, the first set of authentication credentials;

based on validating the first set of authentication credentials, injecting, by the at least one processor, into the first email message, a DomainKeys Identified Mail (DKIM) signature of a second domain different from the first domain, wherein injecting the DKIM signature of the second domain into the first email message produces a first signed message that identifies itself as originating from the second domain, wherein the first signed message is produced without modifying a Header From (RFC.5322) domain and an Envelop From (RFC.5321) domain;

scanning, by the at least one processor, content of the first signed message, wherein scanning the content of the first signed message produces first scan results;

validating, by the at least one processor, the first scan results; and

based on validating the first scan results, sending, by the at least one processor, via the communication interface, to a message recipient server, the first signed message, wherein sending the first signed message to the message recipient server causes the message recipient server to validate the DKIM signature of the first signed message and determine, based on validating the DKIM signature of the first signed message, that the first signed message passes Domain-based Message Authentication, Reporting and Conformance (DMARC) with respect to the second domain.

11. The method of claim 10 , wherein the first domain is a domain name corresponding to a first entity, and the first email message comprises information identifying the first email message's Envelope From domain (RFC.5321) as the domain name corresponding to the first entity, and

wherein the second domain is a domain name corresponding to a second entity different from the first entity, and the first email message comprises information identifying the first email message's Header From domain (RFC.5322) as the domain name corresponding to the second entity.

12. The method of claim 11 , wherein the second entity is an organization, and the first entity is a third-party service provider to the organization.

13. The method of claim 10 , wherein validating the first set of authentication credentials comprises comparing the first set of authentication credentials received from the message source server associated with the first domain with pre-established credentials provided to one or more authorized users of a secure email relay service hosted on the computing platform.

14. The method of claim 10 , wherein scanning the content of the first signed message comprises executing an antispam-antivirus scan on the content of the first signed message.

15. The method of claim 10 , wherein sending the first signed message to the message recipient server causes the message recipient server to validate the DKIM signature of the first signed message by comparing the DKIM signature of the first signed message with a public key linked to the second domain and maintained on a domain name system (DNS) server.

16. The method of claim 10 , wherein sending the first signed message to the message recipient server causes the message recipient server to provide a recipient user with access to the first signed message based on the first signed message passing DMARC with respect to the second domain.

17. The method of claim 16 , wherein sending the first signed message to the message recipient server causes the message recipient server to provide the recipient user with access to the first signed message by adding the first signed message to a mail folder accessible to the recipient user without quarantining the message.

18. The method of claim 16 , wherein sending the first signed message to the message recipient server causes the message recipient server to provide the recipient user with access to the first signed message by sending the first signed message to a recipient user device.

19. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

receive, via the communication interface, from a message source server associated with a first domain, a first email message and a first set of authentication credentials;

validate the first set of authentication credentials;

based on validating the first set of authentication credentials, inject, into the first email message, a DomainKeys Identified Mail (DKIM) signature of a second domain different from the first domain, wherein injecting the DKIM signature of the second domain into the first email message produces a first signed message that identifies itself as originating from the second domain, wherein the first signed message is produced without modifying a Header From (RFC.5322) domain and an Envelop From (RFC.5321) domain;

scan content of the first signed message, wherein scanning the content of the first signed message produces first scan results;

validate the first scan results; and

based on validating the first scan results, send, via the communication interface, to a message recipient server, the first signed message, wherein sending the first signed message to the message recipient server causes the message recipient server to validate the DKIM signature of the first signed message and determine, based on validating the DKIM signature of the first signed message, that the first signed message passes Domain-based Message Authentication, Reporting and Conformance (DMARC) with respect to the second domain.

20. The one or more non-transitory computer-readable media of claim 19 , wherein the first domain is a domain name corresponding to a first entity, and the first email message comprises information identifying the first email message's Envelope From domain (RFC.5321) as the domain name corresponding to the first entity, and

wherein the second domain is a domain name corresponding to a second entity different from the first entity, and the first email message comprises information identifying the first email message's Header From domain (RFC.5322) as the domain name corresponding to the second entity.

Assignments (5)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2021
From: VALESKI, ASHLEY HARLOW
To: PROOFPOINT, INC.
Reel/Frame 057154/0837 →