IP Library Granted Patent US 11,582,263
Granted Patent B2
US 11,582,263 · App. 17/360,322 · Granted Feb 14, 2023

Centralized validation of email senders via EHLO name and IP address targeting

Inventor: Peter Martin Goldstein (San Francisco, CA)
Assignee: ValiMail Inc.
H04L63/20G06F21/56G06F21/6218H04L51/04H04L61/4511H04L63/0236H04L63/08H04L63/126H04L63/14H04L63/145H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,582,263
App. No.
17/360,322
Granted
Feb 14, 2023
Kind
B2
Abstract

A DNS server receives from a receiving email system, a DNS query for an email domain stored at the DNS server, the DNS query including identifying information of a sender of an email. The DNS server extracts the identifying information of the email sender from the DNS query and identifies one of a plurality of delivering organizations from the information. The DNS server determines whether the identified delivering organization is authorized to deliver email on behalf of the email domain. In response to determining that the identified delivering organization is authorized to deliver email on behalf of the email domain, the DNS server generates a target validation record based on the identity of the authorized delivering organization and the email domain, the target validation record including one or more rules indicating to the receiving email system whether the delivering organization is an authorized sender of email for the email domain.

Claims (37)

1. A computer-implemented method, comprising:

receiving, at an authorizing domain name system (DNS) server, an indication from a domain owner system that the domain owner system has authorized a first email system to send or receive emails on behalf of the domain owner system, wherein the domain owner system is associated with a first domain operated by a domain owner DNS server, the domain owner DNS server being a different server than the authorizing DNS server, and wherein the authorizing DNS server, the domain owner system, and the first email system are different entities;

generating a DNS record, the DNS record being a plaintext record that sets forth one or more policies associated with the first email system, the plaintext record describing how emails of the domain owner system are handled through the first email system, the DNS record being specific to a combination of the domain owner system and the first email system;

publishing the DNS record, on behalf of the domain owner system, at a subdomain of the first domain associated with the domain owner system, wherein the first domain is operated by the domain owner DNS server and wherein the domain owner system delegates the subdomain to the authorizing DNS server to operate the subdomain;

receiving a DNS query from a second email system that handles an email received from or transmitting to the first email system, the email including an identifier associated with the first domain associated with the domain owner system, wherein the DNS query is redirected from the first domain operated by the domain owner DNS server to the subdomain; and

returning, on behalf of the domain owner system, the plaintext record in the DNS record published under the subdomain to the second email system, the one or more policies set forth in the plaintext record providing information to the second email system on how the email is handled.

2. The computer-implemented method of claim 1 , wherein the plaintext record is a DNS TXT record.

3. The computer-implemented method of claim 1 , wherein the one or more policies set forth in the plaintext record specify how emails should be sent to the first email system.

4. The computer-implemented method of claim 1 , wherein the one or more policies set forth in the plaintext record include authentication information on how emails transmitted from the first email system are authenticated.

5. The computer-implemented method of claim 1 , wherein the one or more policies are generated by an administrator of the domain owner system through a user interface provided by the authorizing DNS server.

6. The computer-implemented method of claim 5 , wherein the user interface is part of a software as a service (SaaS) platform provided by the authorizing DNS server.

7. The computer-implemented method of claim 1 , wherein the first domain comprises a plurality of DNS records associated with the domain owner system and wherein the domain owner system authorizes a plurality of email systems to send or receive emails on behalf of the domain owner system, wherein each of the plurality of DNS records is associated with the domain owner system and one of the email systems, and the DNS record that sets forth one or more policies associated with the first email system is specific to the combination of the domain owner system and the first email system.

8. A computer-implemented method, comprising:

receiving, at an authorizing domain name system (DNS) server, an indication from a domain owner system that the domain owner system has authorized a first email system to send or receive emails on behalf of the domain owner system, wherein the domain owner system is associated with a first domain operated by a domain owner DNS server, the domain owner DNS server being a different server than the authorizing DNS server, and wherein the authorizing DNS server, the domain owner system, and the first email system are different entities;

generating a DNS record, the DNS record being a plaintext record that sets forth one or more policies associated with the first domain, the plaintext record describing how emails of the domain owner system are handled;

publishing the DNS record, on behalf of the domain owner system, at a subdomain of the first domain associated with the domain owner system, wherein the first domain is operated by the domain owner DNS server and wherein the domain owner system delegates the subdomain to the authorizing DNS server to operate the subdomain;

receiving a DNS query from a second email system that handles an email received from or transmitting to the first email system, the email including an identifier associated with the first domain associated with the domain owner system; and

returning, on behalf of the domain owner system, the plaintext record in the DNS record published under the subdomain to the second email system, the one or more policies set forth in the plaintext record providing information to the second email system to generate a file based on the one or more policies set forth in the plaintext record.

9. The computer-implemented method of claim 8 , wherein the plaintext record is a DNS TXT record.

10. The computer-implemented method of claim 8 , wherein the one or more policies set forth in the plaintext record specify how emails should be sent to the first email system.

11. The computer-implemented method of claim 8 , wherein the one or more policies set forth in the plaintext record include authentication information on how emails transmitted from the first email system are authenticated.

12. The computer-implemented method of claim 8 , wherein the one or more policies are generated by an administrator of the domain owner system through a user interface provided by the authorizing DNS server.

13. The computer-implemented method of claim 12 , wherein the user interface is part of a software as a service (SaaS) platform provided by the authorizing DNS server.

14. The computer-implemented method of claim 8 , wherein the file is a report recording email activities associated with the first email system.

15. A system for operating an authorizing DNS server, the system comprising:

one or more processors; and

memory configured to store computer code comprising instructions, the instructions, when executed by the one or more processors, cause the one or more processors to:

receive an indication from a domain owner system that the domain owner system has authorized a first email system to send or receive emails on behalf of the domain owner system, wherein the domain owner system is associated with a first domain operated by a domain owner DNS server, the domain owner DNS server being a different server than the authorizing DNS server, and wherein the authorizing DNS server, the domain owner system, and the first email system are different entities;

generate a DNS record, the DNS record being a plaintext record that sets forth one or more policies associated with the first email system, the plaintext record describing how emails of the domain owner system are handled through the first email system, the DNS record being specific to a combination of the domain owner system and the first email system;

publish the DNS record, on behalf of the domain owner system, at a subdomain of the first domain associated with the domain owner system, wherein the first domain is operated by the domain owner DNS server and wherein the domain owner system delegates the subdomain to the authorizing DNS server to operate the subdomain;

receive a DNS query from a second email system that handles an email received from or transmitting to the first email system, the email including an identifier associated with the first domain associated with the domain owner system, wherein the DNS query is redirected from the first domain operated by the domain owner DNS server to the subdomain; and

return, on behalf of the domain owner system, the plaintext record in the DNS record published under the subdomain to the second email system, the one or more policies set forth in the plaintext record providing information to the second email system on how the email is handled.

16. The system of claim 15 , wherein the plaintext record is a DNS TXT record.

17. The system of claim 15 , wherein the one or more policies set forth in the plaintext record specify how emails should be sent to the first email system.

18. The system of claim 15 , wherein the one or more policies set forth in the plaintext record include authentication information on how emails transmitted from the first email system are authenticated.

19. The system of claim 15 , wherein the one or more policies are generated by an administrator of the domain owner system through a user interface provided by the authorizing DNS server.

20. The system of claim 19 , wherein the user interface is part of a software as a service (SaaS) platform provided by the authorizing DNS server.

Assignments (3)
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 9, 2026
From: VALIMAIL INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 074281/0239 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2025
From: VALIMAIL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 073910/0374 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2021
From: GOLDSTEIN, PETER MARTIN
To: VALIMAIL INC.
Reel/Frame 056700/0370 →
Continuity (7)
Continuation 17128008 · Dec 19, 2020
Continuation 16296121 · Mar 7, 2019
Continuation 15663771 · Jul 30, 2017
Continuation 15175031 · Jun 6, 2016
Continuation PCTUS2016015796 · Jan 29, 2016
Provisional Application 62116409 · Feb 14, 2015
Related Publication 20210329034A1 · Oct 21, 2021
Cited By (1)
US 12,513,115