IP Library Granted Patent US 11,431,756
Granted Patent B2
US 11,431,756 · App. 17/500,306 · Granted Aug 30, 2022

Authentication of email senders via authorizing DNS server

Inventor: Peter Martin Goldstein (San Francisco, CA)
Assignee: ValiMail Inc.
H04L63/20G06F21/56G06F21/6218H04L51/04H04L61/4511H04L63/0236H04L63/08H04L63/126H04L63/14H04L63/145H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,431,756
App. No.
17/500,306
Granted
Aug 30, 2022
Kind
B2
Abstract

A DNS server receives from a receiving email system, a DNS query for an email domain stored at the DNS server, the DNS query including identifying information of a sender of an email. The DNS server extracts the identifying information of the email sender from the DNS query and identifies one of a plurality of delivering organizations from the information. The DNS server determines whether the identified delivering organization is authorized to deliver email on behalf of the email domain. In response to determining that the identified delivering organization is authorized to deliver email on behalf of the email domain, the DNS server generates a target validation record based on the identity of the authorized delivering organization and the email domain, the target validation record including one or more rules indicating to the receiving email system whether the delivering organization is an authorized sender of email for the email domain.

Claims (51)

1. A system, comprising:

an interface configured to receive one or more inputs for indicating a delivering organization in an authorized deliverer list is authorized to deliver emails on behalf of a domain owner that owns an email domain; and

an authorizing domain name system (DNS) server comprising memory and one or more processors, the authorizing DNS server configured to provide one or more DNS responses on behalf of the domain owner, wherein the authorizing DNS server, the domain owner, and the delivering organization are different entities, wherein the authorizing DNS server is a different server than a server that operates the email domain, and wherein the memory comprises instructions that when executed by the one or more processors cause the one or more processors to:

store the authorized deliverer list associated with the domain owner;

generate a DNS record to include information used to authenticate emails sent from the delivering organization on behalf of the domain owner, the information being related to the delivering organization;

publish the DNS record, on behalf of the domain owner, at a subdomain associated with the domain of the domain owner, wherein the subdomain is a publicly accessible location and the domain owner delegates the subdomain to the authorizing DNS server to operate the subdomain;

receive a DNS query from a receiving email system attempting to authenticate an incoming email that includes an identifier, wherein the DNS query is generated based on the identifier; and

return, as a response to the DNS query and on behalf of the domain owner, the DNS record to the receiving email system, wherein information in the DNS record published under the subdomain determines whether the incoming email is authenticated.

2. The system of claim 1 , wherein the subdomain has an address that includes the domain as part of the address.

3. The system of claim 1 , wherein the authorizing DNS server is an authoritative server of the subdomain.

4. The system of claim 1 , wherein the DNS query is generated by the receiving email system first sending a DNS query to the domain of the domain owner, and the domain has an include directive that points to the subdomain.

5. The system of claim 1 , wherein the DNS record includes one or more policies associated with the domain owner.

6. The system of claim 1 , wherein the identifier is part of header of the incoming email.

7. The system of claim 1 , wherein the DNS query includes the identifier as part of the DNS query.

8. The system of claim 1 , wherein the identifier indicates that the domain is part of a sender address of the incoming email.

9. The system of claim 1 , wherein the interface is a graphical user interface.

10. The system of claim 1 , wherein the one or more inputs are provided by an administrator of the domain owner, the administrator providing at least one of the inputs to generate or verify the authorized deliverer list.

11. A system comprising:

one or more processors; and

memory configured to store code comprising instructions, wherein the instructions, when executed by the one or more processors, cause the one or more processors to:

receive one or more inputs for indicating a delivering organization in an authorized deliverer list is authorized to deliver emails on behalf of a domain owner that owns an email domain;

store the authorized deliverer list associated with the domain owner;

generate a DNS record to include information used to authenticate emails sent from the delivering organization on behalf of the domain owner, the information being related to the delivering organization;

publish, by an authorizing domain name system (DNS) server on behalf of the domain owner, the DNS record at a subdomain associated with the domain of the domain owner, wherein the authorizing DNS server, the domain owner, and the delivering organization are different entities, wherein the authorizing DNS server is a different server than a server that operates the email domain, wherein the subdomain is a publicly accessible location and the domain owner delegates the subdomain to the authorizing DNS server to operate the subdomain;

receive a DNS query from a receiving email system attempting to authenticate an incoming email that includes an identifier, wherein the DNS query is generated based on the identifier; and

return, as a response to the DNS query and on behalf of the domain owner, the DNS record to the receiving email system, wherein information in the DNS record published under the subdomain determines whether the incoming email is authenticated.

12. The system of claim 11 , wherein the subdomain has an address that includes the domain as part of the address.

13. The system of claim 11 , wherein the authorizing DNS server is an authoritative server of the subdomain.

14. The system of claim 11 , wherein the DNS query is generated by the receiving email system first sending a DNS query to the domain of the domain owner, and the domain has an include directive that points to the subdomain.

15. The system of claim 11 , wherein the DNS record includes one or more policies associated with the domain owner.

16. The system of claim 11 , wherein the identifier is part of header of the incoming email.

17. The system of claim 11 , wherein the DNS query includes the identifier as part of the DNS query.

18. The system of claim 11 , wherein the identifier indicates that the domain is part of a sender address of the incoming email.

19. The system of claim 11 , wherein the one or more inputs are received from a graphical user interface.

20. The system of claim 11 , wherein the one or more inputs are provided by an administrator of the domain owner, the administrator providing at least one of the inputs to generate or verify the authorized deliverer list.

21. A computer-implemented method, comprising:

receiving one or more inputs for indicating a delivering organization in an authorized deliverer list is authorized to deliver emails on behalf of a domain owner that owns an email domain;

storing the authorized deliverer list associated with the domain owner;

generating a DNS record to include information used to authenticate emails sent from the delivering organization on behalf of the domain owner, the information being related to the delivering organization;

publishing, by an authorizing domain name system (DNS) server on behalf of the domain owner, the DNS record at a subdomain associated with the domain of the domain owner, wherein the authorizing DNS server, the domain owner, and the delivering organization are different entities, wherein the authorizing DNS server is a different server than a server that operates the email domain, wherein the subdomain is a publicly accessible location and the domain owner delegates the subdomain to the authorizing DNS server to operate the subdomain;

receiving a DNS query from a receiving email system attempting to authenticate an incoming email that includes an identifier, wherein the DNS query is generated based on the identifier; and

returning, as a response to the DNS query and on behalf of the domain owner, the DNS record to the receiving email system, wherein information in the DNS record published under the subdomain determines whether the incoming email is authenticated.

22. The computer-implemented method of claim 21 , wherein the subdomain has an address that includes the domain as part of the address.

23. The computer-implemented method of claim 21 , wherein the authorizing DNS server is an authoritative server of the subdomain.

24. The computer-implemented method of claim 21 , wherein the DNS query is generated by the receiving email system first sending a DNS query to the domain of the domain owner, and the domain has an include directive that points to the subdomain.

25. The computer-implemented method of claim 21 , wherein the DNS record includes one or more policies associated with the domain owner.

26. The computer-implemented method of claim 21 , wherein the identifier is part of header of the incoming email.

27. The computer-implemented method of claim 21 , wherein the DNS query includes the identifier as part of the DNS query.

28. The computer-implemented method of claim 21 , wherein the identifier indicates that the domain is part of a sender address of the incoming email.

29. The computer-implemented method of claim 21 , wherein the one or more inputs are received from a graphical user interface.

30. The computer-implemented method of claim 21 , wherein the one or more inputs are provided by an administrator of the domain owner, the administrator providing at least one of the inputs to generate or verify the authorized deliverer list.

Assignments (3)
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 9, 2026
From: VALIMAIL INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 074281/0239 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2025
From: VALIMAIL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 073910/0374 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2021
From: GOLDSTEIN, PETER MARTIN
To: VALIMAIL INC.
Reel/Frame 058400/0794 →
Continuity (8)
Continuation 17360322 · Jun 28, 2021
Continuation 17128008 · Dec 19, 2020
Continuation 16296121 · Mar 7, 2019
Continuation 15663771 · Jul 30, 2017
Continuation 15175031 · Jun 6, 2016
Continuation PCTUS2016015796 · Jan 29, 2016
Provisional Application 62116409 · Feb 14, 2015
Related Publication 20220070224A1 · Mar 3, 2022