IP Library › Granted Patent US 12,250,283
Granted Patent B2
US 12,250,283 · App. 18/362,848 · Granted Mar 11, 2025

Inline SPF service provider designation

Inventors: Keith Wayne Coleman (Atlanta, GA); Richard Duncan (Atlanta, GA)
Assignee: Fraudmarc Inc.
H04L67/563H04L51/48H04L67/1012H04L67/51H04L61/4511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,283
App. No.
18/362,848
Filed
Jul 31, 2023
Granted
Mar 11, 2025
Kind
B2
Art Unit
2441
USPC
709/203
Abstract

Sender Policy Framework (SPF) is one of the most widely used methods of distinguishing electronic mail that is authorized by the purported sending domain from unauthorized mail. SPF policies are published into a domain's DNS and then looked up and evaluated by mail receivers. Due to the complexity and limitations of the SPF specification, implementation mistakes are widespread. This problem is compounded by the common practice of nesting SPF policies which introduces hidden risks, particularly exceeding DNS lookup limits. To address these issues, inline service provider designation may be configured to capture the benefits of existing techniques without their associated costs. Additionally, the domain owner may enjoy simplified SPF service provider onboarding and policy failover redundancy to protect against SPF service provider disruptions, thus improving policy availability uptime.

Claims (28)

1. A method comprising:

providing at least one active policy service term for inclusion in a Sender Policy Framework (SPF) policy used to delegate functional policy hosting and management to an administratively independent domain,

wherein the at least one active policy service term is provided for insertion into the SPF policy on a line of a Domain Name System (DNS) record prior to a line containing a pre-existing policy term, wherein the at least one active policy service term, while active, renders the pre-existing policy term inactive,

and wherein the at least one active policy term is created based on one or more of:

the pre-existing policy term in a same DNS record as the SPF policy, or

a policy term in an adjacent DNS row.

2. The method of claim 1 , further comprising onboarding an SPF service provider without removal of an existing SPF record.

3. The method of claim 2 , wherein onboarding the SPF service provider comprises prepending the at least one active policy service term to the pre-existing policy term of the existing SPF record.

4. The method of claim 1 , wherein the at least one active policy service term is comprised of a service designation term from an SPF service provider.

5. The method of claim 4 , wherein the at least one active policy service term further comprises a virtual all term.

6. The method of claim 5 , wherein the virtual all term is configured to fail open to enable a pass-through policy evaluation of the pre-existing policy term when the SPF service provider is irresponsive.

7. The method of claim 1 , wherein the inclusion of the at least one active policy service term keeps the pre-existing policy term.

8. The method of claim 7 , wherein the pre-existing policy term remains as a redundant back-up in the event the administratively independent domain is unresponsive.

9. The method of claim 1 , wherein the pre-existing policy term remains inactive and is not evaluated subsequent to a match provided by the at least one active policy service term.

10. The method of claim 9 , wherein inserting the at least one active policy service term comprises moving the pre-existing policy term to an adjacent DNS line.

11. The method of claim 1 , wherein the pre-existing policy term comprises a high-level term that allows the pre-existing policy term to be hosted under a different domain name.

12. A method comprising:

providing at least one active policy service term for inclusion in a Sender Policy Framework (SPF) policy used to delegate functional policy hosting and management to an administratively independent domain,

wherein the at least one active policy service term is provided for insertion into the SPF policy at a Domain Name System (DNS) record prior to a record containing a pre-existing policy term, wherein the at least one active policy service term, while active, renders the pre-existing policy term inactive,

and wherein the at least one active policy term is created based on a policy term in an adjacent DNS record.

13. The method of claim 12 , wherein the at least one active policy service term is comprised of a service designation term from an SPF service provider.

14. The method of claim 13 , wherein the at least one active policy service term further comprises a virtual all term.

15. The method of claim 14 , wherein the virtual all term is configured to fail open to enable a pass-through policy evaluation of the pre-existing policy term when the SPF service provider is irresponsive.

16. The method of claim 12 , wherein the inclusion of the at least one active policy service term keeps the pre-existing policy term.

17. The method of claim 16 , wherein the pre-existing policy term remains as a redundant back-up in the event the administratively independent domain is unresponsive.

18. The method of claim 12 , wherein the pre-existing policy term remains inactive and is not evaluated subsequent to a match provided by the at least one active policy service term.

19. The method of claim 18 , wherein inserting the at least one active policy service term comprises moving the pre-existing policy term to the adjacent DNS record.

20. The method of claim 12 , wherein the pre-existing policy term comprises a high-level term that allows the pre-existing policy term to be hosted under a different domain name.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2023
From: COLEMAN, KEITH WAYNE, MR.; DUNCAN, RICHARD, MR.
To: FRAUDMARC INC.
Reel/Frame 065569/0177 →
Continuity (4)
Continuation 17827879 · May 30, 2022
Continuation 17504433 · Oct 18, 2021
Provisional Application 63092873 · Oct 16, 2020
Related Publication 20240073296A1 · Feb 29, 2024
References Cited (55)
US 8090940B1 · Fenton · 2012 [cited by examiner]
US 8392357B1 · Zou · 2013 [cited by examiner]
US 11019076B1 · Jakobsson · 2021 [cited by examiner]
US 11171939B1 · Blank · 2021 [cited by examiner]
US 11200581B2 · Williams · 2021 [cited by examiner]
US 11212245B1 · Ding · 2021 [cited by examiner]
US 11223599B1 · Mielke · 2022 [cited by examiner]
US 11349945B2 · Coleman · 2022 [cited by examiner]
US 11463392B2 · Coleman et al. · 2022 [cited by applicant]
US 11706178B2 · Coleman et al. · 2023 [cited by applicant]
US 11716403B2 · Coleman · 2023 [cited by examiner]
US 12120079B2 · Coleman et al. · 2024 [cited by applicant]
US 20050144451A1 · Voice · 2005 [cited by examiner]
US 20060031319A1 · Nelson · 2006 [cited by examiner]
US 20060179113A1 · Buckingham · 2006 [cited by examiner]
US 20080184366A1 · Alperovitch · 2008 [cited by examiner]
US 20080189770A1 · Sachtjen · 2008 [cited by examiner]
US 20080282344A1 · Shuster · 2008 [cited by examiner]
US 20080307226A1 · Chow · 2008 [cited by examiner]
US 20090147936A1 · Won · 2009 [cited by examiner]
US 20100121928A1 · Leonard · 2010 [cited by examiner]
US 20100299399A1 · Wanser et al. · 2010 [cited by applicant]
US 20130086187A1 · Cohen · 2013 [cited by examiner]
US 20140181516A1 · Yoshioka · 2014 [cited by examiner]
US 20140215571A1 · Shuster · 2014 [cited by examiner]
US 20160315969A1 · Goldstein · 2016 [cited by applicant]
US 20170078321A1 · Maylor et al. · 2017 [cited by applicant]
US 20170093772A1 · Gupta · 2017 [cited by examiner]
US 20180227259A1 · Gupta · 2018 [cited by examiner]
US 20190141077A1 · Tyler · 2019 [cited by examiner]
US 20190222608A1 · Naccarato · 2019 [cited by examiner]
US 20190379660A1 · Thirumavalavan · 2019 [cited by examiner]
US 20200213332A1 · Thirumavalavan · 2020 [cited by examiner]
US 20210126942A1 · Fantham · 2021 [cited by examiner]
US 20210152610A1 · Fryback · 2021 [cited by examiner]
US 20210266294A1 · Chechik · 2021 [cited by examiner]
US 20210289001A1 · Wilson · 2021 [cited by examiner]
US 20210344721A1 · Coleman · 2021 [cited by examiner]
US 20210352093A1 · Hassanzadeh · 2021 [cited by examiner]
US 20220014543A1 · Jakobsson · 2022 [cited by examiner]
US 20220124059A1 · Coleman et al. · 2022 [cited by applicant]
US 20220124165A1 · Coleman et al. · 2022 [cited by applicant]
US 20220294873A1 · Coleman et al. · 2022 [cited by applicant]
US 20230026045A1 · Coleman et al. · 2023 [cited by applicant]
US 20230121553A1 · Coleman et al. · 2023 [cited by applicant]
US 20240019821A1 · Rice · 2024 [cited by examiner]
U.S. Non-Final Office Action dated Jan. 12, 2022 cited in U.S. Appl. No. 17/504,423, 13 pgs. [cited by applicant]
Lars Lind Nilsson et al., “What does a “-all” do in an included (secondary) SPF record?” Super User, Retrieved Jan. 8, 2022 from https://superuser.com/questions/1167143/what-does-a-all-do-in-an-included-secondary-spf-re… [cited by applicant]
Hakan Lindqvist et al., “SPF with-all includes directive with ˜all?” Server Fault, Retrieved Jan. 8, 202 from https://serverfault.com/questions/848711/spf-with-all-includes-directive-with-all, May 8, 2017, 5 pgs. [cited by applicant]
Roaima et al., “Adding an SPF record for a 3rd party, but don't have one for my own domain,” Server Fault, Retrieved Jan. 8, 2022 from https://serverfault.com/questions/734297/adding-an-spf-record-for-a-3rd-party-but-do… [cited by applicant]
MadHatter et al., “What are SPF records, and how do I configure them?” Server Fault, Retrieved Jan. 8, 2022 from https://serverfault.com/questions/369460/what-are-spf-records-and-how-do-i-configure-them/369478#369478, M… [cited by applicant]
U.S. Non-Final Office Action dated Nov. 8, 2022 cited in U.S. Appl. No. 17/827,879, 17 pgs. [cited by applicant]
Related U.S. Continuation U.S. Appl. No. 18/353,926, filed Jul. 18, 2023 entitled “Regulation of SPF Policy Terms” Inventors: Keith Wayne Coleman et al. [cited by applicant]
U.S. Non-Final Office Action dated Jul. 31, 2024 cited in U.S. Appl. No. 17/966,719, 46 pgs. [cited by applicant]
S. Kitterman, Sender Policy Framework (SFP) for Authorizing Use of Domains in Email, Version 1 (RFC7208), Apr. 1, 2014, Retrieved Jul. 15, 2024 from <URL: https://priorart.ip.com/IPCOM/000236452>. [cited by applicant]