IP Library › Granted Patent US 12,413,601
Granted Patent B2
US 12,413,601 · App. 18/478,989 · Granted Sep 9, 2025

Protecting against DKIM replay

Inventor: Wei-haw Chuang (Menlo Park, CA)
Assignee: Google LLC
H04L63/126H04L9/3247H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,601
App. No.
18/478,989
Filed
Sep 29, 2023
Granted
Sep 9, 2025
Kind
B2
Art Unit
2446
USPC
713/176
Abstract

A method for securing messages includes obtaining, at a first message server, a message for a user of a message service hosted by the first message server, the message including a header including a digital signature signed by an author of the message and a list of one or more recipients of the message. The method includes determining that a Domain Name System (DNS) TXT record associated with the message includes a delegation policy indicating that a second message server declared all intended recipients of the message. In response, the method includes determining that the digital signature by the author is valid and that the user is a declared recipient of the message. The method includes, in response to determining that the digital signature by the author is valid and the user is the declared recipient of the message, indicating the message is authentic.

Claims (70)

1. A computer-implemented method when executed by data processing hardware causes the data processing hardware to perform operations comprising:

obtaining, at a first message server, a message for a user of a message service hosted by the first message server, the message from a second message server hosting a second message service, the message comprising a header, the header comprising:

a digital signature signed by an author of the message; and

a list of one or more recipients of the message;

determining that a Domain Name System (DNS) TXT record associated with the message comprises a delegation policy indicating that the header declared all intended recipients of the message;

in response to determining that the DNS TXT record comprises the delegation policy:

determining that the digital signature by the author is valid; and

determining, using the list of one or more recipients, that the user is a declared recipient of the message; and

in response to determining that the digital signature by the author is valid and the user is the declared recipient of the message, indicating the message is authentic.

2. The method of claim 1 , wherein the operations further comprise:

obtaining, at the first message server, a second message intended for a second user of a third message service hosted by a third message server;

indicating, via an Authenticated Received Chain (ARC) header, that the third message server fails to declare all recipients of messages; and

transmitting the second message to the third message server.

3. The method of claim 1 , wherein the operations further comprise:

receiving, at the first message server, from a third message server, a second message for the user of the message service hosted by the first message server;

determining that the second message is an indirect message; and

responsive to determining that the second message is an indirect message, applying an indirect message policy to the second message.

4. The method of claim 3 , wherein determining that the second message is an indirect message comprises determining a misalignment between a DomainKeys Identified Mail (DKIM) authentication and a sender policy framework (SPF) authentication.

5. The method of claim 3 , wherein the indirect message policy comprises one of:

rejecting the second message; or

quarantining the second message.

6. The method of claim 1 , wherein the operations further comprise:

obtaining, at the first message server, a second message intended for a second user of a third message service hosted by a third message server, the second message comprising a second header;

updating, based on the third message server, the second header to indicate that all intended recipients of the second message are declared; and

transmitting the second message to the third message server.

7. The method of claim 6 , wherein updating the second header comprises adding a forwarded-to declaration.

8. The method of claim 1 , wherein the operations further comprise:

receiving, at the first message server, from a third message server, a second message for the user of the message service hosted by the first message server;

retrieving domain information associated with the third message server; and

determining that the second message is authentic based on the domain information.

9. The method of claim 8 , wherein retrieving the domain information comprises retrieving a public key certificate associated with the third message server.

10. The method of claim 9 , wherein:

the domain information comprises a threshold message recipient quantity; and

determining that the second message is authentic comprises determining that a quantity of recipients receiving the second message satisfies the threshold message recipient quantity.

11. A system comprising:

data processing hardware; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

obtaining, at a first message server, a message for a user of a message service hosted by the first message server, the message from a second message server hosting a second message service, the message comprising a header, the header comprising:

a digital signature signed by an author of the message; and

a list of one or more recipients of the message;

determining that a Domain Name System (DNS) TXT record associated with the message comprises a delegation policy indicating that the header declared all intended recipients of the message;

in response to determining that the DNS TXT record comprises the delegation policy:

determining that the digital signature by the author is valid; and

determining, using the list of one or more recipients, that the user is a declared recipient of the message; and

in response to determining that the digital signature by the author is valid and the user is the declared recipient of the message, indicating the message is authentic.

12. The system of claim 11 , wherein the operations further comprise:

obtaining, at the first message server, a second message intended for a second user of a third message service hosted by a third message server;

indicating, via an Authenticated Received Chain (ARC) header, that the third message server fails to declare all recipients of messages; and

transmitting the second message to the third message server.

13. The system of claim 11 , wherein the operations further comprise:

receiving, at the first message server, from a third message server, a second message for the user of the message service hosted by the first message server;

determining that the second message is an indirect message; and

responsive to determining that the second message is an indirect message, applying an indirect message policy to the second message.

14. The system of claim 13 , wherein determining that the second message is an indirect message comprises determining a misalignment between a DomainKeys Identified Mail (DKIM) authentication and a sender policy framework (SPF) authentication.

15. The system of claim 13 , wherein the indirect message policy comprises one of:

rejecting the second message; or

quarantining the second message.

16. The system of claim 11 , wherein the operations further comprise:

obtaining, at the first message server, a second message intended for a second user of a third message service hosted by a third message server, the second message comprising a second header;

updating, based on the third message server, the second header to indicate that all intended recipients of the second message are declared; and

transmitting the second message to the third message server.

17. The system of claim 16 , wherein updating the second header comprises adding a forwarded-to declaration.

18. The system of claim 11 , wherein the operations further comprise:

receiving, at the first message server, from a third message server, a second message for the user of the message service hosted by the first message server;

retrieving domain information associated with the third message server; and

determining that the second message is authentic based on the domain information.

19. The system of claim 18 , wherein retrieving the domain information comprises retrieving a public key certificate associated with the third message server.

20. The system of claim 19 , wherein:

the domain information comprises a threshold message recipient quantity; and

determining that the second message is authentic comprises determining that a quantity of recipients receiving the second message satisfies the threshold message recipient quantity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2023
From: CHUANG, WEI-HAW
To: GOOGLE LLC
Reel/Frame 065092/0485 →
Continuity (2)
Provisional Application 63378145 · Oct 3, 2022
Related Publication 20240113893A1 · Apr 4, 2024
References Cited (12)
US 10673636B1 · Finke · 2020 [cited by examiner]
US 11212245B1 · Ding · 2021 [cited by examiner]
US 12149633B2 · Chuang · 2024 [cited by examiner]
US 20190319905A1 · Baggett · 2019 [cited by examiner]
US 20200274717A1 · Finke · 2020 [cited by examiner]
US 20210152610A1 · Fryback · 2021 [cited by examiner]
US 20250062914A1 · Chuang · 2025 [cited by examiner]
Bart Butler: “How Proton helped Gmail overcome a DKIM replay attack | Proton Mail”, Aug. 15, 2022 (Aug. 15, 2022, XP093107011. URL: https://web.archive.org/web/20220815055854/https://proton.me/blog/dkim-replay-attack-br… [cited by applicant]
Crocker D et al: “DomainKeys Identified Mail (DKIM) Signatures; rfc63763txt”, Domain Keys Identified Mail (DKIM) Signatures; RFC6376.TXT, Internet Engineering Task Force, IETF; Standard, Internet Society (ISOC) 4, Rue D… [cited by applicant]
Brian Godiksen: “DKIM Replay Attacks | Preventive Measures | Socketlabs”, socketlabs, Feb. 14, 2022 (Feb. 14, 2022), XP093106972, URL:https://www.socketlabs.com/blog/dkim-replay-attacks-preventive-measures-to-protect-em… [cited by applicant]
Anders Berggren: “The DKIM replay attack, and how to mitigate—Halon”, Apr. 28, 2022 (Apr. 28, 2022) XP093107078, URL:https://halon.io/blog/the-dkim-replay-attack-and-how-to-mitigate. [cited by applicant]
International Search Report in related PCT Application No. PCT/US2023/034239, dated Dec. 15, 2023. [cited by applicant]