An official website of the European Union How do you know?      
European Commission logo
JRC Publications Repository Menu

What email servers can tell to Johnny: An empirical study of provider-to-provider email security

cover
With hundred billions of emails sent daily, the adoption of contemporary email security standards and best practices by the respective providers are of utmost importance to everyone of us. Leaving out the user-dependent measures, say, S/MIME and PGP, this work concentrates on the current security standards adopted in practice by providers to safeguard the communications among their SMTP servers. To this end, we developed a non-intrusive tool coined MECSA, which is publicly available as a web application service to anyone who wishes to instantly assess the security status of their email provider regarding both the inbound and outbound channel. By capitalising on the data collected by MECSA over a period of 15 months, that is, about 7,650 assessments, analysing a total of 3,236 unique email providers, we detail on the adoption rate of state-of-the-art SMTP security extensions, including STARTTLS, SPF, DKIM, DMARC, and MTA-STS. Our results indicate a clear increase in encrypted connections and in the use of SPF, but also considerable retardation in the penetration rate of the rest of the standards. This tardiness is further aggravated by the still low prevalence of DNSSEC, which is also appraised for the email security space in the context of this work.
2020-07-22
IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
JRC120814
2169-3536 (online),   
https://ieeexplore.ieee.org/document/9139968,    https://publications.jrc.ec.europa.eu/repository/handle/JRC120814,   
10.1109/ACCESS.2020.3009122 (online),   
Language Citation
NameCountryCityType
Datasets
IDTitlePublic URL
Dataset collections
IDAcronymTitlePublic URL
Scripts / source codes
DescriptionPublic URL
Additional supporting files
File nameDescriptionFile type 
Show metadata record  Copy citation url to clipboard  Download BibTeX
Items published in the JRC Publications Repository are protected by copyright, with all rights reserved, unless otherwise indicated. Additional information: https://ec.europa.eu/info/legal-notice_en#copyright-notice