DNS SPF Query Logging for Real-Time Outbound Email Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic messaging technologies lack real-time visibility into outbound message volumes and patterns from a domain, failing to provide administrators with immediate intelligence on security and resource allocation, and do not allow for immediate authorization of external messaging service providers.

Innovation Solution

Implementing a system that configures the DNS to log SPF queries, extracts data using macro-endowed SPF policies to track username, IP address, and domain, and provides real-time insights into outbound emails, enabling administrators to authorize vendors and restrict unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional email authentication protocols (DMARC, SPF) are used, then message authentication is achieved, but real-time visibility into outbound message volumes and patterns is not provided to administrators

Engineering Contradiction:
Improvevisibility into outbound message volumesVSAvoidtime delay in receiving authentication reports
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by configuring DNS to log SPF queries in real-time as they occur, rather than waiting for periodic DMARC reports. This allows administrators to immediately access outbound message data through the DNS query logs, eliminating the 24-hour delay inherent in traditional DMARC reporting mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces DNS query logging as an intermediary mechanism between email authentication and administrative visibility. By logging SPF DNS queries that occur during email authentication, the system creates a real-time data stream that administrators can monitor, serving as a mediator that provides immediate insight into outbound messaging without requiring changes to the underlying email authentication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If administrators want immediate control over outbound messaging and vendor authorization, then real-time monitoring is needed, but current systems lack mechanisms for immediate authorization and restriction

Engineering Contradiction:
Improveability to authorize and restrict vendorsVSAvoidtime to implement security measures
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system implements feedback by continuously monitoring DNS query logs for SPF records and providing administrators with real-time information about which vendors are being used for outbound messaging. This immediate feedback loop enables administrators to quickly identify unauthorized vendors and take corrective action, rather than discovering issues days later through periodic reports.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables preliminary action by allowing administrators to pre-configure authorized vendors in the DNS system. When SPF queries are logged, the system can immediately compare them against the pre-configured authorization list and either permit or block the messaging activity in real-time, eliminating delays in implementing security restrictions.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If detailed tracking of individual user and third-party service message volumes is implemented, then fraud detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvefraud and abuse detectionVSAvoidsystem architecture for monitoring and control
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies self-service by leveraging the existing DNS infrastructure and SPF query mechanisms that are already in place for email authentication. By simply logging the DNS queries that occur during normal authentication processes, the system obtains detailed messaging data without requiring complex additional tracking infrastructure, agent installation, or message interception mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent demonstrates universality by using the DNS system to serve multiple functions: it continues to perform its traditional role of resolving domain names while simultaneously logging SPF authentication queries for security monitoring purposes. This multi-functionality allows the system to gain fraud detection capabilities without adding separate dedicated monitoring infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12120151B2Low-latency, outbound message monitoring, control, and authentication
Publication Date: 2024.10.15 FRAUDMARC INC
  • US12120151B2 patent drawing
  • US12120151B2 patent drawing
  • US12120151B2 patent drawing

AI summary

Embodiments of the present disclosure provide a first set of methods, computer-readable media, and system configured for: receiving a configuration for a domain name system (DNS) to log all queries; publishing a customized sender policy framework (SPF) policy to the DNS, the customized SPF policy comprising a macro-endowed mechanism; logging a plurality of received SPF customized queries; accessing a log comprising the plurality of received SPF customized queries; extracting data from each of the received SPF customized queries, the data being populated by the macro mechanism associated with the SPF customized query; populating a datastore with extracted data comprising at least one of the following: a username, a IP address, and a domain, as extracted from each received SPF customized query; and providing, based on the extracted data, an indication of outbound emails sent from the domain. In various embodiments, email authorizations and restrictions may be based thereon.