Google Doesn’t Respect Email

| | Comments (2) | TrackBacks (1)
I was just playing around with the new interface for Google Analytics and decided to email myself a report. It's a nice little feature, but there is a serious downside to their implementation. Instead of sending the email from a Google domain (it's not as if they have a shortage) they send it from your email address. While this may seem logical at face value it has serious implications for email security, as you are effectively allowing Google to send mail purporting to be from your domain. If you have been avoiding DKIM and SPF, then this probably won't be a problem for you, but if you have actually implemented it using a relatively strict, and therefore useful policy, then you are going to run into problems. Of course this isn't the first instance of a Google implementation flying in the face of common sense. Their Gmail service has been severely criticised in email filtering circles on may occassions since its introduction due to the lack of a vital part of the email header - the source IP. Whereas other services such as Yahoo! mail or Hotmail / MSN include the sender's actual IP in the email header, Google decided not to. If they'd stopped there it wouldn't be too bad, but they've applied the same logic (or lack of it) to their Google Apps services, so you could easily end up discovering that your mails are being blocked due to abuse of the Google SMTP by others.
digg| bookmark

Categories

,

1 TrackBacks

Listed below are links to blogs that reference this entry: Google Doesn’t Respect Email.

TrackBack URL for this entry: http://www.mneylon.com/cgi-bin/mt/mt-tb.cgi/2053

» from Adsense Expands Options For Publishers

2 Comments

Ed Byrne said:

I think they may do it that way as a lot of admin's are web developers / outsourced techies ... and possibly charging for the analytics ... so it's a very basic type of white labelling.

michele said:

Ed

If it's white labelling it's a terrible implementation.

How can you implement SPF properly with it?


Michele

Michele Neylon - cartoon picture

About this Entry

This page contains a single entry by Michele Neylon published on May 25, 2007 12:23 AM.

Hyperlinks and Online Publications - Silicon Republic Don’t Get it! was the previous entry on this site.

Enum Going Live in Ireland is the next entry on this site.

Find recent content on the main index or look in the archives to find all content.

Powered by Movable Type 4.1