System and method for identifying spoofed email by modifying the sender address
Abstract
A system, method and computer program product are provided for identifying spoofed emails. According to the method, an email addressed to a recipient in a first network is received, with the email including a plurality of headers, and at least one of the plurality of headers including a sender address. It is determined whether the sender address indicates a mailbox from within the first network, and the sender address is modified if it indicates a mailbox within the first network. The email with the modified sender address is sent to the recipient. In one embodiment, a second email is received that is from the recipient and that is addressed to the modified sender address, the modified sender address is modified so as to return it to its original form, and the second email is sent.
Claims
exact text as granted — not AI-modified1 . A method for identifying spoofed emails, the method comprising the steps of:
receiving an email addressed to a recipient in a first network, the email including a plurality of headers, wherein at least one of the plurality of headers includes a sender address; determining whether the sender address indicates a mailbox from within the first network; when the sender address indicates a mailbox from within the first network, modifying at least a portion of the sender address so as to produce a modified sender address that indicates to the recipient that the email is associated with a mailbox that is external to the first network; and sending the email with the modified sender address to the recipient, the modified sender address being visible to the recipient.
2 . The method of claim 1 , wherein the receiving step comprises:
receiving the email that includes a “sender” header field that includes the sender address.
3 . The method of claim 1 , wherein the receiving step comprises:
receiving the email that includes a “from” header field that includes the sender address.
4 . The method of claim 1 , wherein the receiving step comprises:
receiving the email that includes a “reply-to” header field that includes the sender address.
5 . The method of claim 1 , wherein the step of determining comprises:
determining whether the sender address matches any one of a plurality of domains or sub-domains associated with the first network.
6 . The method of claim 1 , wherein the step of modifying comprises:
appending a predetermined sub-domain to the sender address.
7 . The method of claim 1 , wherein the step of modifying comprises:
modifying at least one of a domain and a sub-domain of the sender address.
8 . The method of claim 1 , further comprising:
receiving a second email, the second email being from the recipient and being addressed to the modified sender address; modifying the modified sender address so as to produce the sender address; and sending the second email with the sender address.
9 . A tangible computer readable storage medium encoded with a program for identifying spoofed emails, the program comprising instructions for performing a method comprising the steps of:
receiving an email addressed to a recipient in a first network, the email including a plurality of headers, wherein at least one of the plurality of headers includes a sender address; determining whether the sender address indicates a mailbox from within the first network; when the sender address indicates a mailbox from within the first network, modifying at least a portion of the sender address so as to produce a modified sender address that indicates to the recipient that the email is associated with a mailbox that is external to the first network; and sending the email with the modified sender address to the recipient, the modified sender address being visible to the recipient.
10 . The tangible computer readable storage medium of claim 9 , wherein the receiving step of the method comprises:
receiving the email that includes a “sender” header field that includes the sender address.
11 . The tangible computer readable storage medium of claim 9 , wherein the receiving step of the method comprises:
receiving the email that includes a “from” header field that includes the sender address.
12 . The tangible computer readable storage medium of claim 9 , wherein the modifying step of the method comprises:
appending a predetermined sub-domain to the sender address.
13 . The tangible computer readable storage medium of claim 9 , wherein the modifying step of the method comprises:
modifying at least one of a domain and a sub-domain of the sender address.
14 . The tangible computer readable storage medium of claim 9 , wherein the method further comprises the steps of:
receiving a second email, the second email being from the recipient and being addressed to the modified sender address; modifying the modified sender address so as to produce the sender address; and sending the second email with the sender address.
15 . A computer system for identifying spoofed emails, the computer system comprising:
a receiver receiving an email addressed to a recipient in a first network, the email including a plurality of headers, wherein at least one of the plurality of headers includes a sender address; a processor determining whether the sender address indicates a mailbox from within the first network, the processor modifying at least a portion of the sender address so as to produce a modified sender address that indicates to the recipient that the email is associated with a mailbox that is external to the first network when the sender address indicates a mailbox from within the first network; and a transmitter sending the email with the modified sender address to the recipient, the modified sender address being visible to the recipient.
16 . The computer system of claim 15 , wherein the receiver receives the email that includes a “sender” header field that includes the sender address.
17 . The computer system of claim 15 , wherein the processor modifies the sender address by appending a predetermined sub-domain to the sender address.
18 . The computer system of claim 15 , wherein the processor determines whether the sender address indicates a mailbox from within the first network by determining whether the sender address matches any one of a plurality of domains or sub-domains associated with the first network, and
the processor modifies the sender address by modifying the sender address when the sender address matches any one of the domains or sub-domains associated with the first network.Join the waitlist — get patent alerts
Track US2009113012A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.