Outlook.com given security boost by Microsoft
New webmail service, which is in a trial phase, has gained support for antiphishing and antispam technologies
By Juan Carlos Perez | Published: 13:47, 11 December 2012
Outlook.com, the new webmail service that Microsoft is previewing and that will replace Hotmail, has gained security boosts against phishing and spam.
The new safety features come via support for the DMARC email authentication standard and for EV Certificates, which are designed to strengthen SSL certificates, Microsoft said.
DMARC (Domain-based Message Authentication, Reporting & Conformance) is a technical specification intended to standardise how email recipient systems authenticate incoming messages using the SPF and DKIM technologies.
Related Articles on Techworld
Microsoft, as well as other DMARC supporters like Yahoo, AOL, Facebook, PayPal and Google, believe that DMARC will help cut down on the success of phishing emails that spoof legitimate addresses to trick recipients into disclosing confidential information or clicking on malicious website links.
"Our DMARC implementation helps protect you by making it easier to visually identify mail from senders as legitimate, and helps keep spam and phishing messages from ever reaching your inbox. If a sender supports DMARC, we put a trusted sender logo next to their email indicating it is legitimate," said Krish Vitaldevara from the Outlook.com Program Management Team.
Meanwhile, Microsoft is adding support for EV (Extended Validation) Certificates to Outlook.com, to reduce the likelihood that malicious hackers will be able to trick users into entering confidential information on a fraudulent site designed to resemble Outlook.com.
Microsoft has chosen Verisign to issue Outlook.com's EV Certificates, which require a minimum of 2048-bit encryption. After an EV certificate is validated, users' browsers display a green bar in the URL address bar indicating the site is legitimate.
"While malicious sites might try to impersonate a site's UI or brand, they cannot replicate the browser's green bar. And by deploying EV certificates broadly we can apply 2048 bit encryption not just to your login, but to your actual mail content as well," Vitaldevara said.
Microsoft plans to support EV Certificates in its SkyDrive online storage service and other of its sites soon.
Microsoft made Outlook.com available for public trial in July of this year, saying that the new webmail service offers a re-imagining of personal email, from its back-end technologies to its user interface. About 25 million people are giving Outlook.com a try.