Office 365 Enables ARC for Enhanced Anti-Spoofing Detection

Office 365 Enables ARC for Enhanced Anti-Spoofing Detection


Microsoft has enabled Authenticated Received Chain (ARC) for all for Office 365 hosted mailboxes to improve anti-spoofing detection and to check authentication results within Office 365.


ARC is a protocol designed to provide an authenticated "chain of custody" for messages making it possible for each of the users handling an email to see what other entities handled it previously, as well as determine its authentication assessment at each step during the delivery process.


The ARC protocol supplements the DMARC and DKIM email authentication protocols as part of Internet Mail Handlers' effort to combat email spoofing especially when dealing with forwarded messages.


DMARC.org announced ARC in 2015, IETF's DMARC Working Group adopted it as an official work item in June 2016, and published the specification on July 9th, 2019.


In the video embedded below, DMARC Executive Director Stephen Jones provides a quick overview of how ARC works to help reduce fraud by allowing "senders and receivers to cooperate on stopping fraudulent messages that impersonate a domain from reaching end-users mailboxes."


[embedded content]


Domain spoofing detection


"All hosted mailboxes in Office 365 will now gain the benefit of ARC with improved deliverability of messages and enhanced anti-spoofing detection," says the feature's Microsoft 365 roadmap entry. 


"ARC preserves the email authentication results from all participating intermediaries, or hops, when an email is routed from the ..

Support the originator by clicking the read the rest link below.