Valimail Industry Leadership
Our commitment to restoring email trust.
With deep expertise in internet security and resilient infrastructure, the Valimail team regularly contributes to standards and threat detection communities — driving today’s email authentication policies and tomorrow’s cybersecurity advancements. We have a corporate commitment to lifting up the messaging industry as a whole and working collaboratively with partners throughout the ecosystem to restore trust to email.
We participate in several organizations working to make a difference.
We write and maintain open source code used by the largest mailbox providers (like Oath/Yahoo!) and make our contributions available to all, fixing issues in an accessible, scalable, global way.
We contribute to the protocols that continue to advance email and make it better for everyone.
Messaging Malware Mobile Anti-Abuse Working GroupBoard Member Technical Committee Co-Chair Collaboration Committee Co-ChairVisite website
M3AAWG is where the industry comes together to work against botnets, malware, spam, viruses, DoS attacks and other online exploitation.
Financial Services Information Sharing and Analysis CenterMemberVisite website
FS-ISAC is the only industry forum for collaboration on critical security threats facing the global financial services sector.
Health Information Sharing and Analysis CenterNavigatorVisite website
H-ISAC is a global, non-profit, member-driven organization offering health care stakeholders a trusted community and forum for coordinating, collaborating and sharing vital Physical and Cyber Threat Intelligence and best practices with each other.
Center for Internet SecurityMemberVisite website
CIS harnesses the power of a global IT community to safeguard public and private organizations against cyber threats.
Automotive Information Sharing and Analysis CenterMemberVisite website
AUTO-ISAC is an industry-driven community to share and analyze intelligence about emerging cybersecurity risks to the vehicle, and to collectively enhance vehicle cybersecurity capabilities across the global automotive industry, including light- and heavy-duty vehicle OEMs, suppliers and the commercial vehicle sector.
Retail and Hospitality Information Sharing and Analysis CenterMemberVisite website
This association connects information security teams at the strategic, operational and tactical levels to work together on issues and challenges, to share practices and insights, and to benchmark among each other – all with the goal of building better security for the retail and hospitality industries through collaboration.
Information Technology – Information Sharing and Analysis CenterMemberVisite website
The IT-ISAC mission is to grow a diverse community of companies that leverage information technology and have in common a commitment to cyber-security; to serve as a force multiplier that enables collaboration and sharing of relevant, actionable cyber threat information and effective security policies and practices for the benefit of all.
Internet Engineering Task ForceSecretary of IETF DMARC working group, contributorVisite website
IETF is the premier Internet standards body, developing open standards through open processes.
AuthIndicators Working GroupChairVisite website
AuthIndicators Working Group works to create a richer, more trustworthy inbox experience for all email users worldwide while increasing the use of authentication to reduce email fraud and is the creator of the Brand Indicators for Message Identification (BIMI) standard.
Anti-Phishing Working GroupContributorVisite website
APWG is an international coalition unifying the global response to cybercrime across industry, government and law-enforcement sectors, and NGO communities.
Internet SocietyMemberVisite website
ISOC provides an organizational home and financial support for the Internet standards evolution process.
Online Trust AllianceMemberVisite website
OTA is an initiative within the Internet Society (ISOC), a global non-profit with the mission to promote the open development, evolution, and use of the Internet for the benefit of all people throughout the world.
Global Cyber AllianceMemberVisite website
GCA is an international, cross-sector effort dedicated to eradicating cyber risk and improving our connected world.
Certified Senders AllianceMemberVisite website
CSA acts as a neutral interface between mailbox providers and senders of commercial emails.
Trusted Domain ProjectContributorVisite website
The TDP produces open source products and open standards in support of improving trust in the use of domain names.
DMARC.org promotes the use of DMARC and related email authentication technologies to reduce fraudulent email, in a way that can be sustained at Internet scale.
OpenDKIM is maintained by Valimail. We contribute code to support the evaluation and reporting of ARC to this TDP software that supports 100’s of millions of mailboxes.
Valimail wrote this password policy enforcement extension for devise-gem, which is a flexible authentication solution for Rails based on Warden.
Coppertone, written and maintained by Valimail, provides a Sender Policy Framework (SPF) toolkit for Ruby and includes tools for parsing SPF DNS records, evaluating the result of SPF checks for received emails, and creating appropriate email headers from the SPF result.
Authentication HeadersVisite website
Authentication Headers, written and maintained by Valimail, is a Python library for the generation of email authentication headers. The library can perform DKIM, SPF, DMARC, and ARC validation and generate and affix the corresponding headers.
Sympa is an electronic mailing list manager used to automate list management functions such as subscription, moderation and management of archives.
DNSAdapter contains a set of useful adapter classes that present a common set of return types and errors for DNS services. This adapter layer makes it simple to swap in different DNS providers and was written by Valimail.
Created and maintained by Valimail, Postshiftprovides an Amazon Redshift extension for ActiveRecord 5 (Rails 5) PostgreSQL adapter based off of the existing activerecord5-redshift-adapter.
Mailman ARC patchVisite website
Valimail built the Mailman ARC patch, which provides ARC functionality for Mailman 3. Mailman is one of the most widely deployed mailing list management software in the world.
Valimail maintains OpenDMARC and contributes code to support the evaluation and reporting of ARC. OpenDMARC is a community effort to develop and maintain an open source package for providing DMARC report generation and policy enforcement services.
ARC test suiteVisite website
Written by Valimail, the ARC Test Suite is an informal schema for the open source test suites for the Authenticated Received Chain(ARC)protocol, illustrated with examples
OpenARC is a community effort to develop and maintain an open source library for producing ARC-aware applications, and a “milter”-based filter for providing ARC service. Valimail has contributed, tested, and managed the completion of this project.
Valimail contributed code that supports ARC within Mail::DKIM, which implements the various components of the DKIM and DomainKeys message-signing and verifying standards for Internet mail.
dkimpy is a Python module that implements DKIM (DomainKeys Identified Mail) email signing and verification. It also provides helper scripts for command line signing and verification. Valimail contributions support ARC functionality and bug fixes as the standard evolves.
Dalli is high performance, pure Ruby client for accessing memcached servers and is maintained by Valimail.
DomainKeys Identified Mail (DKIM CRypto UPdate) working group is chartered to update DomainKeys Identified Mail (DKIM, RFC 6376) to handle more modern cryptographic algorithms and key sizes. As shepherds of DCRUP (RFC 8301), Valimail played a key role in the publishing and availability of this standard. We advocate for cryptographic updates that make DKIM stronger.
The Authenticated Received Chain (ARC) protocol allows Internet Mail Handlers to attach assertions of message authentication state to individual messages. As messages traverse ARC-enabled Internet Mail Handlers, additional ARC assertions can be attached to messages to form ordered sets of ARC assertions that represent authentication state along each step of message handling paths. Valimail and Google are two of the editors of the ARC specification. Together, we are working to build ARC as a supplemental but crucial piece of the current DMARC standard.