This invention relates to non-repudiation of origin method for mail proxy based on DNS
domain level certification authority. It contains 1, establishing CA, 2, establishing
level structure CA corresponded with all DNS
domain level structure, 3, generating and distributing MTA
certificate, 4, source MTA calculating Hash value H to mail to be send, making
digital signature to H by private key, said signature information is sig, 5, forming
certificate chain mcerts to
certificate from said field to root field, 5, sending {M, sig, mcerts} to next MTA, 7, identifying MTA certificate as being received by
receiver MTA, 8, taking public key from identified source certificate, identifying the
digital signature of source MTA to M by public key, 9, directly writing user mail box or sending to next MTA. Said invention realizes the forced non-repudiation of origin between MTA to MTA with convergent divergent level CA structure.