First half day of SPF tests from my domain...
Andrew W. Donoho <[email protected]> Thu, 12 Aug 2004 10:13:12 -0500
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
Folks,
Last week I shamelessly copied the spf record of Altavista into my
home domain. Yesterday, I finally got around to turning it on. Here are
the results after about 14 hours of testing.
The main DDG.com spf record is:
DDG.com IN TXT "v=spf1
+exists:CL.%{i}.FR.%{s}.HE.%{h}.null.spf.ddg.com mx a -all"
It was the record typically fetched by the three joe-jobs working my
domain yesterday:
Aug 11 18:20:17.922 queries: client 204.31.203.2#2047: query: ddg.com
IN MX
Aug 11 18:20:19.011 queries: client 204.31.203.2#2047: query: ddg.com
IN TXT
Aug 11 18:20:19.315 queries: client 204.31.203.2#2047: query:
CL.220.118.128.254.FR.preciselybdrb\@ddg.com.HE.220.118.128.254.null.spf
.ddg.com IN A
Aug 11 18:20:19.772 queries: client 204.31.203.2#2047: query: ddg.com
IN A
The first query went about as planned - get the MX, get the TXT, query
for test domain, query for A record. I am confused that there was no
query for the A record for the target of the MX record. If things are
processed in a left to right order, I would expect that query before
the bare A query. Perhaps tomorrow, after the 24 hour TTL has expired,
I will see the behavior I expect.
Aug 11 20:28:01.649 queries: client 213.180.192.168#5301: query:
FW.ddg.com IN AAAA
Aug 11 20:28:01.858 queries: client 213.180.192.168#5301: query:
ddg.com IN TXT
Aug 11 20:28:02.152 queries: client 213.180.192.168#5301: query:
CL.218.147.45.45.FR.roi87iedfl3c\@ddg.com.HE.218.147.45.45.null.spf.ddg.
com IN A
Aug 11 20:28:02.378 queries: client 213.180.192.168#5301: query:
ddg.com IN A
Aug 11 22:07:02.134 queries: client 213.180.192.168#5301: query:
CL.195.54.209.145.FR.xkc78\@ddg.com.HE.bdsm.cust.rinet.ru.null.spf.ddg.c
om IN A
Aug 12 00:14:54.605 queries: client 213.180.192.168#5301: query:
CL.217.23.17.186.FR.1evfcignz\@ddg.com.HE.adm.step.nnov.ru.null.spf.ddg.
com IN A
Aug 12 07:24:38.489 queries: client 213.180.192.168#5301: query:
CL.81.22.2.178.FR.6d4mr\@ddg.com.HE.ddg.com.null.spf.ddg.com IN A
The above represents three separate joe-job attempts on yandex.net.
Notice that the ddg.com A record is cached. The final null.spf query
shows signs of DNS spoofing. Is there is no PTR record for a sender,
then the HE field will have the numeric IP address. Notice that it
claims to be the reverse for ddg.com (which really is either
FW:66.93.83.221 or Mail:66.93.83.131).
Aug 11 18:48:57.682 queries: client 194.67.21.67#32768: query: ddg.com
IN MX
Aug 11 19:43:17.404 queries: client 194.67.21.69#32768: query: ddg.com
IN MX
Aug 11 19:43:18.211 queries: client 194.67.21.69#32768: query:
CL.201.135.197.190.FR.x6cb0e\@ddg.com.HE.dsl-201-135-197-190.prod-
infinitum.com.mx.null.spf.ddg.com IN A
Aug 12 00:33:08.781 queries: client 194.67.21.74#32768: query: ddg.com
IN MX
Aug 12 00:33:09.572 queries: client 194.67.21.74#32768: query:
CL.201.135.32.91.FR.iywrgs38x\@ddg.com.HE.dsl-201-135-32-91.prod-
infinitum.com.mx.null.spf.ddg.com IN A
Aug 12 07:12:10.634 queries: client 194.67.21.68#32768: query: ddg.com
IN MX
The above set of queries look to be incomplete. I expect the cache at
net.rol.ru is masking these effects.
Enjoy the data. I'll post more in the next few days.
Andrew
____________________________________
Andrew W. Donoho
[email protected], PGP Key ID: 0x81D0F250
+1 (512) 453-6652 (o), +1 (512) 750-7596 (m)