Re: How do you handle SPF errors?
Sam Varshavchik <[email protected]>
| Newsgroups | gmane.mail.imap.courier.general |
|---|---|
| Message-ID | <[email protected]> |
Alessandro Vesely writes: > Hi all, > > I received a #@[] bounce for a non-existing [email protected]. I host > cavaliere.it. The domain has spf-all. That Noreply asked for a positive > DSN, which was sent and then bounced to me. The original message should > have been blocked, but they managed to generate an error, and I accept > "error" in BOFHSPFMAILFROM (and "all" in BOFHSPFFROM). > > I have the message header from the bounce. I only copy Received-SPF lines: > > Received-SPF: error (Address does not pass the Sender Policy Framework) > SPF=HELO; > sender=cavaliere.it; > remoteip=64.188.19.148; > remotehost=; > helo=cavaliere.it; > receiver=wmail.tana.it; > Received-SPF: error (Address does not pass the Sender Policy Framework) > SPF=MAILFROM; > [email protected]; > remoteip=64.188.19.148; > remotehost=; > helo=cavaliere.it; > receiver=wmail.tana.it; > [...] > Received-SPF: fail (Address does not pass the Sender Policy Framework) > SPF=FROM; > [email protected]; > remoteip=64.188.19.148; > remotehost=; > helo=cavaliere.it; > receiver=wmail.tana.it; > > Any idea how they issued an error? > > Does people reject on error as well as on fail? Your SPF includes a lookup against list.dnswl.org If the lookup fails, looks like that'll be an ERROR. This is vulnerable to DNS hiccups. I think it's a random DNS hiccup. _______________________________________________ courier-users mailing list [email protected] Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQRupkKLJP96aW75pIOKYPgoojZS4gUCZWkrkQAKCRCKYPgoojZS 4rS0AQDeCfucB+viB99UT9jViMLQPTdNP9K2JxL50wYSwyY34wEApl/6GKY6Nj8F /+hroGMf4lhSImt/tNqXoBSjpFyBbwA= =wH3P -----END PGP SIGNATURE-----