Re: Problem getting python-policyd-spf to reject on Permerror

"David Jones via spf-devel" <[email protected]> Thu, 14 Dec 2017 19:03:21 -0600
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
On 12/14/2017 03:48 PM, Scott M. Parrill wrote:
> I'm rather new to working with SPF records but isn't being able
> to report incorrect SPF and DKIM records part of the purpose of
> DMARC?  Assuming they have DMARC correctly configured of course.
>=20
> Scott
>=20
>=20

Seems like most sysadmins/mail admins have just heard about SPF recently=20
when Google and other mail providers started taking SPF seriously about=20
3 years ago to put SPF soft fails into the Spam/Junk folders and=20
rejecting for SPF hard fails.

Google does do a good job to lead the way with good bounce messages with=20
links to good documentation.  I guess it's going to take Google stepping=20
up and bouncing Permerrors before sysadmins are going to fix their SPF=20
record problems and enable DMARC reporting.

DMARC is good for feedback but it takes a skilled mail admin that=20
understands the details of SPF and DKIM to setup and parse the feedback=20
XML reports.  You can outsource this report gathering and summarization=20
to companies like Dmarcian.com but it still takes some skilled analysis=20
and lots of time -- like months of gathering DMARC report feedback to=20
get an accurate picture of legit sources of email for a domain for a=20
complete SPF record.

I wish the industry as a whole would push toward making SPF records=20
mandatory with correct syntax (no Permerrors) before email would deliver=20
much like FCrDNS is pretty much mandatory these days.

Then we would move on to DKIM, DMARC and ARC...

--=20
David Jones