Re: Problem getting python-policyd-spf to reject on Permerror
"David Jones via spf-devel" <[email protected]> Thu, 14 Dec 2017 19:03:21 -0600
| Newsgroups | gmane.mail.spam.spf.devel |
|---|---|
| Message-ID | <[email protected]> |
On 12/14/2017 03:48 PM, Scott M. Parrill wrote: > I'm rather new to working with SPF records but isn't being able > to report incorrect SPF and DKIM records part of the purpose of > DMARC? Assuming they have DMARC correctly configured of course. >=20 > Scott >=20 >=20 Seems like most sysadmins/mail admins have just heard about SPF recently=20 when Google and other mail providers started taking SPF seriously about=20 3 years ago to put SPF soft fails into the Spam/Junk folders and=20 rejecting for SPF hard fails. Google does do a good job to lead the way with good bounce messages with=20 links to good documentation. I guess it's going to take Google stepping=20 up and bouncing Permerrors before sysadmins are going to fix their SPF=20 record problems and enable DMARC reporting. DMARC is good for feedback but it takes a skilled mail admin that=20 understands the details of SPF and DKIM to setup and parse the feedback=20 XML reports. You can outsource this report gathering and summarization=20 to companies like Dmarcian.com but it still takes some skilled analysis=20 and lots of time -- like months of gathering DMARC report feedback to=20 get an accurate picture of legit sources of email for a domain for a=20 complete SPF record. I wish the industry as a whole would push toward making SPF records=20 mandatory with correct syntax (no Permerrors) before email would deliver=20 much like FCrDNS is pretty much mandatory these days. Then we would move on to DKIM, DMARC and ARC... --=20 David Jones