Re: Problem getting python-policyd-spf to reject on Permerror
"Leandro" <[email protected]> Fri, 15 Dec 2017 08:29:58 -0200
| Newsgroups | gmane.mail.spam.spf.devel |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--------------DBDFEC397D7DF9B4DBA46B9E
Content-Type: text/plain; charset=utf-8; format=flowed
content-transfer-encoding: quoted-printable
Em 14/12/2017 23:03, David Jones via spf-devel escreveu:
> On 12/14/2017 03:48 PM, Scott M. Parrill wrote:
>> I'm rather new to working with SPF records but isn't being able
>> to report incorrect SPF and DKIM records part of the purpose of
>> DMARC?=C2=A0 Assuming they have DMARC correctly configured of course.
>>
>> Scott
>>
>>
>
> Seems like most sysadmins/mail admins have just heard about SPF=20
> recently when Google and other mail providers started taking SPF=20
> seriously about 3 years ago to put SPF soft fails into the Spam/Junk=20
> folders and rejecting for SPF hard fails.
>
> Google does do a good job to lead the way with good bounce messages=20
> with links to good documentation.=C2=A0 I guess it's going to take Google=
=20
> stepping up and bouncing Permerrors before sysadmins are going to fix=20
> their SPF record problems and enable DMARC reporting.
>
> DMARC is good for feedback but it takes a skilled mail admin that=20
> understands the details of SPF and DKIM to setup and parse the=20
> feedback XML reports.=C2=A0 You can outsource this report gathering and=20
> summarization to companies like Dmarcian.com but it still takes some=20
> skilled analysis and lots of time -- like months of gathering DMARC=20
> report feedback to get an accurate picture of legit sources of email=20
> for a domain for a complete SPF record.
>
> I wish the industry as a whole would push toward making SPF records=20
> mandatory with correct syntax (no Permerrors) before email would=20
> deliver much like FCrDNS is pretty much mandatory these days.
Hi guys. We have a RBL project based in SPF here in Brazil:
http://spfbl.net/en/dnsbl
This is a GPL project called SPFBL. This project uses SPF technology for=20
sender validation and makes a sender reputation too:
https://github.com/leonamp/SPFBL
Many providers is correcting the customer's SPF here and the results=20
with FAIL is dropping because this result affects the origin IP=20
reputation. The SOFTFAIL causes a defer, so this result is dropping here=20
too.
>
> Then we would move on to DKIM, DMARC and ARC...
>
We are implementing DKIM validation at this moment. DMARC will be=20
implemented next year.
-------------------------------------------
Sender Policy Framework: http://www.openspf.net [http://www.openspf.net]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbo=
x.com/member/]
Archives: https://www.listbox.com/member/archive/1007/=3Dnow
RSS Feed: https://www.listbox.com/member/archive/rss/1007/6959932-f3d1312d
Modify Your Subscription: https://www.listbox.com/member/?member_id=3D69599=
32&id_secret=3D6959932-d95100fc
Unsubscribe Now: https://www.listbox.com/unsubscribe/?member_id=3D6959932&i=
d_secret=3D6959932-4aedb9c4&post_id=3D20171215052958:E415F982-E182-11E7-888=
F-FDD20A7B9A05
Powered by Listbox: http://www.listbox.com
--------------DBDFEC397D7DF9B4DBA46B9E
Content-Type: text/html; charset=utf-8
content-transfer-encoding: quoted-printable
<html><html><html><head><meta content=3D"text/html; charset=3Dutf-8" http-e=
quiv=3D"Content-Type" /></head><body bgcolor=3D"#FFFFFF" text=3D"#000000">
Em 14/12/2017 23:03, David Jones via spf-devel escreveu:<br /><blockquo=
te cite=3D"mid:[email protected]" type=3D"cite">=
On
12/14/2017 03:48 PM, Scott M. Parrill wrote:
<br /><blockquote type=3D"cite">I'm rather new to working with SP=
F records
but isn't being able
<br />
to report incorrect SPF and DKIM records part of the purpose of
<br />
DMARC? Assuming they have DMARC correctly configured of cours=
e.
<br /><br />
Scott
<br /><br /><br /></blockquote><br />
Seems like most sysadmins/mail admins have just heard about SPF
recently when Google and other mail providers started taking SPF
seriously about 3 years ago to put SPF soft fails into the
Spam/Junk folders and rejecting for SPF hard fails.
<br /><br />
Google does do a good job to lead the way with good bounce
messages with links to good documentation. I guess it's goi=
ng to
take Google stepping up and bouncing Permerrors before sysadmins
are going to fix their SPF record problems and enable DMARC
reporting.
<br /><br />
DMARC is good for feedback but it takes a skilled mail admin that
understands the details of SPF and DKIM to setup and parse the
feedback XML reports. You can outsource this report gathering a=
nd
summarization to companies like Dmarcian.com but it still takes
some skilled analysis and lots of time -- like months of gathering
DMARC report feedback to get an accurate picture of legit sources
of email for a domain for a complete SPF record.
<br /><br />
I wish the industry as a whole would push toward making SPF
records mandatory with correct syntax (no Permerrors) before email
would deliver much like FCrDNS is pretty much mandatory these
days.
<br /></blockquote><br />
Hi guys. We have a RBL project based in SPF here in Brazil:<br /><block=
quote><a class=3D"moz-txt-link-freetext" href=3D"http://spfbl.net/en/dnsbl"=
>http://spfbl.net/en/dnsbl</a><br /></blockquote>
This is a GPL project called SPFBL. This project uses SPF technology
for sender validation and makes a sender reputation too:<br /><blockquo=
te><a class=3D"moz-txt-link-freetext" href=3D"https://github.com/leonamp/SP=
FBL">https://github.com/leonamp/SPFBL</a><br /></blockquote>
Many providers is correcting the customer's SPF here and the results
with FAIL is dropping because this result affects the origin IP
reputation. The SOFTFAIL causes a defer, so this result is dropping
here too.<span class=3D"short_text" id=3D"result_box" lang=3D"en"><span=
class=3D"alt-edited"><br /></span></span><br /><blockquote cite=3D"mid:f95=
[email protected]" type=3D"cite"><br />
Then we would move on to DKIM, DMARC and ARC...
<br /><br /></blockquote><br />
We are implementing DKIM validation at this moment. DMARC will be
implemented next year.<br /><br /><div bgcolor=3D"#ffffff" id=3D"listbo=
x-footer" style=3D"width:auto;margin:0;padding:5px;background-color:#fff;cl=
ear:both;border-top: 1px solid #ccc;"><p style=3D"font-family:Arial,sans-se=
rif;margin:0.5em auto">Sender Policy Framework: <a href=3D"http://www.opens=
pf.net">http://www.openspf.net</a><br />=0D
Modify Your Subscription: <a href=3D"http://www.listbox.com/member/">http:/=
/www.listbox.com/member/</a><table bgcolor=3D"#ffffff" border=3D"0" cellpad=
ding=3D"0" cellspacing=3D"0" style=3D"background-color:#fff" width=3D"100%"=
><tr><td padding=3D"4px"><font color=3D"#333333" size=3D"1" style=3D"font-f=
amily:helvetica, sans-serif;">
<a href=3D"https://www.listbox.com/member/archive/1007/=3Dnow" style=
=3D"text-decoration:none;color:#669933;border-bottom: 1px solid #444444" ti=
tle=3D"Go to archives for spf-devel">Archives</a>
<a border=3D"0" href=3D"https://www.listbox.com/member/archive/rss/1007/695=
9932-f3d1312d" style=3D"text-decoration:none;color:#669933" title=3D"RSS fe=
ed for spf-devel"><img border=3D"0" src=3D"http://postlink.www.listbox.com/=
2444577/833487e62783d55fe81f119fb93ef644/6959932/c96a5796.jpg?uri=3DaHR0cHM=
6Ly93d3cubGlzdGJveC5jb20vaW1hZ2VzL2ZlZWQtaWNvbi0xMHgxMC5qcGc" /></a>
| <a href=3D"https://www.listbox.com/member/?member_id=3D6959932&id_secret=
=3D6959932-d95100fc" style=3D"text-decoration:none;color:#669933;border-bot=
tom: 1px solid #444444" title=3D"">Modify</a>
Your Subscription | <a href=3D"https://www.listbox.com/unsubscribe/?member=
_id=3D6959932&id_secret=3D6959932-4aedb9c4&post_id=3D20171215052958:E415F98=
2-E182-11E7-888F-FDD20A7B9A05" style=3D"text-decoration:none;color:#669933;=
border-bottom: 1px solid #444444" title=3D"">Unsubscribe Now</a><td align=
=3D"right" valign=3D"top"><a href=3D"http://www.listbox.com" style=3D"borde=
r-bottom:none;">
<img border=3D"0" src=3D"http://postlink.www.listbox.com/2444578/3379085af0=
f1cf7fc3708f04b4471ae2/6959932/c96a5796.png?uri=3DaHR0cHM6Ly93d3cubGlzdGJve=
C5jb20vaW1hZ2VzL2xpc3Rib3gtbG9nby1zbWFsbC5wbmc" title=3D"Powered by Listbox=
" /></a></td></font></td></tr></table></div></body></html></html></html>=
--------------DBDFEC397D7DF9B4DBA46B9E--