Re: OpenSPF Why Page and SPF record types

alan <[email protected]> Thu, 01 Aug 2013 10:09:41 +0100
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
At 09:19 01/08/2013  Thursday, Richard Lawley wrote:
>Hi,
>
>I'm not sure if anyone on here is responsible for or involved with the OpenSPF WHY page.

i am not the maintainer
but i can clearly see in
http://www.openspf.org/Why/API

that your request would be impossible
as it would require at least 4 more fields

that would require both modification to spf-librarys (to provide the information to users)
and the website to allow users to pass it on

a did i lookup spf or txt
b ip of your dns server i looked up
c "full strng of the spf record I obtained"

and none of these pieces of information are available to the person constructing the link

as my MTA would be the software making the call to the spf-library
supplying mfrom or hostname, ip-recieved-from
and receiving a reply of pass/fall/neutral/hardfail/softfail + "spf-writers-exp-txt" as output

and then constructing the url knowing only the data above + my own hostname and that I'm using spfv1
(as no one sane allows the use of M$-sender-ID aka v2)


>I just spent quite some time tracking down a problem with SPF records on one of my domains, which ended up being down to the DNS software my DNS host uses serving a synthesised SPF type record.  This was invisible through their editor, and is also hard to query since support for the record type was not in the version of dig which I was initially using, nor does nslookup support it in Windows.  The problem also compounded by them serving different synthesised results from both of the nameservers, one of them ending in -all and the other ~all.

I would suggest this is such an uncommon problem as to not warrent a solution
(simply drop any provider crazy enough to, A use software that adds anything to your DNS without your consent/knowledge, B neither maintain the software so both servers are consistent in results, C fails to inform you of the software clearly, the Internet is a big place with many providers do not support anyone incapable of doing their job well and responsibly, and DNS is too key to leave in the hands of incompetents)

>This is clearly a niche situation - for a message to be bounced it had to be checked by an SPF implementation that took SPF-type records instead of TXT-type records

there are many (actually many will first check spf, then if none check txt)
those many are (luckily for you) limited to the capabilities of the resolving DNS servers they use
(as many of those resolvers do-not handle spf, so the library then goes on to txt after it gets an error in response to its initial spf lookup)

>, and it had to have been served by the DNS server with the -all record.  However, less of a niche situation would be where SPF and TXT records both exist but do not match.

in either case the first returned spf will always be the one used
(as one of the things any library attempts to do is limit the number of queries it will make, so if it does spf and txt, it will only try the second one if it does not get a response from the first)

It is/was safely assumed that if spf and txt records both exist the admin would have sole responsibility for ensuring both were accurate, error free and identical.

If you could name the provider and what dns tool/software is doing this heinous act it would be appreciated, as sort of providers/software we could all do with being warned against accidentally using


>One of the bounce messages has directed me to the OpenSPF WHY page, which was showing me that the message didn't match my SPF record, but that it shouldn't have stopped the message (presumably it had hit the server with the ~all record).  What I would like to suggest is that the record checker prints the contents of the SPF record it retrieved (and ideally the type of record it is!) in order to make it more obvious what was going on.
>
>Additional diagnostic steps could potentially be added, such as showing that conflicting SPF and TXT records exist, but my first suggestion would have helped me solve this a lot.  Just hoping that this can help someone else in a similar situation!
>
>Regards,
>
>Richard
>
>Sender Policy Framework: <http://www.openspf.net>http://www.openspf.net
>Modify Your Subscription: <http://www.listbox.com/member/>http://www.listbox.com/member/
><https://www.listbox.com/member/archive/735/=now>Archives<https://www.listbox.com/member/archive/rss/735/13124949-ec5a0568> | <https://www.listbox.com/member/?&>Modify Your Subscription | <https://www.listbox.com/unsubscribe/?&&post_id=20130801041958:23FDF6DA-FA83-11E2-9291-F76E11191F9C>Unsubscribe Now<http://www.listbox.com>