Re: OpenSPF Why Page and SPF record types

Richard Lawley <[email protected]> Thu, 1 Aug 2013 11:39:11 +0100
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <CAPEApXJevFC3AT5zNyOvBAYZ8pufe+W6F=y1kJL8u6ZwbBkg8w@mail.gmail.com>
--001a11c2f63ae70fc904e2e07341
Content-Type: text/plain; charset=ISO-8859-1

Alan,

Actually my suggestion requires NO changes to the API.  It was a suggestion
that the WHY diagnostic page would display the record it used in displaying
the message - nothing to do with the data being passed in the URL, or any
changes to the MTA.  The WHY page does its own check using the parameters
supplied in the URL and displays the results.  My suggestion is just to add
extra information to these results - the value of the SPF/TXT record
retrieved in order to do the check.

For example, I went to the WHY page using the link from my bounce before,
and it said there was a problem.  If I visit the same link now after fixing
my DNS records, it says that there is no reason for a bounce - the page
looks up my SPF record on the fly.

I'm aware that SPF records will be used if they exist before TXT records,
and I was not suggesting that SPF libraries should behave any differently,
and definitely should not do more DNS lookups than necessary.  Diagnostic
tools, however, are a different matter and that's where I was suggesting
the change be made.  The WHY page already returns more information than
your SPF library would return to the MTA (e.g. enough information to
explain the ~all/-all setting on the record it examined).

The DNS server software concerned is Simple DNS, which has a feature where
it will synthesise SPF records if none are present, and another to
synthesis a TXT record to match a SPF record if only one is present (though
not the other way around).  The provider previously did not support editing
of SPF records, but in response to my support request has enabled this
request.  The problem therefore is no longer an issue for me, but I was
trying to make suggestions which may help others in the same situation.

Regards,

Richard


On 1 August 2013 10:09, alan <[email protected]> wrote:

> At 09:19 01/08/2013  Thursday, Richard Lawley wrote:
> >Hi,
> >
> >I'm not sure if anyone on here is responsible for or involved with the
> OpenSPF WHY page.
>
> i am not the maintainer
> but i can clearly see in
> http://www.openspf.org/Why/API
>
> that your request would be impossible
> as it would require at least 4 more fields
>
> that would require both modification to spf-librarys (to provide the
> information to users)
> and the website to allow users to pass it on
>
> a did i lookup spf or txt
> b ip of your dns server i looked up
> c "full strng of the spf record I obtained"
>
> and none of these pieces of information are available to the person
> constructing the link
>
> as my MTA would be the software making the call to the spf-library
> supplying mfrom or hostname, ip-recieved-from
> and receiving a reply of pass/fall/neutral/hardfail/softfail +
> "spf-writers-exp-txt" as output
>
> and then constructing the url knowing only the data above + my own
> hostname and that I'm using spfv1
> (as no one sane allows the use of M$-sender-ID aka v2)
>
>
> >I just spent quite some time tracking down a problem with SPF records on
> one of my domains, which ended up being down to the DNS software my DNS
> host uses serving a synthesised SPF type record.  This was invisible
> through their editor, and is also hard to query since support for the
> record type was not in the version of dig which I was initially using, nor
> does nslookup support it in Windows.  The problem also compounded by them
> serving different synthesised results from both of the nameservers, one of
> them ending in -all and the other ~all.
>
> I would suggest this is such an uncommon problem as to not warrent a
> solution
> (simply drop any provider crazy enough to, A use software that adds
> anything to your DNS without your consent/knowledge, B neither maintain the
> software so both servers are consistent in results, C fails to inform you
> of the software clearly, the Internet is a big place with many providers do
> not support anyone incapable of doing their job well and responsibly, and
> DNS is too key to leave in the hands of incompetents)
>
> >This is clearly a niche situation - for a message to be bounced it had to
> be checked by an SPF implementation that took SPF-type records instead of
> TXT-type records
>
> there are many (actually many will first check spf, then if none check txt)
> those many are (luckily for you) limited to the capabilities of the
> resolving DNS servers they use
> (as many of those resolvers do-not handle spf, so the library then goes on
> to txt after it gets an error in response to its initial spf lookup)
>
> >, and it had to have been served by the DNS server with the -all record.
>  However, less of a niche situation would be where SPF and TXT records both
> exist but do not match.
>
> in either case the first returned spf will always be the one used
> (as one of the things any library attempts to do is limit the number of
> queries it will make, so if it does spf and txt, it will only try the
> second one if it does not get a response from the first)
>
> It is/was safely assumed that if spf and txt records both exist the admin
> would have sole responsibility for ensuring both were accurate, error free
> and identical.
>
> If you could name the provider and what dns tool/software is doing this
> heinous act it would be appreciated, as sort of providers/software we could
> all do with being warned against accidentally using
>
>
> >One of the bounce messages has directed me to the OpenSPF WHY page, which
> was showing me that the message didn't match my SPF record, but that it
> shouldn't have stopped the message (presumably it had hit the server with
> the ~all record).  What I would like to suggest is that the record checker
> prints the contents of the SPF record it retrieved (and ideally the type of
> record it is!) in order to make it more obvious what was going on.
> >
> >Additional diagnostic steps could potentially be added, such as showing
> that conflicting SPF and TXT records exist, but my first suggestion would
> have helped me solve this a lot.  Just hoping that this can help someone
> else in a similar situation!
> >
> >Regards,
> >
> >Richard
> >
> >Sender Policy Framework: <http://www.openspf.net>http://www.openspf.net
> >Modify Your Subscription: <http://www.listbox.com/member/>
> http://www.listbox.com/member/
> ><https://www.listbox.com/member/archive/735/=now>Archives<
> https://www.listbox.com/member/archive/rss/735/13124949-ec5a0568> | <
> https://www.listbox.com/member/?&>Modify Your Subscription | <
> https://www.listbox.com/unsubscribe/?&&post_id=20130801041958:23FDF6DA-FA83-11E2-9291-F76E11191F9C>Unsubscribe
> Now<http://www.listbox.com>
>
>
>
> -------------------------------------------
> Sender Policy Framework: http://www.openspf.net [http://www.openspf.net]
> Modify Your Subscription: http://www.listbox.com/member/ [
> http://www.listbox.com/member/]
>
> Archives: https://www.listbox.com/member/archive/735/=now
> RSS Feed: https://www.listbox.com/member/archive/rss/735/24836610-4f4eb4b5
> Modify Your Subscription:
> https://www.listbox.com/member/?&
> Unsubscribe Now:
> https://www.listbox.com/unsubscribe/?&&post_id=20130801051108:4B237CEC-FA8A-11E2-B638-85190246559F
> Powered by Listbox: http://www.listbox.com
>



-------------------------------------------
Sender Policy Framework: http://www.openspf.net [http://www.openspf.net]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/735/=now
RSS Feed: https://www.listbox.com/member/archive/rss/735/6959934-50ec8f89
Modify Your Subscription: https://www.listbox.com/member/?member_id=6959934&id_secret=6959934-b7c4528d
Unsubscribe Now: https://www.listbox.com/unsubscribe/?member_id=6959934&id_secret=6959934-edadf31a&post_id=20130801063922:9DB4D2D8-FA96-11E2-A370-DC1D38637AE9
Powered by Listbox: http://www.listbox.com

--001a11c2f63ae70fc904e2e07341
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Alan,<div><br></div><div>Actually my suggestion requires N=
O changes to the API. =A0It was a suggestion that the WHY diagnostic page w=
ould display the record it used in displaying the message - nothing to do w=
ith the data being passed in the URL, or any changes to the MTA. =A0The WHY=
 page does its own check using the parameters supplied in the URL and displ=
ays the results. =A0My suggestion is just to add extra information to these=
 results - the value of the SPF/TXT record retrieved in order to do the che=
ck.</div>
<div><br></div><div>For example, I went to the WHY page using the link from=
 my bounce before, and it said there was a problem. =A0If I visit the same =
link now after fixing my DNS records, it says that there is no reason for a=
 bounce - the page looks up my SPF record on the fly.</div>
<div><br></div><div>I&#39;m aware that SPF records will be used if they exi=
st before TXT records, and I was not suggesting that SPF libraries should b=
ehave any differently, and definitely should not do more DNS lookups than n=
ecessary. =A0Diagnostic tools, however, are a different matter and that&#39=
;s where I was suggesting the change be made. =A0The WHY page already retur=
ns more information than your SPF library would return to the MTA (e.g. eno=
ugh information to explain the ~all/-all setting on the record it examined)=
.</div>
<div><br></div><div>The DNS server software concerned is Simple DNS, which =
has a feature where it will synthesise SPF records if none are present, and=
 another to synthesis a TXT record to match a SPF record if only one is pre=
sent (though not the other way around). =A0The provider previously did not =
support editing of SPF records, but in response to my support request has e=
nabled this request. =A0The problem therefore is no longer an issue for me,=
 but I was trying to make suggestions which may help others in the same sit=
uation.</div>
<div><br></div><div>Regards,</div><div><br></div><div>Richard</div></div><d=
iv class=3D"gmail_extra"><br><br><div class=3D"gmail_quote">On 1 August 201=
3 10:09, alan <span dir=3D"ltr">&lt;<a href=3D"mailto:spfdiscuss@alandohert=
y.net" target=3D"_blank">[email protected]</a>&gt;</span> wrote:<b=
r>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div class=3D"im">At 09:19 01/08/2013 =A0Thu=
rsday, Richard Lawley wrote:<br>
&gt;Hi,<br>
&gt;<br>
&gt;I&#39;m not sure if anyone on here is responsible for or involved with =
the OpenSPF WHY page.<br>
<br>
</div>i am not the maintainer<br>
but i can clearly see in<br>
<a href=3D"http://www.openspf.org/Why/API" target=3D"_blank">http://www.ope=
nspf.org/Why/API</a><br>
<br>
that your request would be impossible<br>
as it would require at least 4 more fields<br>
<br>
that would require both modification to spf-librarys (to provide the inform=
ation to users)<br>
and the website to allow users to pass it on<br>
<br>
a did i lookup spf or txt<br>
b ip of your dns server i looked up<br>
c &quot;full strng of the spf record I obtained&quot;<br>
<br>
and none of these pieces of information are available to the person constru=
cting the link<br>
<br>
as my MTA would be the software making the call to the spf-library<br>
supplying mfrom or hostname, ip-recieved-from<br>
and receiving a reply of pass/fall/neutral/hardfail/softfail + &quot;spf-wr=
iters-exp-txt&quot; as output<br>
<br>
and then constructing the url knowing only the data above + my own hostname=
 and that I&#39;m using spfv1<br>
(as no one sane allows the use of M$-sender-ID aka v2)<br>
<div class=3D"im"><br>
<br>
&gt;I just spent quite some time tracking down a problem with SPF records o=
n one of my domains, which ended up being down to the DNS software my DNS h=
ost uses serving a synthesised SPF type record. =A0This was invisible throu=
gh their editor, and is also hard to query since support for the record typ=
e was not in the version of dig which I was initially using, nor does nsloo=
kup support it in Windows. =A0The problem also compounded by them serving d=
ifferent synthesised results from both of the nameservers, one of them endi=
ng in -all and the other ~all.<br>

<br>
</div>I would suggest this is such an uncommon problem as to not warrent a =
solution<br>
(simply drop any provider crazy enough to, A use software that adds anythin=
g to your DNS without your consent/knowledge, B neither maintain the softwa=
re so both servers are consistent in results, C fails to inform you of the =
software clearly, the Internet is a big place with many providers do not su=
pport anyone incapable of doing their job well and responsibly, and DNS is =
too key to leave in the hands of incompetents)<br>

<div class=3D"im"><br>
&gt;This is clearly a niche situation - for a message to be bounced it had =
to be checked by an SPF implementation that took SPF-type records instead o=
f TXT-type records<br>
<br>
</div>there are many (actually many will first check spf, then if none chec=
k txt)<br>
those many are (luckily for you) limited to the capabilities of the resolvi=
ng DNS servers they use<br>
(as many of those resolvers do-not handle spf, so the library then goes on =
to txt after it gets an error in response to its initial spf lookup)<br>
<div class=3D"im"><br>
&gt;, and it had to have been served by the DNS server with the -all record=
. =A0However, less of a niche situation would be where SPF and TXT records =
both exist but do not match.<br>
<br>
</div>in either case the first returned spf will always be the one used<br>
(as one of the things any library attempts to do is limit the number of que=
ries it will make, so if it does spf and txt, it will only try the second o=
ne if it does not get a response from the first)<br>
<br>
It is/was safely assumed that if spf and txt records both exist the admin w=
ould have sole responsibility for ensuring both were accurate, error free a=
nd identical.<br>
<br>
If you could name the provider and what dns tool/software is doing this hei=
nous act it would be appreciated, as sort of providers/software we could al=
l do with being warned against accidentally using<br>
<div class=3D"im"><br>
<br>
&gt;One of the bounce messages has directed me to the OpenSPF WHY page, whi=
ch was showing me that the message didn&#39;t match my SPF record, but that=
 it shouldn&#39;t have stopped the message (presumably it had hit the serve=
r with the ~all record). =A0What I would like to suggest is that the record=
 checker prints the contents of the SPF record it retrieved (and ideally th=
e type of record it is!) in order to make it more obvious what was going on=
.<br>

&gt;<br>
&gt;Additional diagnostic steps could potentially be added, such as showing=
 that conflicting SPF and TXT records exist, but my first suggestion would =
have helped me solve this a lot. =A0Just hoping that this can help someone =
else in a similar situation!<br>

&gt;<br>
&gt;Regards,<br>
&gt;<br>
&gt;Richard<br>
&gt;<br>
</div>&gt;Sender Policy Framework: &lt;<a href=3D"http://www.openspf.net" t=
arget=3D"_blank">http://www.openspf.net</a>&gt;<a href=3D"http://www.opensp=
f.net" target=3D"_blank">http://www.openspf.net</a><br>
&gt;Modify Your Subscription: &lt;<a href=3D"http://www.listbox.com/member/=
" target=3D"_blank">http://www.listbox.com/member/</a>&gt;<a href=3D"http:/=
/www.listbox.com/member/" target=3D"_blank">http://www.listbox.com/member/<=
/a><br>

&gt;&lt;<a href=3D"https://www.listbox.com/member/archive/735/=3Dnow" targe=
t=3D"_blank">https://www.listbox.com/member/archive/735/=3Dnow</a>&gt;Archi=
ves&lt;<a href=3D"https://www.listbox.com/member/archive/rss/735/13124949-e=
c5a0568" target=3D"_blank">https://www.listbox.com/member/archive/rss/735/1=
3124949-ec5a0568</a>&gt; | &lt;<a href=3D"https://www.listbox.com/member/?&=
amp;" target=3D"_blank">https://www.listbox.com/member/?&amp;</a>&gt;Modify=
 Your Subscription | &lt;<a href=3D"https://www.listbox.com/unsubscribe/?&a=
mp;&amp;post_id=3D20130801041958:23FDF6DA-FA83-11E2-9291-F76E11191F9C" targ=
et=3D"_blank">https://www.listbox.com/unsubscribe/?&amp;&amp;post_id=3D2013=
0801041958:23FDF6DA-FA83-11E2-9291-F76E11191F9C</a>&gt;Unsubscribe Now&lt;<=
a href=3D"http://www.listbox.com" target=3D"_blank">http://www.listbox.com<=
/a>&gt;<br>

<br>
<br>
<br>
-------------------------------------------<br>
Sender Policy Framework: <a href=3D"http://www.openspf.net" target=3D"_blan=
k">http://www.openspf.net</a> [<a href=3D"http://www.openspf.net" target=3D=
"_blank">http://www.openspf.net</a>]<br>
Modify Your Subscription: <a href=3D"http://www.listbox.com/member/" target=
=3D"_blank">http://www.listbox.com/member/</a> [<a href=3D"http://www.listb=
ox.com/member/" target=3D"_blank">http://www.listbox.com/member/</a>]<br>
<br>
Archives: <a href=3D"https://www.listbox.com/member/archive/735/=3Dnow" tar=
get=3D"_blank">https://www.listbox.com/member/archive/735/=3Dnow</a><br>
RSS Feed: <a href=3D"https://www.listbox.com/member/archive/rss/735/2483661=
0-4f4eb4b5" target=3D"_blank">https://www.listbox.com/member/archive/rss/73=
5/24836610-4f4eb4b5</a><br>
Modify Your Subscription: <a href=3D"https://www.listbox.com/member/?&amp;"=
 target=3D"_blank">https://www.listbox.com/member/?&amp;</a><br>

Unsubscribe Now: <a href=3D"https://www.listbox.com/unsubscribe/?&amp;&amp;=
post_id=3D20130801051108:4B237CEC-FA8A-11E2-B638-85190246559F" target=3D"_b=
lank">https://www.listbox.com/unsubscribe/?&amp;&amp;post_id=3D201308010511=
08:4B237CEC-FA8A-11E2-B638-85190246559F</a><br>

Powered by Listbox: <a href=3D"http://www.listbox.com" target=3D"_blank">ht=
tp://www.listbox.com</a><br>
</blockquote></div><br></div>
<div style=3D"width:auto;margin:0;padding:5px;background-color:#fff;clear:b=
oth;border-top: 1px solid #ccc;" bgcolor=3D"#ffffff">
<p style=3D'font-family:Arial,sans-serif;margin:0.5em auto'>Sender Policy F=
ramework: <a href=3D"http://www.openspf.net">http://www.openspf.net</a><br>=
=0D
Modify Your Subscription: <a href=3D"http://www.listbox.com/member/">http:/=
/www.listbox.com/member/</a></p>
<table border=3D"0" cellspacing=3D"0" cellpadding=3D"0" width=3D"100%" styl=
e=3D"background-color:#fff" bgcolor=3D"#ffffff">
  <tr>
    <td padding=3D"4px">
      <font color=3D"#333333" size=3D"1" style=3D"font-family:helvetica, sa=
ns-serif;">
      <a style=3D"text-decoration:none;color:#669933;border-bottom: 1px sol=
id #444444"
href=3D"https://www.listbox.com/member/archive/735/=3Dnow" title=3D"Go to a=
rchives for spf-discuss">Archives</a>
<a border=3D"0" style=3D"text-decoration:none;color:#669933" href=3D"https:=
//www.listbox.com/member/archive/rss/735/6959934-50ec8f89" title=3D"RSS fee=
d for spf-discuss"><img border=3D0 src=3D"https://www.listbox.com/images/fe=
ed-icon-10x10.jpg" /></a>
 | <a style=3D"text-decoration:none;color:#669933;border-bottom: 1px solid =
#444444"
href=3D"https://www.listbox.com/member/?member_id=3D6959934&id_secret=3D695=
9934-b7c4528d" title=3D"">Modify</a>
 Your Subscription | <a style=3D"text-decoration:none;color:#669933;border-=
bottom: 1px solid #444444"
href=3D"https://www.listbox.com/unsubscribe/?member_id=3D6959934&id_secret=
=3D6959934-edadf31a&post_id=3D20130801063922:9DB4D2D8-FA96-11E2-A370-DC1D38=
637AE9" title=3D"">Unsubscribe Now</a>
<td valign=3D"top" align=3D"right"><a style=3D"border-bottom:none;" href=3D=
"http://www.listbox.com">
<img src=3D"https://www.listbox.com/images/listbox-logo-small.png"
title=3D"Powered by Listbox" border=3D"0" /></a></td>

      </font>
    </td>
  </tr>
</table>
</div>

--001a11c2f63ae70fc904e2e07341--