Re: SPF Record Issue
Scott Kitterman <[email protected]> Thu, 12 Sep 2013 22:52:25 -0400
| Newsgroups | gmane.mail.spam.spf.discuss |
|---|---|
| Message-ID | <1826971.E5P0SbBIjl@scott-latitude-e6320> |
It's a matter of local policy for the receiver. There no standard. RFC 4408 is, intentionally, very light on receiver policy. Scott K On Thursday, September 12, 2013 14:52:29 Roman Gelfand wrote: > consider the follwoing situation... > > A user sends email with from: address as [email protected]. The > domain.com doesn't have spf txt record. The smtp server used to send > this email is mx1.anotherdomai.com. This domain has spf txt record. > Are you saying spf checker on the destination smtp server is going to > know to check the source smtp host for spf txt record? If so, what > happens when there is clash between domain.com's spf txt record and > that of mx1.anotherdomai.com where domain.com forbids the smtp host > from sending the email and mx1.anotherdomai.com allows? In terms of > not ending up in the destination spam box, which one is more preferred > by the spf checker? spf txt record for domain.com or > mx1.anotherdomai.com? > > On Tue, Sep 10, 2013 at 7:18 AM, alan <[email protected]> wrote: > > At 01:04 10/09/2013 Tuesday, you wrote: > >>On 09/09/2013 07:22 PM, Roman Gelfand wrote: > >>>thanks for all the help. I still have a couple of questions... > >>> > >>>1. Can you have more than 1 spf txt records for a domain? > >> > >>Absolutely not. > >> > >>>2. What does putting host name before v=spf1 do for us? is that > >>>somehow used in conjunction with helo? Can you have multiple host > >>>names separated by spaces before v=spf1? > >> > >>That is the syntax used by the BIND family of DNS servers used to indicate > >>which domain the record is for. The syntax used by your DNS server may > >>vary. The BIND syntax is the canonical syntax used for discussing DNS > >>records via email. You should learn it.>> > >>>3. I am not quite sure what you mean by ... > >>>if they are the same machine then you should investigate and compile a > >>>list of all its ips so that you can pass the common (does helo == > >>>ip-in-A-of-helo test many receivers perform to weed out bots) > >>>could you give an example. > >> > >>Suppose the mail server uses mail1.example.com as its HELO name, and has > >>IPs 192.0.2.1 and 198.51.100.3 (is on two different ISPs). Then the HELO > >>SPF record could be > >> > >>mail1.example.com IN TXT "v=spf1 ip4:192.0.2.1 ip4:198.51.100.3 -all" > >> > >>Or possibly: > >> > >>mail1.example.com IN TXT "v=spf1 a -all" > >> > >> IN A 192.0.2.1 > >> IN A 198.51.100.3 > > > > or to put it another way every hostname IS a domain (in dns terms) > > > > thus in my case the SPF for my example domain (below) > > as my real SPF records are to complex/experimental and the domains are to > > > > but feel free to actually check the real domains alandoherty.net and > > alan.gothic.ie and the provider domain orionnetworks.ie that the servers > > are part of > > > > but basically their are 3 mailservers > > and in this example i have given one 2 ips (all ips are my own so should > > not annoy anyone) (but as all are well secured by automatons probing them > > may result in autoblacklisting) > > > > example.com IN A 193.120.238.106 ;my > > webserver/mailserver > > > > IN MX 10 mx10.example.com ;my mailservers > > answering/25 helo-id and TLS cert IN MX 20 > > mx20.example.com ;my other mailservers answering/25 > > helo-id and TLS cert IN MX 20 mx30.example.com ;my > > other mailservers answering/25 helo-id and TLS cert> > > IN TXT "v=spf1 ip4:193.120.238.109 ip4:193.120.238.106 > > ip4:195.2.202.63 ip4:195.2.202.40 -all"> > > IN TXT "spf2.0/mfrom ip4:193.120.238.109 ip4:193.120.238.106 > > ip4:195.2.202.63 ip4:195.2.202.40 -all"> > > IN TXT "spf2.0/pra ip4:193.120.238.109 ip4:193.120.238.106 > > ip4:195.2.202.63 ip4:195.2.202.40 ?all"> > > ;last 2 lines just for the broken sender-id checkers > > to ensure they do not block mail via mailinglists> > > www.example.com IN A 193.120.238.106 ;my webserver > > > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > some-desktop.example.com IN A 193.120.xx.xx ;a machine > > > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > support.example.com IN A 193.120.238.106 ;another website > > > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > smtps.example.com IN A 193.120.238.106 ;my mailservers > > answering/587 helo-id and TLS cert> > > IN A 193.120.238.109 ;used by clients to > > send/relay mail outward > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > mx10.example.com IN A 193.120.238.109 ;my mailserver > > incomming> > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > mx20.example.com IN A 193.120.238.106 ;my mailserver > > incomming> > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > mx30.example.com IN A 195.2.202.63 ;my mailserver > > incomming> > > IN A 195.2.202.40 > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > host1.example.com IN A 193.120.238.106 ;my PTR record > > > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > host2.example.com IN A 193.120.238.109 ;my PTR record > > > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > host3.example.com IN A 195.2.202.64 ;my PTR record > > > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > host3a.example.com IN A 195.2.202.40 ;my PTR record > > > > IN MX 0 . ;explicitly states > > not ever legal user@xxx > > IN TXT "v=spf1 -all" ;explicitly states > > not ever legal to spf > > > > host1.mxout.example.com IN A 193.120.238.106 ;my mailservers > > outgoing/sending helo-id and> > > ;where postmaster@ > > messages come > > from > > > > IN MX 10 mx10.example.com > > IN MX 20 mx20.example.com > > > > IN TXT "v=spf1 ip4:193.120.238.106 -all" ;explicitly > > states IT IS legal to spf> > > host2.mxout.example.com IN A 193.120.238.109 ;my mailservers > > outgoing/sending helo-id and> > > ;where postmaster@ > > messages come > > from > > > > IN MX 10 mx10.example.com > > IN MX 20 mx20.example.com > > > > IN TXT "v=spf1 ip4:193.120.238.109 -all" ;explicitly > > states IT IS legal to spf> > > host3.mxout.example.com IN A 195.2.202.63 ;my mailservers > > outgoing/sending helo-id and> > > IN A 195.2.202.40 ;where postmaster@ > > messages come from > > IN MX 10 mx10.example.com > > IN MX 20 mx20.example.com > > > > IN TXT "v=spf1 ip4:195.2.202.63 ip4:195.2.202.40 -all" > > ;explicitly states IT IS legal to spf> > > _client._smtp.host1.mxout.example.com SRV 1 2 1 > > host1.mxout.example.com. _client._smtp.host2.mxout.example.com > > SRV 1 2 1 host2.mxout.example.com. > > _client._smtp.host3.mxout.example.com SRV 1 2 1 > > host3.mxout.example.com. > > > > _client._smtp.example.com SRV 1 1 1 example.com. > > > > ;the _client._smtp lines authorised the three listed names to be used in > > helo and deauthorise any other using an old/unused protocol called csv, > > but as it costs nothing i still use it as it was well designed > > > > <http://en.wikipedia.org/wiki/Certified_Server_Validation>http://en.wikipe > > dia.org/wiki/Certified_Server_Validation