Re: Mail server lookup

Gino Cerullo <[email protected]> Sun, 29 Sep 2013 13:45:23 -0400
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
In addition to what Alan said, as a general rule of thumb, any domain or ho=
stname that publishes an =91A=91 record should have a corresponding SPF rec=
ord that tells the world whether it is allowed to send mail and, if allowed=
, what IP addresses are authorized. Otherwise all those domain/host names a=
re subject to abuse.


On 2013-09-29, at 12:00 PM, alan <[email protected]> wrote:

> At 16:03 29/09/2013  Sunday, you wrote:
>> My "send from" domain is unbeatablesale.com.  The mail server domain
>> is pmx1.unbeatablesale.biz.
>>=20
>> It appears some receiving smtp servers, microsoft, very few, require
>> the txt spf record of the sending mail server.
>=20
> as all should
>=20
>> Is this correct spf implementation?
>=20
> yes
>=20
>> If yes, do all mainstream mail providers that have spf checking check fo=
r mail server's spf txt record?=20
>=20
> unfortunately many have never even read the docs
>=20
>> The reason why I am asking is that I would rather put spf record on the =
outbound mail
>> server, ie pmx1.unbeatablesale.biz,
>=20
> you should as its easy
>=20
>> rather than on "send from" domain unbeatablesale.com.
>=20
> its not an either or, you should authenticate both, but as always you nev=
er have to use spf at all
>=20
>=20
> yes spf is used to check/prevent forgeries on both
>=20
> the helo/ehlo domain of the sending server
> AND
> the 'mail from'/envelope-sender=20
>=20
> a pass/hardfail/neutral/none/softfail on either (depending on receiver po=
licy) effects the accept/reject decision making
>=20
> some servers do not bother checking for forgeries of the helo/ehlo, some =
do
> (i know I do with spf,csv,dns and syntax checking to name a few)
> it really helps avoid a lot of bot-mail where its obvious the helo is inv=
alid
> (as few bots have a domain pointed at their ip that passes any of the abo=
ve)
> and most send mail from domians that do not use spf or do not hardfail so=
 envelope-sender checking is useless in those cases
>=20
> the reasoning is obvious
> setting up an spf for the helo domain is easy (as most mailservers only h=
ave one sending ip and there is never a need for a neutral or softfail resp=
onse)
> (protects against people claiming to send their spam via your servers)
> additionally hints that your server is potentially well-run which earns t=
rustability points with providers like myself
>=20
> setting up an spf for the envelope-sender is still advised however
> as people can and do send forgeries via otherwise legit un forged smtp se=
rvers
> and by not protecting your envelope-senders domain you would be allowing =
anyone to forge it via any other mailserver.



--
Gino Cerullo

Pixel Point Studios
21 Chesham Drive
Toronto, ON  M3M 1W6

416-247-7740