Robert Sterba wrote: > Based on what I've seen in ASSP SPF checking does not bypass > additional filters. It's only used to filter or add to the message > scoring based on failures.
I block SPF hardfails outright. Softfails are highly scored (80% of the block score threshold). > Looking at the SPF data for that domain (yonasite.com) ANY IP would > pass. Where did you get THAT idea from? The record for that domain says, any MX or PTR record for 'yonasite.com' is a valid sender. Anyone else sending mail as 'yonasite.com' is a softfail. The only IPs listed as permitted is 64.118.89.89, anything else is a softfail. > ::SPF rant:: Spammers can setup SPF records just as well as the rest > of the world. I've never been a big fan of it. I've never had good > luck with it with any spam filtering product. I just disable it. In > certain cases you can get false positives from it. IE Someone on a > job board submits a response to your job posting and uses their email > address. The Job site sends you the email. Then gets rejected by SPF > because the persons email domain has a SPF record which obviously > wouldn't have the Job site listed as a valid sender. Adn of course as > we see a valid record doesn't mean anything at all..... ::end rant:: First off SPF is intended to prevent spoofing, if the spammer wants to send as their own domain so be it. I can block them all the easier. If they want to sent as paypal, ebay, or amazon they would get blocked because of the SPF test. Second, if the jobsite is sending mail AS the user they deserve to get blocked, thats NOT a false positive to me. They should be sending as themselves but setting the FROM as the user, the "envelope-from" and "Return-Path" should belong to the jobsite. Kevin ------------------------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Still grepping through log files to find problems? Stop. Now Search log events and configuration files using AJAX and a browser. Download your FREE copy of Splunk now >> http://get.splunk.com/ _______________________________________________ Assp-user mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/assp-user
