> On Jun 5, 2017, at 1:41 PM, Philip Paeps <[email protected]> wrote:
> 
> On 2017-06-05 13:32:59 (-0700), Autumn Tyr-Salvia <[email protected]> wrote:
>> A customer of mine is trying to get DMARC set up on a given domain, and has 
>> set up aligned SPF on their corporate mail server. Unfortunately, we're 
>> seeing an issue, and I'm looking for advice on a resolution.
>> 
>> When someone sets up an out of office autoresponder on the corporate mail 
>> server, those messages are not configured to use a return-path address. My 
>> understanding is that this is the RFC-correct way to do that.
>> 
>> Unfortunately, when you do that, SPF evaluation then defaults to the HELO 
>> domain. Since this customer is using a hosted email service provider, the 
>> HELO domain belongs to their email provider and not them, which in turn 
>> kills their alignment. Thus, DMARC failures on all autoresponders.
>> 
>> Thoughts on the best resolution for something like this?

I’d go for an aligned DKIM signature. Or use an actual return-path for the 
bounces. 

> Put the mail provider's HELO names in your SPF record?  The SPF record should 
> list all the mail servers that send mail on behalf of a domain.

That’s not going to help as it’s not in the same organizational space as the 
5322.from.

laura 


-- 
Having an Email Crisis?  800 823-9674 

Laura Atkins
Word to the Wise
[email protected]
(650) 437-0741          

Email Delivery Blog: http://wordtothewise.com/blog      






_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Reply via email to