On Mon, 2017-06-05 at 13:32 -0700, Autumn Tyr-Salvia wrote:
> Hello,
> A customer of mine is trying to get DMARC set up on a given domain,
> and has set up aligned SPF on their corporate mail server.
> Unfortunately, we're seeing an issue, and I'm looking for advice on a
> resolution.
>
> When someone sets up an out of office autoresponder on the corporate
> mail server, those messages are not configured to use a return-path
> address. My understanding is that this is the RFC-correct way to do
> that.
>
> Unfortunately, when you do that, SPF evaluation then defaults to the
> HELO domain. Since this customer is using a hosted email service
> provider, the HELO domain belongs to their email provider and not
> them, which in turn kills their alignment. Thus, DMARC failures on all
> autoresponders.
>
> Thoughts on the best resolution for something like this?
The resolution is to DKIM-sign all mail before turning on DMARC.
SPF can't pass on forwarded messages, and the sender doesn't control
which messages get forwarded or not, the receiver does. Lots of email
gets forwarded to Gmail, for instance. And, of course, you have your
auto-responder issue - which can never pass SPF, because the identifier
has to be aligned with the From: address to pass DMARC.
_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop