Hello

I have an SPF record created in DNS for my domain. In my main.cf config file
for Postfix I have the following SPF settings:

spf_received_header = yes
spf_mark_only = no

smtpd_recipient_restrictions =  peject_spf_invalid_sender,
                                              permit_spf_valid_sender,

smtpd_sender_restrictions =  reject_spf_invalid_sender,
                                           permit_spf_valid_sender


Is the above config correct to reject received emails that is NOT being
delivered from the specified IP addresses in SPF?

I basically want to reject/fail emails that are not coming from the correct
IP address specified by the domains SPF record.

Also, recently I received one of these:

This is a spf/dkim authentication-failure report for an email message
received from IP 14.16.26.208 on Sun, 11 Jan 2015 00:32:42 +0800.
Below is some detail information about this message:
 1. SPF-authenticated Identifiers: none;
 2. DKIM-authenticated Identifiers: none;
 3. DMARC Mechanism Check Result: Identifier non-aligned, DMARC mechanism
check failures;

For more information please check Aggregate Reports or mail to [hidden
email].

Feedback-Type: auth-failure
User-Agent: NtesDmarcReporter/1.0
Version: 1
Original-Mail-From: [hidden email]
Arrival-Date: Sun, 11 Jan 2015 00:32:42 +0800
Source-IP: 14.16.26.208
Reported-Domain: mydomain.com
Original-Envelope-Id: PMCowEApi0cjVLFUK2fmEQ--.1291S2
Authentication-Results: 163.com; dkim=none; spf=fail [hidden email]
Delivery-Result: delivered

Received: from qoeeisq (unknown [150.108.4.5])
    by mydomain.com with SMTP id 1UqgGfirbN2SASB9.1
    for [hidden email]; Sun, 11 Jan 2015 00:32:40 +0800
Message-ID: <2D836C2DA068C6B28993B9B4FEBCFF2D@qoeeisq>
From: "---" [hidden email]
To: [hidden email]
Subject: =?big5?B?ru+sS6tC?=
Date: Sun, 11 Jan 2015 00:32:35 +0800
MIME-Version: 1.0
Content-Type: text/plain;
    charset="big5"
Content-Transfer-Encoding: base64
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.5512
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512

Does this mean SPF has failed as it said that the delivery results says
delivered? I didn't receive this email so maybe its fake? What is the above
message?

Thank you.



--
View this message in context: 
http://postfix.1071664.n5.nabble.com/SPF-configurations-tp73872.html
Sent from the Postfix Users mailing list archive at Nabble.com.

Reply via email to