Re: I have a question concerning the spf

2009-09-03 Thread Matus UHLAR - fantomas
On 24.08.09 12:04, Faehl, Chris wrote:
 You've specified your policy as neutral in your SPF record with ?all. 
 
 Try -all, or +all if you're not ready to put some meat on your SPF plate. 

I'd object against use of +all, I've read reports about spammers using that
to exploit the SPF system. 

I'd advise going to ~all or -all, depending on configuration of his mail
systems. 

 -Original Message-
 From: bind-users-boun...@lists.isc.org 
 [mailto:bind-users-boun...@lists.isc.org] On Behalf Of fakessh
 Sent: Monday, August 24, 2009 10:32 AM
 To: Bind users; Bind users
 Subject: I have a question concerning the spf
 
 I use bind, and I have a configuration that seems normal to me on my server
 
 Here 
 fakessh.eu.   IN  MX  10fakessh.eu.
 fakessh.eu.   IN  TXT  v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu ?all

add SPF record with the same content.

 problem is when I'm trying to configure my mail server via 
 check-a...@verifier.port25.com  and check-au...@verifier.port25.com
 
 spf field is marked as neutral, also follows senderid as neutral
 
 how to have the SPF OK, knowing that neutral is not really an answer

Please move this discussion to SPF community mailing lists.
-- 
Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety. -- Benjamin Franklin, 1759
___
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


I have a question concerning the spf

2009-08-24 Thread fakessh
I use bind, and I have a configuration that seems normal to me on my server

Here 
fakessh.eu. IN  MX  10fakessh.eu.
fakessh.eu. IN  TXT  v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu ?all

problem is when I'm trying to configure my mail server via 
check-a...@verifier.port25.com  and check-au...@verifier.port25.com

spf field is marked as neutral, also follows senderid as neutral

how to have the SPF OK, knowing that neutral is not really an answer

I have enclosed a return from this location check-au...@verifier.port25.com
This message is an automatic response from Port25's authentication verifier
service at verifier.port25.com.  The service allows email senders to
perform
a simple check of various sender authentication mechanisms.  It is
provided
free of charge, in the hope that it is useful to the email community.
 While
it is not officially supported, we welcome any feedback you may have at
verifier-feedb...@port25.com.

Thank you for using the verifier,

The Port25 Solutions, Inc. team

==
Summary of Results
==
SPF check:          neutral
DomainKeys check:   pass
DKIM check:         pass
Sender-ID check:    neutral
SpamAssassin check: ham

==
Details:
==

HELO hostname:  r13151.ovh.net
Source IP:      94.23.60.214
mail-from:      fake...@fakessh.eu

--
SPF check details:
--
Result:         neutral (SPF-Result: Neutral)
ID(s) verified: smtp.mail=fake...@fakessh.eu
DNS record(s):
    fakessh.eu. 38400 IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu
?all
    fakessh.eu. 38400 IN MX 10 fakessh.eu.
    fakessh.eu. 38400 IN A 87.98.186.232
    fakessh.eu. 38400 IN MX 10 fakessh.eu.
    fakessh.eu. 38400 IN A 87.98.186.232

--
DomainKeys check details:
--
Result:         pass 
ID(s) verified: header.from=fake...@fakessh.eu
DNS record(s):
    mail._domainkey.fakessh.eu. 38400 IN TXT
k=rsa;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9fPmEi5XsPtXlqwyWX0sho5YXtCz+YVTS8EbKTFn6POlxMgAj6x/FjMEv2TnRm02AEXMK6we68pWR+SkEufjwQ+7zGpOp2wdLLLNBjatX/bzxQoQmpOuQJzA9hi9NTShZLM4TJVdTCBIp62M0ryHmeW2GiFOrw+8mX5x3nNt7BQIDAQAB

--
DKIM check details:
--
Result:         pass (matches From: fake...@fakessh.eu)
ID(s) verified: header.d=fakessh.eu
Canonicalized Headers:
    From:'20'fake...@fakessh.eu'20'fake...@fakessh.eu'0D''0A'
    To:'20'check-a...@verifier.port25.com,'0D''0A'
    '20'check-au...@verifier.port25.com'0D''0A'
    Date:'20'Mon,'20'24'20'Aug'20'2009'20'18:17:05'20'+0200'0D''0A'
    MIME-Version:'20'1.0'0D''0A'
    Content-Type:'20'text/plain;'0D''0A'
    '20''20'charset=us-ascii'0D''0A'
    Content-Transfer-Encoding:'20'7bit'0D''0A'
    Message-Id:'20'200908241817.06403.fake...@fakessh.eu'0D''0A'
   
DKIM-Signature:'20'v=1;'20'a=rsa-sha1;'20'c=simple;'20'd=fakessh.eu;'20'h=from:to:date'0D''0A'
   
'09':mime-version:content-type:content-transfer-encoding:message-id;'0D''0A'
    '09''20's=mail;'20'bh=uoq1oCgLlTqpdDX/iUbLy7J1Wic=;'20'b=

Canonicalized Body:
    '0D''0A'
    

DNS record(s):
    mail._domainkey.fakessh.eu. 38400 IN TXT
k=rsa;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9fPmEi5XsPtXlqwyWX0sho5YXtCz+YVTS8EbKTFn6POlxMgAj6x/FjMEv2TnRm02AEXMK6we68pWR+SkEufjwQ+7zGpOp2wdLLLNBjatX/bzxQoQmpOuQJzA9hi9NTShZLM4TJVdTCBIp62M0ryHmeW2GiFOrw+8mX5x3nNt7BQIDAQAB

NOTE: DKIM checking has been performed based on the latest DKIM specs
(RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for
older versions.  If you are using Port25's PowerMTA, you need to use
version 3.2r11 or later to get a compatible version of DKIM.

--
Sender-ID check details:
--
Result:         neutral (SPF-Result: Neutral)
ID(s) verified: header.from=fake...@fakessh.eu
DNS record(s):
    fakessh.eu. 38400 IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu
?all
    fakessh.eu. 38400 IN MX 10 fakessh.eu.
    fakessh.eu. 38400 IN A 87.98.186.232
    fakessh.eu. 38400 IN MX 10 fakessh.eu.
    fakessh.eu. 38400 IN A 87.98.186.232

--
SpamAssassin check details:
--
SpamAssassin v3.2.5 (2008-06-10)

Result:         ham  (2.7 points, 5.0 required)

 pts rule name              description
 --
--
 0.7 SPF_NEUTRAL            SPF: sender does not match SPF record
(neutral)
-2.6 

RE: I have a question concerning the spf

2009-08-24 Thread Faehl, Chris
You've specified your policy as neutral in your SPF record with ?all. 

Try -all, or +all if you're not ready to put some meat on your SPF plate. 

--
Chris Faehl
Hosting Engineering Systems Manager, RightNow Technologies


-Original Message-
From: bind-users-boun...@lists.isc.org 
[mailto:bind-users-boun...@lists.isc.org] On Behalf Of fakessh
Sent: Monday, August 24, 2009 10:32 AM
To: Bind users; Bind users
Subject: I have a question concerning the spf

I use bind, and I have a configuration that seems normal to me on my server

Here 
fakessh.eu. IN  MX  10fakessh.eu.
fakessh.eu. IN  TXT  v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu ?all

problem is when I'm trying to configure my mail server via 
check-a...@verifier.port25.com  and check-au...@verifier.port25.com

spf field is marked as neutral, also follows senderid as neutral

how to have the SPF OK, knowing that neutral is not really an answer

I have enclosed a return from this location check-au...@verifier.port25.com
This message is an automatic response from Port25's authentication verifier
service at verifier.port25.com.  The service allows email senders to
perform
a simple check of various sender authentication mechanisms.  It is
provided
free of charge, in the hope that it is useful to the email community.
 While
it is not officially supported, we welcome any feedback you may have at
verifier-feedb...@port25.com.

Thank you for using the verifier,

The Port25 Solutions, Inc. team

==
Summary of Results
==
SPF check:          neutral
DomainKeys check:   pass
DKIM check:         pass
Sender-ID check:    neutral
SpamAssassin check: ham

==
Details:
==

HELO hostname:  r13151.ovh.net
Source IP:      94.23.60.214
mail-from:      fake...@fakessh.eu

--
SPF check details:
--
Result:         neutral (SPF-Result: Neutral)
ID(s) verified: smtp.mail=fake...@fakessh.eu
DNS record(s):
    fakessh.eu. 38400 IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu
?all
    fakessh.eu. 38400 IN MX 10 fakessh.eu.
    fakessh.eu. 38400 IN A 87.98.186.232
    fakessh.eu. 38400 IN MX 10 fakessh.eu.
    fakessh.eu. 38400 IN A 87.98.186.232

--
DomainKeys check details:
--
Result:         pass 
ID(s) verified: header.from=fake...@fakessh.eu
DNS record(s):
    mail._domainkey.fakessh.eu. 38400 IN TXT
k=rsa;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9fPmEi5XsPtXlqwyWX0sho5YXtCz+YVTS8EbKTFn6POlxMgAj6x/FjMEv2TnRm02AEXMK6we68pWR+SkEufjwQ+7zGpOp2wdLLLNBjatX/bzxQoQmpOuQJzA9hi9NTShZLM4TJVdTCBIp62M0ryHmeW2GiFOrw+8mX5x3nNt7BQIDAQAB

--
DKIM check details:
--
Result:         pass (matches From: fake...@fakessh.eu)
ID(s) verified: header.d=fakessh.eu
Canonicalized Headers:
    From:'20'fake...@fakessh.eu'20'fake...@fakessh.eu'0D''0A'
    To:'20'check-a...@verifier.port25.com,'0D''0A'
    '20'check-au...@verifier.port25.com'0D''0A'
    Date:'20'Mon,'20'24'20'Aug'20'2009'20'18:17:05'20'+0200'0D''0A'
    MIME-Version:'20'1.0'0D''0A'
    Content-Type:'20'text/plain;'0D''0A'
    '20''20'charset=us-ascii'0D''0A'
    Content-Transfer-Encoding:'20'7bit'0D''0A'
    Message-Id:'20'200908241817.06403.fake...@fakessh.eu'0D''0A'
   
DKIM-Signature:'20'v=1;'20'a=rsa-sha1;'20'c=simple;'20'd=fakessh.eu;'20'h=from:to:date'0D''0A'
   
'09':mime-version:content-type:content-transfer-encoding:message-id;'0D''0A'
    '09''20's=mail;'20'bh=uoq1oCgLlTqpdDX/iUbLy7J1Wic=;'20'b=

Canonicalized Body:
    '0D''0A'
    

DNS record(s):
    mail._domainkey.fakessh.eu. 38400 IN TXT
k=rsa;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9fPmEi5XsPtXlqwyWX0sho5YXtCz+YVTS8EbKTFn6POlxMgAj6x/FjMEv2TnRm02AEXMK6we68pWR+SkEufjwQ+7zGpOp2wdLLLNBjatX/bzxQoQmpOuQJzA9hi9NTShZLM4TJVdTCBIp62M0ryHmeW2GiFOrw+8mX5x3nNt7BQIDAQAB

NOTE: DKIM checking has been performed based on the latest DKIM specs
(RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for
older versions.  If you are using Port25's PowerMTA, you need to use
version 3.2r11 or later to get a compatible version of DKIM.

--
Sender-ID check details:
--
Result:         neutral (SPF-Result: Neutral)
ID(s) verified: header.from=fake...@fakessh.eu
DNS record(s):
    fakessh.eu. 38400 IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu
?all
    fakessh.eu. 38400 IN MX 10 fakessh.eu.
    fakessh.eu. 38400 IN A 87.98.186.232
    fakessh.eu. 38400 IN MX 10 fakessh.eu