Re: I have a question concerning the spf
On 24.08.09 12:04, Faehl, Chris wrote: You've specified your policy as neutral in your SPF record with ?all. Try -all, or +all if you're not ready to put some meat on your SPF plate. I'd object against use of +all, I've read reports about spammers using that to exploit the SPF system. I'd advise going to ~all or -all, depending on configuration of his mail systems. -Original Message- From: bind-users-boun...@lists.isc.org [mailto:bind-users-boun...@lists.isc.org] On Behalf Of fakessh Sent: Monday, August 24, 2009 10:32 AM To: Bind users; Bind users Subject: I have a question concerning the spf I use bind, and I have a configuration that seems normal to me on my server Here fakessh.eu. IN MX 10fakessh.eu. fakessh.eu. IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu ?all add SPF record with the same content. problem is when I'm trying to configure my mail server via check-a...@verifier.port25.com and check-au...@verifier.port25.com spf field is marked as neutral, also follows senderid as neutral how to have the SPF OK, knowing that neutral is not really an answer Please move this discussion to SPF community mailing lists. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. -- Benjamin Franklin, 1759 ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users
I have a question concerning the spf
I use bind, and I have a configuration that seems normal to me on my server Here fakessh.eu. IN MX 10fakessh.eu. fakessh.eu. IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu ?all problem is when I'm trying to configure my mail server via check-a...@verifier.port25.com and check-au...@verifier.port25.com spf field is marked as neutral, also follows senderid as neutral how to have the SPF OK, knowing that neutral is not really an answer I have enclosed a return from this location check-au...@verifier.port25.com This message is an automatic response from Port25's authentication verifier service at verifier.port25.com. The service allows email senders to perform a simple check of various sender authentication mechanisms. It is provided free of charge, in the hope that it is useful to the email community. While it is not officially supported, we welcome any feedback you may have at verifier-feedb...@port25.com. Thank you for using the verifier, The Port25 Solutions, Inc. team == Summary of Results == SPF check: neutral DomainKeys check: pass DKIM check: pass Sender-ID check: neutral SpamAssassin check: ham == Details: == HELO hostname: r13151.ovh.net Source IP: 94.23.60.214 mail-from: fake...@fakessh.eu -- SPF check details: -- Result: neutral (SPF-Result: Neutral) ID(s) verified: smtp.mail=fake...@fakessh.eu DNS record(s): fakessh.eu. 38400 IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu ?all fakessh.eu. 38400 IN MX 10 fakessh.eu. fakessh.eu. 38400 IN A 87.98.186.232 fakessh.eu. 38400 IN MX 10 fakessh.eu. fakessh.eu. 38400 IN A 87.98.186.232 -- DomainKeys check details: -- Result: pass ID(s) verified: header.from=fake...@fakessh.eu DNS record(s): mail._domainkey.fakessh.eu. 38400 IN TXT k=rsa;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9fPmEi5XsPtXlqwyWX0sho5YXtCz+YVTS8EbKTFn6POlxMgAj6x/FjMEv2TnRm02AEXMK6we68pWR+SkEufjwQ+7zGpOp2wdLLLNBjatX/bzxQoQmpOuQJzA9hi9NTShZLM4TJVdTCBIp62M0ryHmeW2GiFOrw+8mX5x3nNt7BQIDAQAB -- DKIM check details: -- Result: pass (matches From: fake...@fakessh.eu) ID(s) verified: header.d=fakessh.eu Canonicalized Headers: From:'20'fake...@fakessh.eu'20'fake...@fakessh.eu'0D''0A' To:'20'check-a...@verifier.port25.com,'0D''0A' '20'check-au...@verifier.port25.com'0D''0A' Date:'20'Mon,'20'24'20'Aug'20'2009'20'18:17:05'20'+0200'0D''0A' MIME-Version:'20'1.0'0D''0A' Content-Type:'20'text/plain;'0D''0A' '20''20'charset=us-ascii'0D''0A' Content-Transfer-Encoding:'20'7bit'0D''0A' Message-Id:'20'200908241817.06403.fake...@fakessh.eu'0D''0A' DKIM-Signature:'20'v=1;'20'a=rsa-sha1;'20'c=simple;'20'd=fakessh.eu;'20'h=from:to:date'0D''0A' '09':mime-version:content-type:content-transfer-encoding:message-id;'0D''0A' '09''20's=mail;'20'bh=uoq1oCgLlTqpdDX/iUbLy7J1Wic=;'20'b= Canonicalized Body: '0D''0A' DNS record(s): mail._domainkey.fakessh.eu. 38400 IN TXT k=rsa;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9fPmEi5XsPtXlqwyWX0sho5YXtCz+YVTS8EbKTFn6POlxMgAj6x/FjMEv2TnRm02AEXMK6we68pWR+SkEufjwQ+7zGpOp2wdLLLNBjatX/bzxQoQmpOuQJzA9hi9NTShZLM4TJVdTCBIp62M0ryHmeW2GiFOrw+8mX5x3nNt7BQIDAQAB NOTE: DKIM checking has been performed based on the latest DKIM specs (RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for older versions. If you are using Port25's PowerMTA, you need to use version 3.2r11 or later to get a compatible version of DKIM. -- Sender-ID check details: -- Result: neutral (SPF-Result: Neutral) ID(s) verified: header.from=fake...@fakessh.eu DNS record(s): fakessh.eu. 38400 IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu ?all fakessh.eu. 38400 IN MX 10 fakessh.eu. fakessh.eu. 38400 IN A 87.98.186.232 fakessh.eu. 38400 IN MX 10 fakessh.eu. fakessh.eu. 38400 IN A 87.98.186.232 -- SpamAssassin check details: -- SpamAssassin v3.2.5 (2008-06-10) Result: ham (2.7 points, 5.0 required) pts rule name description -- -- 0.7 SPF_NEUTRAL SPF: sender does not match SPF record (neutral) -2.6
RE: I have a question concerning the spf
You've specified your policy as neutral in your SPF record with ?all. Try -all, or +all if you're not ready to put some meat on your SPF plate. -- Chris Faehl Hosting Engineering Systems Manager, RightNow Technologies -Original Message- From: bind-users-boun...@lists.isc.org [mailto:bind-users-boun...@lists.isc.org] On Behalf Of fakessh Sent: Monday, August 24, 2009 10:32 AM To: Bind users; Bind users Subject: I have a question concerning the spf I use bind, and I have a configuration that seems normal to me on my server Here fakessh.eu. IN MX 10fakessh.eu. fakessh.eu. IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu ?all problem is when I'm trying to configure my mail server via check-a...@verifier.port25.com and check-au...@verifier.port25.com spf field is marked as neutral, also follows senderid as neutral how to have the SPF OK, knowing that neutral is not really an answer I have enclosed a return from this location check-au...@verifier.port25.com This message is an automatic response from Port25's authentication verifier service at verifier.port25.com. The service allows email senders to perform a simple check of various sender authentication mechanisms. It is provided free of charge, in the hope that it is useful to the email community. While it is not officially supported, we welcome any feedback you may have at verifier-feedb...@port25.com. Thank you for using the verifier, The Port25 Solutions, Inc. team == Summary of Results == SPF check: neutral DomainKeys check: pass DKIM check: pass Sender-ID check: neutral SpamAssassin check: ham == Details: == HELO hostname: r13151.ovh.net Source IP: 94.23.60.214 mail-from: fake...@fakessh.eu -- SPF check details: -- Result: neutral (SPF-Result: Neutral) ID(s) verified: smtp.mail=fake...@fakessh.eu DNS record(s): fakessh.eu. 38400 IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu ?all fakessh.eu. 38400 IN MX 10 fakessh.eu. fakessh.eu. 38400 IN A 87.98.186.232 fakessh.eu. 38400 IN MX 10 fakessh.eu. fakessh.eu. 38400 IN A 87.98.186.232 -- DomainKeys check details: -- Result: pass ID(s) verified: header.from=fake...@fakessh.eu DNS record(s): mail._domainkey.fakessh.eu. 38400 IN TXT k=rsa;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9fPmEi5XsPtXlqwyWX0sho5YXtCz+YVTS8EbKTFn6POlxMgAj6x/FjMEv2TnRm02AEXMK6we68pWR+SkEufjwQ+7zGpOp2wdLLLNBjatX/bzxQoQmpOuQJzA9hi9NTShZLM4TJVdTCBIp62M0ryHmeW2GiFOrw+8mX5x3nNt7BQIDAQAB -- DKIM check details: -- Result: pass (matches From: fake...@fakessh.eu) ID(s) verified: header.d=fakessh.eu Canonicalized Headers: From:'20'fake...@fakessh.eu'20'fake...@fakessh.eu'0D''0A' To:'20'check-a...@verifier.port25.com,'0D''0A' '20'check-au...@verifier.port25.com'0D''0A' Date:'20'Mon,'20'24'20'Aug'20'2009'20'18:17:05'20'+0200'0D''0A' MIME-Version:'20'1.0'0D''0A' Content-Type:'20'text/plain;'0D''0A' '20''20'charset=us-ascii'0D''0A' Content-Transfer-Encoding:'20'7bit'0D''0A' Message-Id:'20'200908241817.06403.fake...@fakessh.eu'0D''0A' DKIM-Signature:'20'v=1;'20'a=rsa-sha1;'20'c=simple;'20'd=fakessh.eu;'20'h=from:to:date'0D''0A' '09':mime-version:content-type:content-transfer-encoding:message-id;'0D''0A' '09''20's=mail;'20'bh=uoq1oCgLlTqpdDX/iUbLy7J1Wic=;'20'b= Canonicalized Body: '0D''0A' DNS record(s): mail._domainkey.fakessh.eu. 38400 IN TXT k=rsa;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9fPmEi5XsPtXlqwyWX0sho5YXtCz+YVTS8EbKTFn6POlxMgAj6x/FjMEv2TnRm02AEXMK6we68pWR+SkEufjwQ+7zGpOp2wdLLLNBjatX/bzxQoQmpOuQJzA9hi9NTShZLM4TJVdTCBIp62M0ryHmeW2GiFOrw+8mX5x3nNt7BQIDAQAB NOTE: DKIM checking has been performed based on the latest DKIM specs (RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for older versions. If you are using Port25's PowerMTA, you need to use version 3.2r11 or later to get a compatible version of DKIM. -- Sender-ID check details: -- Result: neutral (SPF-Result: Neutral) ID(s) verified: header.from=fake...@fakessh.eu DNS record(s): fakessh.eu. 38400 IN TXT v=spf1 ip4:94.23.60.255 mx mx:fakessh.eu ?all fakessh.eu. 38400 IN MX 10 fakessh.eu. fakessh.eu. 38400 IN A 87.98.186.232 fakessh.eu. 38400 IN MX 10 fakessh.eu