For future reference if you want to start a new thread, compose a new
email to the list address. Don't reply to a random post and replace the
subject and body. Traditional threading is based on headers, and isn't
affected by changing the subject.

On Fri, 30 Oct 2020 16:02:52 +0100
Marc Roos wrote:

>  
> I had a phishing mail skip my spf check. The spf check was done on
> the Return-Path and not the From:. Is a default convention? 

It's not a convention, it's part of the original specification and now
the RFC. SPF runs against the envelope sender, with the helo hostname as
a secondary check.

SPF_PASS has only a nominal score, with SPF whitelisting you are
whitelisting the envelope address, so it doesn't matter hugely.


> How does 
> spamassassin treat a different Return-Path and From in a message? 

There are some meta rules that involve a comparison.



Reply via email to