D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] SPF and false positives

 

On Thu, 1 Apr 2010, John Horne wrote:

On Thu, 2010-04-01 at 13:22 +0100, Simon Waters wrote:

We forward a lot of email without rewriting envelope sender

Which is why rejecting failed SPF is not a good idea. We didn't, but do
now, rewrite sender addresses, although we had no complaints before.

Different situations though - the university knows what emails address it's "clients" have - hosting ISPs may not... And it's not uncommon for punters to use one ISP that they have email with to send email from all accounts & email addresses they have... smtp-auth and off you go...

Because SPF is broken by design, it rejects too much genuine email, so
almost no one rejects outright.

We will reject mail outright if the SPF record states only '-all'. We've
had no complaints about that.

I'm sure paying customers would complain though...

Gordon

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/linux_adm/list-faq.html