LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-11-2023, 10:22 AM   #1
mfoley
Senior Member
 
Registered: Oct 2008
Location: Columbus, Ohio USA
Distribution: Slackware
Posts: 2,612

Rep: Reputation: 180Reputation: 180
email SPF record issue


I've been "enjoying" configuring email and DNS for the past year and a half. I thought I had things pretty well sorted out, but no. Another issue. I have a setup whereby email is hosted by Exchange:
Code:
>host cwa4502.org
cwa4502.org has address 172.67.175.38
cwa4502.org mail is handled by 0 cwa4502-org.mail.protection.outlook.com.
There is another subdomain computer, members.cwa4502.org, at a different location with IP 74.218.88.254. When I try to send an email from a user on members.cwa4502.org to my gmail account I get the following:
Code:
   ----- The following addresses had permanent fatal errors -----
<mercureytech@gmail.com>
    (reason: 550-5.7.26 This mail has been blocked because the sender is unauthenticated.)

   ----- Transcript of session follows -----
... while talking to gmail-smtp-in.l.google.com.:
>>> DATA
<<< 550-5.7.26 This mail has been blocked because the sender is unauthenticated.
<<< 550-5.7.26 Gmail requires all senders to authenticate with either SPF or DKIM.
<<< 550-5.7.26 
<<< 550-5.7.26  Authentication results:
<<< 550-5.7.26  DKIM = did not pass
<<< 550-5.7.26  SPF [cwa4502.org] with ip: [74.218.88.254] = did not pass
However, the SPF record for cwa4502.org is:
Code:
v=spf1 include:spf.protection.outlook.com include:members.cwa4502.org -all
And the IP for members.cwa4502.org is 74.218.88.254, so why did it not pass?

Last edited by mfoley; 11-11-2023 at 10:26 AM.
 
Old 11-11-2023, 12:18 PM   #2
scasey
LQ Veteran
 
Registered: Feb 2013
Location: Tucson, AZ, USA
Distribution: CentOS 7.9.2009
Posts: 5,750

Rep: Reputation: 2222Reputation: 2222Reputation: 2222Reputation: 2222Reputation: 2222Reputation: 2222Reputation: 2222Reputation: 2222Reputation: 2222Reputation: 2222Reputation: 2222
Is there an SPF record (a TXT record containing “v=spf1 …”) for the subdomain? Apparently not.
See http://www.open-spf.org/FAQ/One_record_for_each_domain/
Every domain that’s sending email needs to have an SPF record.

Also review the “include” mechanism section in
http://www.open-spf.org/SPF_Record_Syntax/

Gmail has chosen to reject all email that fails SPF. I do that too. If the sender isn’t using an authenticated mail server, I don’t need to get the email. It’s something we all should have done long ago.

Authentication doesn’t stop UCE, but (presumably) if the mail server is authenticated, the operator of that server will take appropriate action against spammers using the server.

Last edited by scasey; 11-11-2023 at 12:32 PM.
 
Old 11-11-2023, 02:28 PM   #3
mfoley
Senior Member
 
Registered: Oct 2008
Location: Columbus, Ohio USA
Distribution: Slackware
Posts: 2,612

Original Poster
Rep: Reputation: 180Reputation: 180
OK, I'll try that and report back.
 
  


Reply

Tags
email, fail, spf



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Correct SPF record for email server danjde Linux - Server 4 09-19-2016 01:49 AM
SPF record on a relayed email depam Linux - Security 1 05-22-2014 08:29 AM
Starting spf-milter: spf-milter: Milter for 'spf-milter' not found in /etc/mail/sendm Niceman2005 Linux - Software 1 07-06-2009 03:07 AM
SPF record question Sheridan Linux - Networking 0 02-16-2008 02:48 AM
SPF record macadam Linux - Security 4 05-03-2005 08:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 11:43 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration