LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 12-30-2013, 06:33 AM   #1
markotitel
Member
 
Registered: Feb 2009
Location: Titel - Serbia
Posts: 181

Rep: Reputation: 18
Using google MX, proper SPF record setup help.


Hi, I have some "purple haze" regarding SPF record.
I am using google MX, and have two servers which are sending mails besides using standard webmail for office usage.
One server is webserver and other is monitoring which is behind firewall located at our office and is monitoring several linux machines.

Here is SPF record that is giving headache
Quote:
v=spf1 a mx ip4:my_domain.com_ip ip4:my_office_ip include:_spf.google.com ip4:178.221.103.89 ~all
Problem I have is "strange":
- Using gmail web panel I can send mail to 99.99% domains, but to some I get message
Quote:
Technical details of temporary failure:
The recipient server did not accept our requests to connect. Learn more at http://support.google.com/mail/bin/a...py?answer=7720
[(0) smtp.my_domain.com. [My_Office_IP]:587: Connection refused]
Google aparently tries to connect to smtp.my_domain.com which resolves to my_office_ip and it cannot because there is no mailserver there (I have logged attemps and it is google IP), after that I get my email bounced back.
Now what is strange here is that I dont have any smtp.my_domain.com record, although I have wildcard record *.my_domain.com but that shouldnt be the problem.

I have solved the problem by removing my_office_ip form SPF record and now it looks like this
Quote:
v=spf1 a mx ip4:my_domain.com_ip include:_spf.google.com ip4:178.221.103.89 ~all
so if there is no my_office_ip google doesnt check it and mails pass, but I need my_office_ip as permitted sender also because of some reports.

What seems to be the problem here?

I forgot to add, gmail tries to connect to my office_ip just in case whem I am sending mails to those domains where I get mails bounced back, also those domains are using google MX.

Last edited by markotitel; 12-30-2013 at 06:56 AM.
 
Old 12-30-2013, 09:55 AM   #2
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
What if you create an explicit smtp... record instead of letting the wild card handle it. Give an it an IP that IS reachable (it doesn't necessarily have to be the one it came from).
 
Old 12-31-2013, 04:40 AM   #3
markotitel
Member
 
Registered: Feb 2009
Location: Titel - Serbia
Posts: 181

Original Poster
Rep: Reputation: 18
I can do that, but that is not a solution , it is hard core "hack" . I have removed that "problematic" ip from SPF for now, but I dont know why google tries to connect to it, only mx records in dns are gmail MX.
 
Old 12-31-2013, 08:41 AM   #4
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
Various people do various things to try to prevent spoofing/spam. Some you might tell to go to hell. e.g. Ebay (I think it is) won't send email to you if you have what THEY call a "generic" reverse lookup record. Our solution to that is to say "Ebay is NOT a business related address so we're not going to modify our DNS because they've come up with a bizarre definition no one else uses. Google on the other hand has gmail for all sorts of different people so trying to say there is no need for gmail in your business is a little harder.

In my not so humble opinion it isn't really a hack if you point your smtp server record to a real smtp server instead of your generic IP using the wild card. It probably makes more sense than removing your allowed sender from spf because some folks may reject email that comes from that path due to the existence of an spf in the first place. (That is to say you are NOT required to have an spf record at all but once you make one then people that check for it will assume anything that didn't come from your approved email in spf is trying to spoof.)

Of course if you really don't like having a defined smtp record what you could do is remove your wild card an only have real A records or CNAMES for the things that you DO want using your main IP so that smtp doesn't match the wild card.
 
Old 12-31-2013, 09:03 AM   #5
yo8rxp
Member
 
Registered: Jul 2009
Location: Romania
Distribution: Ubuntu 10.04 Gnome 2
Posts: 102

Rep: Reputation: 31
google mx

looks like it aint about MX , but some RBL spamhouse or nuclear filter in postfix main.cf , which supposed to filter SPAM , but it filters google also
Could ya post some /etc/postfix/main.cf here ?
look for lines containing

reject_rbl_client

i had same problem with nuclear RBL , and got to stick with spamhouse only

Sincerely ,
Gabriel linux-romania.com

Last edited by yo8rxp; 12-31-2013 at 09:04 AM.
 
Old 01-04-2014, 05:46 AM   #6
markotitel
Member
 
Registered: Feb 2009
Location: Titel - Serbia
Posts: 181

Original Poster
Rep: Reputation: 18
Thanks for the help, problem is not in Postfix, as I said we use google MX . I havent done much research afterwards, for now I have returned that "problematic" IP in spf record and waiting again to see what is happening .
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] i need help to write SPF record idnotcrae Linux - Server 8 11-10-2012 04:38 AM
hosting server SPF TXT record setup kitek Linux - Server 2 06-17-2012 07:30 AM
My SPF record is broken...how to fix in BIND? sneakyimp Linux - Server 6 03-05-2010 02:08 PM
SPF record question Sheridan Linux - Networking 0 02-16-2008 02:48 AM
SPF record macadam Linux - Security 4 05-03-2005 08:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 03:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration