LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-30-2005, 01:19 AM   #1
macadam
Member
 
Registered: Sep 2003
Posts: 72

Rep: Reputation: 15
SPF record


Hello,

I have a few domains using my mail server: mail.mydomain.com
in the DNS record of mydomain.com, I have the following SPF records:

mydomain.com. IN TXT "v=spf1 mx -all"
mydomain.com. IN TXT "v=spf1 a -all"
mail.mydomain.com. IN TXT "v=spf1 a -all"
mail.mydomain.com. IN TXT "v=spf1 mx -all"

However I still reveive spam emails with the adress user@mail.mydomain.com

Can anybody help?

Regards,

macadam
 
Old 04-30-2005, 07:56 AM   #2
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
I don't think you understand SPF correctly. SPF is designed as an "authentication" mechanism for mail servers to validate that a particular piece of mail is coming from a legitimate mail server for a given domain.

The records you have added allow other mail servers to validate your domain. These records don't do anything for your domain. SPF also won't do anything unless you have an SMTP server that has implemented SPF. Furthermore, SPF simply blocks spam coming from hosts that it cannot validate as legitimate mail servers for the sending domain. It does nothing to block spam coming from legit mail servers based on content of the message.

Finally, using SPF at this point would likely block email from literally *millions* of domains. If implemented correctly, an SPF-enabled SMTP server would drop mail for which it cannot validate any mail servers. So if a given domain does not have a valid SPF record, the message would be dropped. The SPF website "brags" about "tens of thousands of domains" using SPF already. While this may sound like a lot, that number is inconsequential considering that there are something like 25 *million* domains registered under .com alone.
 
Old 05-02-2005, 10:00 AM   #3
Donboy
Member
 
Registered: Aug 2003
Location: Little Rock, Arkansas
Distribution: RH, Fedora, Suse, AIX
Posts: 736

Rep: Reputation: 31
Track, I agree with you totally, but just wanted to mention one thing... counting the number of domains using SPF is a foolish way to judge how widespread SPF has become. It's possible for one server to have thousands of domains. So if that server is mine, I can setup SPF checking on my server and *boom* you now have thousands of domains using SPF.

I read somewhere (I believe spamhaus.com) that they estimate there is something like 100,000 email servers worldwide that is handling the bulk of internet mail.
 
Old 05-03-2005, 04:58 PM   #4
TheLinuxDuck
Member
 
Registered: Sep 2002
Location: Tulsa, OK
Distribution: Slack, baby!
Posts: 349

Rep: Reputation: 33
My understanding of SPF is really limited, but from what I remember, it's
pretty much dead in the water and mostly problematic. Here's a good
read on it:
http://homepages.tesco.net/~J.deBoyn...s-harmful.html
 
Old 05-03-2005, 08:13 PM   #5
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
Quote:
Originally posted by Donboy
counting the number of domains using SPF is a foolish way to judge how widespread SPF has become. It's possible for one server to have thousands of domains. So if that server is mine, I can setup SPF checking on my server and *boom* you now have thousands of domains using SPF.
ehhh... servers != domains... and I said domains, so I'm not sure where this is going?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Unable to record mic-in with SoundBlaster Live! while able to record other sources max76230 Linux - Newbie 2 03-14-2005 04:31 AM
Need help setting up SPF in DNS Oracledesign Red Hat 3 12-05-2004 08:46 PM
SPF issue with when replying to .gmx addresses thorn54 Linux - Software 0 08-10-2004 10:59 AM
what goes in the mx record? ziggie216 Linux - General 1 11-14-2003 03:50 PM
MX Record minor Linux - General 3 07-23-2001 06:06 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration