LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-01-2008, 11:12 AM   #1
bskrakes
Member
 
Registered: Sep 2006
Location: Canada, Alberta
Distribution: RHEL 4 and up, CentOS 5.x, Fedora Core 5 and up, Ubuntu 8 and up
Posts: 251

Rep: Reputation: 32
Question Web and Mail Server - Protect my IP - SPF records?


Hi there,

So I have been running my own web server for a long time now and never had problems (knock on wood). As of late I have been getting mail messages stuck in my mail queue. The below quote is an example of one of the e-mails I have in my queue:

Quote:
Received: (qmail 7077 invoked for bounce); 1 Apr 2008 02:35:00 -0600
Date: 1 Apr 2008 02:35:00 -0600
From: MAILER-DAEMON@plesk.urhostingpro.com
To: divinities7@ecrha.org
Subject: failure notice
Now here is what I am running for my server:
Cent OS 5.0
Plesk Hosting Control Panel 8.3.0 which uses QMAIL as the mail program.

I have created an SPF record for each domain/client that I host, the record looks as follows:

Quote:
v=spf1 a mx ~all
To my knowledge the above SPF record should only let messages get sent from my server and no where else. Meaning the message must get relayed through my box regardless of where my client is. Having said that then I shouldn't get bounce back messages, correct?

Any and all help on this would be great!
 
Old 04-01-2008, 11:42 AM   #2
KenJackson
Member
 
Registered: Jul 2006
Location: Maryland, USA
Distribution: Fedora and others
Posts: 757

Rep: Reputation: 145Reputation: 145
It can fail for many reasons. Is there more information in the failure message?

As for the SPF record, my knowledge is limited to what I've read on wikipedia, but I believe ~all is a soft failure, which means messages sent from other IPs would actually be delivered and merely tagged as possible junk. Whereas -all would be needed to make them fail.

Also, it's my understanding that some mail servers ignore the SPF records.
 
Old 04-01-2008, 01:11 PM   #3
bskrakes
Member
 
Registered: Sep 2006
Location: Canada, Alberta
Distribution: RHEL 4 and up, CentOS 5.x, Fedora Core 5 and up, Ubuntu 8 and up
Posts: 251

Original Poster
Rep: Reputation: 32
Unfortunately there is nothing else to the error message, just that.

I better read up a little more the on SPF record.... still I am guessing someone is spoofing my server's name because I don't have an SPF.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
BIND DNS - MX, TXT and SPF records when hosting multiple domains on same machine? icebrian Linux - Networking 3 05-02-2011 08:21 AM
SPF records for mail hua Linux - Server 4 01-09-2007 10:30 AM
LXer: State of E-Mail Authentication: SPF Dead, Others on Life Support LXer Syndicated Linux News 0 04-20-2006 07:33 AM
How the DNS-server is connected to work of a web-server and a mail-server? ukrainet Linux - Newbie 2 01-10-2005 09:18 PM
can we configure a Linux server with mail server,file server and web server kumarx Linux - Newbie 5 09-09-2004 06:21 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration