Richard Lawley
2013-08-01 08:19:49 UTC
Hi,
I'm not sure if anyone on here is responsible for or involved with the
OpenSPF WHY page.
I just spent quite some time tracking down a problem with SPF records on
one of my domains, which ended up being down to the DNS software my DNS
host uses serving a synthesised SPF type record. This was invisible
through their editor, and is also hard to query since support for the
record type was not in the version of dig which I was initially using, nor
does nslookup support it in Windows. The problem also compounded by them
serving different synthesised results from both of the nameservers, one of
them ending in -all and the other ~all.
This is clearly a niche situation - for a message to be bounced it had to
be checked by an SPF implementation that took SPF-type records instead of
TXT-type records, and it had to have been served by the DNS server with the
-all record. However, less of a niche situation would be where SPF and TXT
records both exist but do not match.
One of the bounce messages has directed me to the OpenSPF WHY page, which
was showing me that the message didn't match my SPF record, but that it
shouldn't have stopped the message (presumably it had hit the server with
the ~all record). What I would like to suggest is that the record checker
prints the contents of the SPF record it retrieved (and ideally the type of
record it is!) in order to make it more obvious what was going on.
Additional diagnostic steps could potentially be added, such as showing
that conflicting SPF and TXT records exist, but my first suggestion would
have helped me solve this a lot. Just hoping that this can help someone
else in a similar situation!
Regards,
Richard
-------------------------------------------
Sender Policy Framework: http://www.openspf.net [http://www.openspf.net]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]
Archives: https://www.listbox.com/member/archive/735/=now
RSS Feed: https://www.listbox.com/member/archive/rss/735/6959934-50ec8f89
Modify Your Subscription: https://www.listbox.com/member/?member_id=6959934&id_secret=6959934-b7c4528d
Unsubscribe Now: https://www.listbox.com/unsubscribe/?member_id=6959934&id_secret=6959934-edadf31a&post_id=20130801041958:23FDF6DA-FA83-11E2-9291-F76E11191F9C
Powered by Listbox: http://www.listbox.com
I'm not sure if anyone on here is responsible for or involved with the
OpenSPF WHY page.
I just spent quite some time tracking down a problem with SPF records on
one of my domains, which ended up being down to the DNS software my DNS
host uses serving a synthesised SPF type record. This was invisible
through their editor, and is also hard to query since support for the
record type was not in the version of dig which I was initially using, nor
does nslookup support it in Windows. The problem also compounded by them
serving different synthesised results from both of the nameservers, one of
them ending in -all and the other ~all.
This is clearly a niche situation - for a message to be bounced it had to
be checked by an SPF implementation that took SPF-type records instead of
TXT-type records, and it had to have been served by the DNS server with the
-all record. However, less of a niche situation would be where SPF and TXT
records both exist but do not match.
One of the bounce messages has directed me to the OpenSPF WHY page, which
was showing me that the message didn't match my SPF record, but that it
shouldn't have stopped the message (presumably it had hit the server with
the ~all record). What I would like to suggest is that the record checker
prints the contents of the SPF record it retrieved (and ideally the type of
record it is!) in order to make it more obvious what was going on.
Additional diagnostic steps could potentially be added, such as showing
that conflicting SPF and TXT records exist, but my first suggestion would
have helped me solve this a lot. Just hoping that this can help someone
else in a similar situation!
Regards,
Richard
-------------------------------------------
Sender Policy Framework: http://www.openspf.net [http://www.openspf.net]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]
Archives: https://www.listbox.com/member/archive/735/=now
RSS Feed: https://www.listbox.com/member/archive/rss/735/6959934-50ec8f89
Modify Your Subscription: https://www.listbox.com/member/?member_id=6959934&id_secret=6959934-b7c4528d
Unsubscribe Now: https://www.listbox.com/unsubscribe/?member_id=6959934&id_secret=6959934-edadf31a&post_id=20130801041958:23FDF6DA-FA83-11E2-9291-F76E11191F9C
Powered by Listbox: http://www.listbox.com