SPF and redirecting Personal Domain Emails to btin...

Concern has been raised due to  Critical Path not delivering emails that SPF checks might stop emails, using  personal domain email addresses that were redirected (ie forwarded) to btinternet addresses, being delivered. Now that Critical Path appear to have temporarily fixed the issue the following email header obtained after the fix shows that the concerns are unfounded.  
It is preferable  that when the "temporary" is removed removed from the current fix,  BT ensure that Critical Path are not allowed to prevent delivery of any emails but pass them on to the recipient in a similar way as illustrated below.
The email header below, taken after the temporary fix by Critical Path, shows that when the redirection takes place no SPF check is done. It also shows that SPF check failure takes place when emails are forwarded from Critical Path to Yahoo.
Note that most of the header has to be read from bottom to top eg Section A followed by Section B etc.
The email was to payments@redacted ( ie @xxx.co.uk) that was redirected to [email protected] (ie [email protected])
The redirection takes place at sections B and C.
This email has several interesting features two of which are:
1. It has a spoofed senders address and
2. It contains a virus.
EMAIL Header
X-Apparently-To: [email protected] via 46.228.38.45; Tue, 05 Nov 2013 12:56:56 +0000
Received-SPF: fail (domain of ups.com does not designate 65.20.0.12 as permitted sender)
X-YMailISG: xWHRedactedS4oyc-
X-Originating-IP: [65.20.0.12]
Authentication-Results: mta1054.bt.mail.ir2.yahoo.com  from=ups.com;
domainkeys=neutral (no sig);  from=ups.com; dkim=neutral (no sig)
D
Received: from 127.0.0.1  (EHLO smtpin26.bt.ext.cpcloud.co.uk) (65.20.0.12)
  by
       mta1054.bt.mail.ir2.yahoo.com with SMTP; Tue, 05 Nov 2013 12:56:56 +0000
X-RazorGate-Spam: Suspected Spam
X-CTCH-RefID: str=0001.0A090206.5278DFCF.0130,ss=4,sh,re=0.000,recu=0.000,reip=0.000,vtr=str,vl=3,vh,cl=4,cld=1,fgs=2147483656
X-CTCH-VOD: Virus
X-CTCH-Spam: Confirmed
C
Received: from mailex.mailcore.me (94.136.40.61)
                    by
          smtpin26.bt.ext.cpcloud.co.uk (8.6.100.99.10223)
        id 5278DFA600034221 for [email protected]; Tue, 5 Nov 2013 12:56:56 +0000
B
Received: from sender.siscontroller360.net.br ([192.241.183.204])
            by smtp03.mailcore.me with esmtp (Exim 4.80.1)
            (envelope-from <[email protected]>)
            id 1VdgBi-00084G-Ah
            for payments@REDACTED; Tue, 05 Nov 2013 12:56:56 +0000
A
Received: by sender.siscontroller360.net.br (Postfix, from userid 48)
            id 870CA1C0A1B; Tue,  5 Nov 2013 14:56:52 -0200 (BRST)
To: payments@REDACTED
Date: Tue, 5 Nov 2013 14:56:52 –0200
From: UPS Quantum View <[email protected]>
Message-ID: <[email protected]>
X-Priority: 3
X-Mailer: PHPMailer 5.1 (phpmailer.sourceforge.net)
Message-ID:
Received-SPF: pass (google.com: domain of [email protected] does designate 192.123.32.83 as permitted sender) client-ip=192.123.32.83;
Received: from 192.123.32.83 (EHLO mailer.ups.com) (192.123.32.83)
Received: by mailer.ups.com (Postfix, from userid 1000) id A838D7824B;
X-Mailer: MIME-tools 5.41 (Entity 5.404)
X-Message-Status: s1:0
X-SID-PRA: UPS Quantum View<[email protected]>
X-SID-Result: TempError
Conversion-With-Loss: Yes
Sensitivity: 3
Expiry-Date: Never
X-MSmail-Priority: High
X-Originating-Email: UPS Quantum View<[email protected]>
X-Originating-IP: [92.123.32.83]
X-iGspam-global: Unsure, spamicity=0.748491 - pe=7.48e-01 - pf=0.748491 - pg=0.748491
X-oemPro-CSID: MjgxXzI3NA==
Received: UPS Quantum View<[email protected]>
Errors-To: [email protected],
            [email protected], [email protected]
DomainKey-Status: good
Received-SPF: pass
MIME-Version: 1.0
Content-Type: multipart/mixed;
            boundary="b1_575091d94b25242718267b4bd3e3dd7d"
Subject: UPS Delivery Notification Tracking Number : DIFIFK802DIFIFK296
X-WebFusion-Spam-Score: 4.3 (++++)
X-Spam-Score: 4.3 (++++)
X-WebFusion-Spam-Flag: YES
X-Spam-Flag: YES

Oliver341 wrote:
Amazon - Sender with SPF hard fail policy
123-reg - email forwarder
Critical Path - Destination mailbox
Mail route (prior to relaxation of SPF reject):
Amazon -> 123-reg
Works fine
123-reg -> CP
Email rejected due to SPF check failed
The "spf fail" you are seeing in your headers is actually added by Yahoo, since your mailbox has not yet been migrated to CP, and your btinternet mail is being forwarded to your BT Yahoo mailbox. Yahoo do not reject mail on SPF hard fail.   I indicated this in my post.
Prior to the relaxation of SPF reject by CP, CP was not forwarding your mail to Yahoo because CP was taking the decision to reject the mail on SPF hard fail.
I have headers before the temporary fix that have no indication of CP checking SPF.
Mail route (post relaxation of SPF reject):
Amazon -> 123-reg
Works fine
123-reg -> CP
Email now not rejected due to SPF check failed
But no indication that it did any checking.
CP -> Yahoo (if mailbox not yet migrated)
Yahoo adds SPF fail header but mail still accepted
My comments on your diagnosis is in red above.
It looks as if CP might handle "SPF hard fail policy" differently (from the obvious) than other policies eg not report them.
Has anyone got any headers for BT Mail implementations ?
Failure to deliver emails to recipients without any notification is unacceptable for any public email service.

Similar Messages

  • Failure in redirecting Personal Domain Emails to B...

    I've tried emailing BT but had no response, so posting here.
    I've discovered that over the last month or so an unknown quantity of emails to my personal domain have bounced.  These have included emails from BT.  My domain is managed by 123-reg and emails to my domain are forwarded to my ISP, BTInternet.  I have managed to get hold of a bounced email and it contains the message:
    X-Postfix; host mx0.123-reg.co.uk[94.136.40.153] said: 550-Callout verification failed:
    550 550 SPF CHECK FAILED (in reply to RCPT TO command)
    I'm not familiar with email protocols but 123-reg informs me that this message indicates that their mails server has detected that the SPF data was malformed.  A quick 'Google' leads me to understand that the mail server detected that the sender's email address was not consistent with the sending mail server.  Is this correct?  If so, how can I get BT to send properly formed emails to me instead of blaming my domain server?
    Ian

    IanMK13 wrote:
    @Jonkarra
    I'm confused. The MX records for my domain are held on a 123 DNS server but my mail is sent from a BTInternet SMTP server. Does this mean these emails will bounce if I send to a destination using SPF validation? I've not been receiving any bounce messages.
    SPF uses additional records in your DNS record rather than just the MX record. The way it works is when the recieving server recieves an email say from example.org, it will do a dns query looking for the SPF records for example.org. Those records contain the valid ip addresses that can send email from that domain say for example 1.1.1.1. So for example your email server recives an email from [email protected] it then does a DNS query which returns that the only host which is a valid source for example.com email is 1.1.1.1. So thats fine and dandy if the email is from 1.1.1.1 but if its from for example 2.2.2.2 then the email will be rejected. Now that email could be coming from 2.2.2.2 for any reason it could be that there is a forward set on the email server, it could be a badly configured client or it could be someone attempting to spoof mail from the example.com domain. SPF email checking is fairly new and is one of two competing standards the other is DKIM which actually adds a signature to outgoing mail the public key for which is stored on the DNS record of the domain. Neither of these are as yet used widely, there is some but not massive demand for it, I think most peeps now communicate via facebook or IM rather than email.

  • When I use a simple form, I get this error message "Form communication is configured with an email address of..." and the person's email address did not get sent a message

    I was unable to use the simple form to which I should simply put the email address of the person to whom the form should be sent to.  I get this error message:
    As a result of this, this person did not get any filled form response.  Where did I go wrong and how can fix this.
    Second question, I am using GoDaddy.com account and they have their own set of php form.  If I want to use their php form, where in Adobe muse, can I insert their php?

    Hello Tonchee
    If you are seeing an Apple ID that is not yours, then you have purchased content on your iPad that is tied to that Apple ID. You would need to know that password or remove the content that is associated with that Apple ID.
    Using your Apple ID for Apple services
    http://support.apple.com/kb/ht4895
    Thanks for using Apple Support Communities.
    Regards,
    -Norm G.

  • Hosting .Mac and Personal Domain Separately - Help!

    Hi,
    I have three websites I have made using iWeb, and one personal domain. I would like to host two of the sites only on .Mac, and host the third site on the personal domain. I set up the CNAME and it works but I do not want two of the sites to be linked to the personal domain.
    Is there a way to do this?
    Should I copy iWeb and use the copy for one or the other?
    Can I separate the website files or something?
    Thanks in advance!

    When I go to mysite.com, the iWeb page I want shows up, and I can go through the pages of the site. But if I type in mysite.com/site2.html or mysite.com/site3.html my other sites come up. I don't want those two sites to be accessible from mysite.com.
    Thanks for the clarification.
    Of course one has to know the names of your other sites in order to access them.
    Some ways to divorce them more totally might to
    +password protect them
    +purchase another .Mac account (or use a family account) for them
    +manually move them to iDisk/Sites. Then they would have the url homepage.mac.com/username/sitename (not sure all features would work).
    PS A further option might be to use ordinary forwarding plus masking instead of CNAME. When you do that, your personal url is sent to your longer .Mac url, web.mac.com/username/sitename. I don't know what happens when you try to type in a different sitename after the personal name.

  • Personal Domain and typing site without "www"

    I set up my personal domain through iWeb. Typing www.sitename.com works great, but if I leave the www off the address it points to a godaddy page where my name is registered. Is there another setting to change for this?

    I am using namesecure.com.
    Here is what my setup looks like:
    A Name:
    domain.com points to IP (IP set by namesecure.com)
    CNAME
    www.domain.com points to web.mac.com
    I did not set up a CNAME for domain.com because namesecure.com will not allow for an empty CNAME.
    What I did instead was set my URL forwarding to go to http://www.domain.com/ and set my IP forwarding to go to the IP given by my name server. IP forwarding is turned on.
    So if someone goes to www.domain.com they are taken to web.mac.com and my personal domain shows up in the address bar. If someone goes to domain.com then the A Name IP sends them to ??? which then does a URL forward... I don't know how this is working but it is.
    You can test my results here:
    http://www.autumnalbliss.com
    http://autumnalbliss.com
    Message was edited by: Shawn Towne

  • .mac and personal domain question

    I'm sure this has been addressed several times, although, I can't find the answer in a quick search...
    I set-up a personal domain on my account. I have several websites going in iWeb, however. Can I still host my personal domain on .mac, but still publish my other sites to my .mac url? How do I switch back-n-forth between my .mac url and my personal domain without messing things up?!
    Thanks so much for the help!
    Cheers,
    Lilly
    Message was edited by: TXlillypad

    How do I switch iWeb to publish to my .mac rather than my personal domain? Is that possible?
    iWeb always publishes to .Mac, nowhere else, regardless of what it says somewhere in the app. You can always reach all your sites via the url http://web.mac.com/username/sitename.

  • Help to add new mail with personal domain.tld

    Dear Sirs ,
    following we hereby state that we have a little problem on blackbbery we use . when planting a personal domain email .
    we did not find a lot of options , such as setting and other ports .
    that there is only :
    email address: [email protected]
    password : password - user - mail
    we 've completely fill out the form that must be filled on top , but always considered wrong . and when we see the custom options that contain only :
    server address : mail.mydomain.tld
    Username : [email protected]
    there are no other options such as ports and others .
    and each of us filled in accordance with the request, always considered wrong and asked for mydoamin.tld contacted .
    Please explain how so we can plant mydomain.tld email on blackberry OS7 and OS6 and OS5 .
    please note we managed to grow on blackberry os10 . highly unlikely we force them below the os users to exchange the device os10 because of financial reasons is not allowed .
    thank you

    When creating an email account, you should find the link to "Advanced Options" at the base of the screen.
    If not, see this:
    Article ID: KB31575 BlackBerry smartphone has no option for Internet Mail Account in Email Setup Application
    Article ID: KB15499 How to set up a BlackBerry Internet Service email address from the BlackBerry smartphone
    1. If any post helps you please click the below the post(s) that helped you.
    2. Please resolve your thread by marking the post "Solution?" which solved it for you!
    3. Install free BlackBerry Protect today for backups of contacts and data.
    4. Guide to Unlocking your BlackBerry & Unlock Codes
    Join our BBM Channels (Beta)
    BlackBerry Support Forums Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

  • .Mac site to personal domain

    Hi all,
    does any of you know how is it possible that a .Mac site is transferred to a personal domain? It's not redirected: both sites are identical.
    See here
    h**p://web.mac.com/uomoragno/blog/spider-mac/spider-mac.html
    And here
    h**p://www.spider-mac.com/blog/spider-mac/spider-mac.html
    Thanks.
    --Antonio

    You don't have to transfer anything.
    With a Personal Domain your pages are stil on MMe. You have to add a CNAME at your registrar.
    Go to your MME account and click Personal domain.
    https://secure.me.com/account/
    Then click +Find a Help topic+. Then click Account.
    If on the other hand you mean to host your webpages at some provider, then you have to publish to a folder and upload the folder to that host.

  • I'm a bit confused about the Personal Domain concept

    I've always had my own website, www.myname.com, which I've paid a monthly fee for hosting. Can I design my new website using iweb (I'm working on it and it's looking fine), and then use my 20 gig of mobile me space (or whatever I need) to host the site (saving the other hosting fee). Will someone be able to type in the URL "www.myname.com" and get to my iweb created site. Also, will it simply be forwarded to the mobileme URL, or will the address still read "www.myname.com". Am I getting this all wrong, backwards, upside down?
    Thanks in advance.

    Yes, you can create a new site, publish to MobileMe and redirect your domain name to it. More info on that can be had here:
    http://discussions.apple.com/thread.jspa?threadID=1164519&tstart=0
    http://docs.info.apple.com/article.html?path=MobileMe/Account/en/acct17114.html
    http://iwebfaq.org/site/iWeb_Domains.html
    FWIW MMe tends to be much slower overall and has no ear to ear support in case you need it. For a personal site it's OK but for a commercial site you would be better off on a commercial hosting server.
    OT

  • Email and transferring over a my personal domain

    Hi have a business domain name that i want to swicth over to mobile me add some memory to it. I Already have a site running and it has run it course. Both personal domain goes though different company, one bring network solution and the other active domain. I went and bought iLife 09 for some reason that it would be easier to recreate more personal domain. and I Love apple stuff. When I tried a few months ago with my business one at network at it go so great. We lost are email for a day for so and they told I have to call apple. I quest what I am looking for and going through active domain and how do I set up my company email. I would like to me a informed before I go asking them them some question. How host the email account? How many can I have? I to all the graphics I you for my companies, like logos and and stull just go into my idisk, moble.me account and I get back them up leter? I would be nice the have a personal and companies web site through IWeb. I'm pretty new to to all. Right now my mobile me has my site as HillFamilyFund.com. But I would like my company to come up the same same with [email protected] There it is again. I worried about the email and how many I have. I have been able to find out the setting to tell newtork and Active what I need to do and many them. I'm gone on way too long. Thanks

    MobileMe is not suitable for hosting a business website.
    You cannot set up web mail and you can only have one "real" domain name redirect.
    MobileMe is slow, unreliable and has no tech support.
    For a business site you need several web mail addresses that you can redirect to your Mac Mail if you want and you need the ability to have contact forms.
    If you want to be found in search engines and optimize your site so that it will download on a PC running Internet Explorer you will find that MobileMe makes this very difficult to achieve compared with using a "real" server.
    To give you an idea about what's involved in SEO look here.......
    http://www.iwebformusicians.com/SearchEngines/SEO.html
    and for contact forms....
    http://www.iwebformusicians.com/Tricks/Forms.html

  • Personal Domains and Email Accounts

    I have a client that wants to use personal domain names and also wants to use email addresses with these domains. Do we need to set him up and have the website point to his .mac pages and then have the email set up on another server? Can you create email accounts to work with personal domains through .Mac?
    Holla at me and let me know!!!
    Thanks in advance.

    Look here: http://discussions.apple.com/thread.jspa?threadID=1320456&tstart=0
    and here:
    http://discussions.apple.com/thread.jspa?threadID=1288484&tstart=0

  • .mac Hosting and Personal domain

    Any help?
    I bought a domain name from a registar in Greece and signed up for Google Apps.
    The @mydomain.co.gr woks with google mail and I want to keep it like this.
    Do I have to buy additional hosting services to be able to publish my site at .mac using www.mydomain.co.gr.
    Will my site be at web.mac.com or it must be hosted somewhere else an redirected to .mac?

    Chuck, you wrote that "all you should have to do is point the domain name to the .mac address." Can you please explain how? I have been on phone support and email contact with Apple and NOBODY knows how to do this! I kid you not. There are articles on How To but it doesn't work for me. My website does not publish to my personal domain name on iWeb and .mac, despite following the procedural instructions from Apple.
    At this point, my website is "published" to mac.com/myusername, but NOT to my personal domain name.
    Thanks for any suggestions you can give.
    Maria

  • Can you have an email account from a personal domain on mobile me?

    I want to be able to answer emails that come in from my personal domain website (www.writenow-communications.ca) with an email address [email protected] (I want mobile me email to reply from that name.)
    Is this possible, and if it is, how do I do it?
    I'm using iWeb '08.
    Thanks!

    iWeb is an application to create and publish webpages.
    It does not deal with e-mail either with MobileMe or 3rd party accounts.
    Better ask in the [MobileMe Mail forum.|http://discussions.apple.com/forum.jspa?forumID=960]

  • Personal Domains and Multiple Sites

    Hi, I've looked through several pages worth of questions but none of them seems to be exactly like what I want to get done.
    First, I have 2 sites in iWeb. The second was created in iWeb '08 just because of the addition of the Personal Domain feature and so for the first time, I want a site that is hosted at Mac.com.
    The first site is hosted elsewhere. I always publish to a folder and use an FTP software to upload it.
    So, obviously, what I want to do is to use "Publish to .Mac" to upload my 2nd website ONLY to .Mac. But, iWeb seems to want to publish both. Even after I deleted the 1st website manually in iDisk, iWeb will publish a folder with the 1st website's name and throw in some content (like feed.xml, and "Media" and "Scripts" directories).
    So, Question 1, can I make iWeb to stop this? Or, will have to create multiple Domain files and manage the 2 sites separately?
    The other question is this. I just set up a CNAME thingy with Godaddy.
    Let's say my domain is www.hogehoge.com.
    I set the CNAME alias to web.mac.com.
    In iWeb, I call the 2nd website "hogehoge" (just so I know which site it is). When iWeb publishes that site, everything goes inside
    Web/Sites/hogehoge
    And when I access the site at www.hogehoge.com, the index.html in Web/Sites
    will redirect me to the index.html (or, since I currently only have the blog file, /blog/blog.html file) inside the hogehoge directory, so the address looks like
    www.hogehoge.com/hogehoge/blog/blog.html
    but that *****. I don't want the second "hogehoge". Is there any way to get rid of that?
    Hope those questions were clear enough...

    I've just started with multiple iWeb sites. While I still need to look at one of these utilities to manage multiple websites independently, I think I already figured out how to publish to multiple .Mac accounts from within my main user. The method below worked for me, although it published my entire set of sites, so yeah, still need to work around that.
    Granted, having multiple users on your Mac, each associated with specific .Mac accounts would certainly work, and the cost is $0, but depending on where you keep files you need to access for each web site (like iphoto, itunes, etc), hopping between users could be a bit messy. I suppose you could store everything in the SHARED folder in the User directory, though.
    THE METHOD
    Assuming you have a utility to manage multiple iWeb sites (the two popular ones seem to be iWebsite (free) and Multisite (shareware), neither of which I've tried yet), I THINK another way you can publish to a specific .Mac account is simply to go into SYSTEM PREFERENCES, click on the .Mac icon, and then SIGN OUT of your current .Mac account (do this right before you're ready to publish). You are then presented with a dialog to sign in to a different .Mac account ---> enter the access to the one you want to publish to. Now, when you hit 'Publish to .Mac' in iWeb, it defaults to THIS account and publishes it there. You just have to remember to go back into SYSTEM PREFERENCES and log back in to your original .Mac account when you're finished publishing.
    The advantage to this, as I see it, is staying in my primary user and having access to all the files I need, as well as being able to switch to other apps and running programs in my primary account without issue.
    Again, relatively new to iWeb, and I haven't played too much with this, so feel free to correct me if I'm wrong ....

  • Email at personal domain

    I have my personal domain published with iWeb at www.mac.com. I would like to know if I can set up email with my domain name.
    www.name@personal domain.com????

    It is tricky but here is how I did it.
    I use ENOM as a registrar (godaddy should offer the same service) With my registrar, I forward my [email protected] email to my .Mac account email. That is the easy part to figure out. Now all my email from [email protected] goes to my .Mac email account. They next step is to send mail from [email protected] To do this I modifed my .Mac account settings in entourage. I changed the email address to [email protected] and I changed my outgoing SMTP server to the one for my internet service provider (mail.charter.net) (mail.bellsouth.net), etc.
    This makes your .Mac account a shell account it receives mail to itself and mail forwarded from [email protected] but it is not used to send mail back out. That is done by my ISP that doesn't require a secure connection from within its network
    This would not work well for a roaming laptop or if ever wanted to sent mail from your .Mac email address but it works otherwise.

Maybe you are looking for

  • Help me find my iPhone

    I lunfortunately had my iPhone stolen three nights ago and have absolutely no idea where it could be. I went on iCloud.com and used the Find My iPhone service to locate my phone and it showed up with a grey circle meaning offline, but it gave me a lo

  • Does my mac have to be on to use apple tv

    I was thinking about picking up an apple tv sometime soon but I wanted to know if you need to have your mac on to watch purchased content on the apple tv. So say for instance I buy an episode of Father Ted on my iPhone 4 or Mac, would I be able to wa

  • Export from running swf to eps?

    I'd like to export, say, the current frame being displayed in Flash Player (or previewing in the authoring environment) to eps, ultimately bound for Illustrator. I know it can be done; Joshua Davis boasts about it in one of Adobe's showcase panels. E

  • Why I cant see PDF files in skydrive on my Mac air?

    why cant I see pdf files in skydrive ?

  • MDM Issues -ii-

    Hello experts, when a validation fails - Error message pops up. Now, what should we do with the records that failed at validation? Will they be automatically Deleted from table?? or Should we need to change the data(then and there) and run the valida