SPF Record (How Do I Add?)

Has anyone added a SPF record to cut down on spammers sending mail that looks like it came from your domain? What's your experience been since? I would like some assistance on getting this done on my Mac 10.4 Server.
Thanks in advance!
Powermac G5 Dual 2.5   Mac OS X (10.4)  

http://www.openspf.org/ has wizard that builds a SPF
record based on answers to simply questions about
your network. You can use it as a starting point.
Camelot is correct, the best place to get information about SPF is at the openspf.org web site or the newer new.openspf.org site. Make sure you read all the information because publishing SPF records can have an impact on how your users send email. Be especially aware of the impact if you use email forwarding. Email forwarding breaks SPF!
You should also join the SPF Help mailing list if you have any further questions that are not answered at the SPF web site. I read all the postings to that list and myself and others will be more than happy to answer any further questions you have.
As for how effective it is - hard to say because no
one ever lets you know when they block mail due to
SPF restrictions.
Actually, if you fail an SPF check you are sent a bounce email that includes a link to the SPF web site explaining why the email bounced. Here is a sample of a link for an email that my server bounced.
Please see http://www.openspf.org/why.html?sender=ceo%401000planets.com&ip=85.2.114.191&rec eiver=server.pixelpointstudios.lan, header_comment=server.pixelpointstudios.lan: domain of [email protected] does not designate 85.2.114.191 as permitted sender
However, for the trivial amount of work it is to
implement it's worth doing. There's an element of
chicken-and-egg in the whole process - people won't
start adding SPF records until mail servers start
checking them, but mail servers won't check them
until they're being added to the DNS.
Well, there are two parts to SPF. There is the publishing of SPF records to protect your own domains and there is the checking of SPF records to validate the email that is sent to you.
By merely publishing SPF records you are already doing quite a bit. On top of the fact that your are protecting your own domains from fraudulent use, you are also helping stem the flow of forged email for those who are evaluating SPF records on the receiving end.
If you are running Mac OS X Server 10.4.x, the included SpamAssassin install will evaluate SPF records and use the results in its scoring if you install the SPF Perl modules.
If you want to go further than that you can install the Mail::SPF::Query Perl module and a Postfix policy plug-in and block SPF failures at your MTA.
Anything you can do to help stem the flow, as well as
protect your corporate identity has to be a good
thing.
Can't argue with you there!

Similar Messages

  • How do I add multiple text block records from text file?

    The data manager documentation (page 151) for MDM 5.5 SP3 indicates that one or more new text blocks can be added to the Text Blocks object table from files. It is noted that the files must be plain text files.
    I use notepad and create a text file with two lines as follows:
    Test 1
    Test 2
    When I try to add the text blocks following documentation mentioned above, it only adds one record for the Data Group I have chosen and the record contains the entry "Test 1" from the first line in the text file.
    How can I add multiple records to the data group from a file?

    From my testing it appears that you need to have one text file per text block record in Data Manager.
    I wrote VBA macro to so that I could input my text blocks into an Excel spreadsheet and then the macro will take the contents of each cell in a highlighted column and create one text file per cell.
    Then using Data manager, I can select all of the text files at once and it will import them, creating one record per text file.

  • How can I add a new record in an Access table.

    How can I add a new record in access with LabView, using activex, without using the database connectivity tools.
    Message Edited by Noawena on 05-16-2008 09:25 AM

    Much easier with a toolkit but you could use ADO objects,
    get connection, make a SQL object "INSERT record INTO table where  ...." 
    Execute the parameterized query
    Free up record sets data
    close connection when done.
    This is a very simplified version
    Paul
    Paul Falkenstein
    Coleman Technologies Inc.
    CLA, CPI, AIA-Vision
    Labview 4.0- 2013, RT, Vision, FPGA

  • How can I add new content in iDVD to a DVD-RW disc which has ample remaining free space? After preparing the new video for burning and clicking on Burn to iDVD, I get a window saying the disc's already recorded and that I can either Erase or Eject.

    How can I add new content in iDVD to a DVD-RW disc with a video previously successfully recorded on it? (The disc has ample remaining free space.)
    After preparing the new video for burning and clicking in the File menu on Burn to iDVD, I get a window saying the disc's already recorded and that I can either Erase or Eject. My assumption has been that iDVD would automatically find the free space and continue with the new recording from there. I'd be grateful if anyone can shine light on this.

    There are, but not with a DVD written as a movie disk. It must be closed when completed, or it doesn't work.
    Apple's built in Burn utility also automatically closes any data CD, DVD or Blu-ray disk you burn. Doesn't matter how much space is unused, you can't use it. You'd have to use a more advanced disk creation app, such as Toast Titanium. I then have the option of choosing to write the data as a session:
    I can keep doing this until the disk is full. If I've written five sessions to the disk, when I put it in the drive, five CD/DVD icons will appear on the desktop since the OS will treat each session as if they are separate physical disks. At any point you choose Write Disk when writing a group of data, that means you're closing the disk, and again can't add anything after that. So if I had written two sessions, and the third was Write Disk, it's over. I can't put anything else on that disk.

  • How do I add SRV record to my DNS for Office 365?

    How do I add the following record?
    Add the SIP SRV record for Lync web conferencing.
    Create a new SRV record.
    In the new record, make sure that the fields are set to precisely the following values:
    Record Type: SRV
    Service: _sip
    Protocol: _tls
    Port: 443
    Weight: 1
    Priority: 100
    TTL: Set this value to 1 hour or to the equivalent in minutes (60), seconds (3600), etc.
    Name: @
    Target: sipdir.online.lync.com
    Save the record.
    Need help ASAP because my clients Email is down when I changed Domain Name Servers to Business Catalyst.
    All Office 365 functions were lost.
    Thank you for some assistance - URGENT,
    Jim Vernon
    Hopegate Software

    Here is an image of the settings that Office 365 says i need to correct in my DNS settings on Business Catalyst:

  • How does one add a personal recorded M4R file to the ring tones in the UK system for iPhone 3GS

    How does one add a personal recorded M4R file to the ring tones in the UK system for iPhone 3GS.
    I have tried all sorts of ways of adding my personal M4R file but can't find the place (within the UK versions of iTunes} to transfer this file so that I can select it as a ring tone.
    I've tried also changing to the US version of iTunes and still can't find a way of doing it, although I have heard that it can be done.

    You should be able to just drop it into the library within iTunes.
    http://cnettv.cnet.com/create-free-iphone-ringtones-using-itunes-8-0/9742-1_53-5 0003920.html
    Check out the video above for a lot good info. The ringtone must be less than 35 seconds.

  • How do I add music from a music cd on a MacBook Pro?  Up until this morning I got a window that asked me if I wanted to record or play the cd I just inserted.  Now that window no longer appears.  Any suggestions on how to rectify this?

    How do I record music from a music cd to my MacBook Pro?  Up until this morning I would get a pop up window that asked if I wanted to play or record the disc I just put in.  That screen no longer appears - a disk starts to play.  I can stop the auto play but how do I add the music to my existing music collection?
    Thanks

    Do you mean "how do you rip a CD to iTunes?" If so, just insert the CD into the optical drive of the MBP, launch iTunes, edit the ID3 tags to show what you want, then click the "import" button in the lower right corner of the window.

  • How Do I Add A Pre-recorded Voice Over to an iMovie Project?

    I have an audio file with the voice over I want to add to my movie project (which has an insturmental music track I want to duck during the voice over). How can I add this pre-recorded voice over track to my project?

    You can drag in the voiceover file and drop it on top of the clip where you want it to start. It does not have to be perfectly placed, because you can fine tune it later by dragging.
    I would suggest putting your voiceover file in iTunes and dragging in from the music browser, but it also works to drag in from the Finder. If you drag in from the Finder, you must take care not to move it later, or the iMovie Project will not be able to find it.

  • How do I set an SPF record?

    I'm quite unfamiliar with SPF records, but I'm using FreshBooks to invoice my clients. However, my invoices seem to be going to many people's junk and spam folders. Freshbooks is suggesting to set an SPF record to avoid this. Can this be done with icloud emails, or is this specifically for a privately owned domain email?

    If you have set up your Domain A-record on the registra to point web traffic to BC you do not set up another A-record in BC.

  • Leopard DNS Server: Zones with SPF records?

    Hi all,
    I'm trying to figure out how to setup SPF (Sender Policy Framework) records for some domains I'm currently managing with a Leopard DNS server and I don't see any documentation anywhere. Can someone please tell me if it's even an option? I'm new to running DNS with Leopard, so I could use all the help I can get.
    Sincerely,
    Israel
    Message was edited by: Israel Thompson
    Message was edited by: Israel Thompson

    Israel Thompson wrote:
    So let me see if I have this right. Any changes I want to make that will not be editable in the GUI, I want to do them in db.mydomain.com instead of db.mydomain.com.zone.apple? Easy enough. However I tried adding "v=spf1 a mx ~all" (with quotes) to my file and it appeared to have broken the dns zone. What’s the proper way to enter these in manually? Can you give me an example of how it looks in your zone files? I’ve pasted a sample of mine below. Tell me if anything is wrong.
    Israel,
    I am new to Leopard Server - so I'm no DNS guru. I, too, have not used a DNS setup tool that requires a FQDN just associate an IP with the base of the domain (mydomain.com.). How did you get your 'mydomain.com. IN A 11.22.33.44' accomplished? Did you create a new A record and put mydomain.com. in the Machine Name field?
    Here's my setup:
    ========================
    db.mydomain.com
    ========================
    ;THE FOLLOWING INCLUDE WAS ADDED BY SERVER ADMIN. PLEASE DO NOT REMOVE.
    $INCLUDE /var/named/zones/db.mydomain.com.zone.apple
    ========================
    db.mydomain.com.zone.apple
    ========================
    $TTL 10800
    mydomain.com. IN SOA ns1.mydomain.com. admin.mydomain.com. (
    2008010951 ;Serial
    7200 ;Refresh
    3600 ;Retry
    604800 ;Expire
    345600 ;Negative caching TTL
    mydomain.com. IN NS ns1.mydomain.com.
    mydomain.com. IN NS ns.mydomain.com.
    mydomain.com. IN A 64.251.168.218
    mydomain.com. IN TXT "v=spf1 ip:64.251.168.218 ip:64.251.168.220 ~all"
    www IN A 64.251.168.218
    mail.mydomain.com. IN A 64.251.168.220
    mail.mydomain.com. IN TXT "v=spf1 a ~all"
    xserve.mydomain.com. IN A 64.251.168.218
    xserve.mydomain.com. IN TXT "v=spf1 a ~all"
    ns IN A 64.251.168.218
    ns1 IN A 64.251.168.220
    mydomain.com. IN MX 10 mail.mydomain.com.
    ... where xserve.mydomain.com is my machine's hostname.
    I have a funky setup for DNS because I don't have a different, or second, DNS server (just the one on my Xserve with everything else) and my name servers are under this zone. I added the two IPs for my mail and hostname to the base SPF record. Someone could still spoof from using the name or www domains (same IPs) but I can check for it using Postfix up front. I also added "v=spf1 a ~all" in case another mail server tries to check the mailing server or hostname directly.
    You'll usually want to set a TXT "v=spf1 ~all" (SPF null) for any records that have no possibility for mail origins, like your ftp and mobile, but it appears you also have a similar issue to me - those services will be running under the same IPs as the mail service. This is why I added "v=spf1 a ~all" to all essential services (mail and hostname). I don't know what will happen if you add an SPF null to an unnecessary service that happens to also have the same IP. (Will the IP get blocked in a cache during a lookup??) So I didn't add an SPF TXT to those domains. I'm a little confused at this point. I should probably read more about it.
    http://www.openspf.org/FAQ/Common_mistakes
    Also, you'll notice I added FQDN to mail and xserve. If I do this and ensure they are in my reverse DNS PTR records then I've seen that when I add new zone records with same IPs (like for another domain) then the PTR records don't keep switching to the newest entry (why does it do that?).
    I don't think your use of the . in the CNAME records is correct. I think the CNAME records are probably unnecessary since you have already fully defined the domains in A records. Also, those A records probably don't need FQDNs (with the ending .). I only added mine for the reason noted above, concerning the PTR records.
    I hope someone who knows some more than I can chime in on this.
    Larry
    Message was edited by: Larry_S (removed mx from SPF TXT for main domain record, as it was redundant with the ip:)

  • Creating SPF records

    Having run a few tests on our Server, on of the errors that has come up is that we don't have any SPF records.
    Doing a search sends me to the following site, but it always comes up with the error - System Maintenance in progress. Please try again later.
    microsoft.com/mscorp/safety/content/technologies/senderid/wizard/
    Having looked at some other sites, I come up with different answers.
    Here is my example, our website is hosted by another company, but we run our own mail server.  I have used the following examples
    domain - mydomain.com
    mail server ip - 1.2.3.4
    One wizard come up with the following to add to my DNS
    mydomain.com.  IN TXT "v=spf1 ip4:1.2.3.4"
    Another wizard comes up with the following
    "v=spf1 ip4:1.2.3.4 ?all"
    Another wizard comes up with the following
    "v=spf1 ip4:1.2.3.4 -all"
    Any advice appreciated.
    Trevor

    Hi
    No ones mentioned this that I;ve seen. But the SPF settings get applied to the domain at Nameserver level, so not on the local server, but wherever is configured that
    www.mydomain.com - goes to 10.20.30.40 and remote.mydomain.com goes to 1.2.3.4 and mail.mydomain.com go to 1.2.3.4 etc
    On the name server you set up a new TXT for .mydomain.com
    the values need to have
    v=spf1 - to show this is the SPF settings
    I would then add the IP's and Domains of any PC authorised to send emails on your behalf
    i.e. +ip4:1.2.3.4 +a:mail.mydomain.com +a:remote.mydomain.com - This covers your server doing email directly from it... some SPF servers I've found look for the a record and not IP when tracing back (usually pain ones, so never hurts to add as resolves
    to same place)
    If your website hosted elsewhere has an email form on it you'll need to authorise your webserver to send on your behalf as it will most likely send from a @mydomain.com email address (your own server could class it as spam if not included)
    so +ip4:x.x.x.x(webserver IP) +a:www.mydomain.com
    As for the all bit
    -all is best - means no one else can pretend to be you. I;ve not used ?all, but due to the experience I'm about to explain it could be useful (saves having to use ~all which makes spf pointless)
    If you use -all SPF checkers will only allow emails to come from authorised senders. This leads to a problem with people they email without things set up right... had a few problems. A clients customer, had a spam checker that was offsite, that forwards
    the email on to the server. so email goes from SenderA to SpamCheckerB. SpamCheckerB scans the email and then forwards on to mailserverC
    MailserverC is also set up to check for spam including SPF..... problems is the email has been 'officially' sent from SpamcheckerB and not SenderA.... thus gets rejected by SPF
    If senderA doesn;t use SPF it all goes through fine, or if SPF set to ~all goes through fine
    Obviously this is a bad set up at the customers end, but if your client or yourself can not send to certain customers (no matter how misconfigured they are, and it being their fault) has a knock on to the business
    So please be aware of that if you use -all which is obviously best. Not sure what ?all would do in this case...
    so my setting for your SPF would be
    v=spf1 +ip4:1.2.3.4 +a:mail.mydomain.com +a:remote.mydomain.com +ip4:x.x.x.x(webserver IP) +a:www.mydomain.com -all
    Hope this helps and gives you some trouble shooting ideas in advance

  • SPF record confusion

    I've read through a number of forum posts here and elsewhere and still find this a confusing thing to setup.  I believe it is partly because of the way terminology is being used.
    We host our own email on Exchange 2010 servers and have a number of email domains.
    domaina.com
    domainb.com
    domainc.com
    domaind.com
    The mx records for all the above domains look like: mail.domaina.com IPADDRESS (same for domain b, domain c, etc).
    We use an external email filtering service.  As a result, our MX records list the filtering service addresses as the highest priority, with our own mail host listed last: mail.ourdomain.com
    We only send mail from our own email servers.  We do not relay any of our email to another server for delivery to the internet.  We do not use the email filtering service for any outbound email.
    I only want to include the three servers of ours that deliver mail to the internet in our SPF record.
    In the past, when I have done a telnet session to test SMTP from another server inside our network to one of the outbound servers, our server might respond with a different hostname in the HELO/EHLO (one of the four different mail.domaina.com, mail.domainb.com,
    mail.domainc.com or mail.domaind.com hostnames).  For the example, I will say that mail.domaina.com is our primary mail domain which also matches the subject name on our SSL certificates.
    Using a number of different SPF record generating tools, I come up with different SPF records and reading the SPF record creation guidelines, I don't find it any more clear.
    Some of the tools even suggest that the email server names be included in the SPF record.  Here is what was suggested, more or less, by the SPF record generating tools:
    "v=spf1 mx a a:hubtransportserver1.domaina.com a:hubtransportserver2.domaina.com a:hubtransportserver3.domaina.com ip4:xxx.xxx.xxx.202/31 ~all"
    I used a CIDR calculator to convert the three public IP addresses used by our outbound email servers to generate the CIDR range.
    With the information above, can anyone offer guidance on what the proper SPF record format is?  The Microsoft SPF tool is still broken - you can't add more than one mx record domain, no matter how you enter them in the box.  It will work if you only
    enter one mx record domain.
    Any help is appreciated!

    it should have the IP addresses or the domain name of all the server which is authorized to receive the email for your domain 
    Example:
    "v=spf1 ip4:192.168.0.1/16 -all"
    example.com. IN TXT "v=spf1 include:example.net -all"
    ; AND
    example1.com. IN SPF "v=spf1 include:example1.net -all"

  • How do I add the country code to all contacts when it did not previously appear?

    I just moved from the US to the UK and purchased a new iPhone 4S.  When my contacts migrated from Outlook to the iPhone they did not include the country code in the US and therefore all contacts numbers are now listed incorrectly.  How can I add the country code to hundreds of contacts painlessly?
    Thanks in advance.

    International Assist is activated.  Upon further review this appears to be a case of the original country codes not being added when the contact list was constructed.  iOS has not figured this out and thus when changing countries I've been forced to add the country codes to every contact record manually.  Disappointing and very labour intensive.  If only Apple allowed for a macro that simplified the mass change.

  • How do I add more channels to my input source?

    I'm trying to record my son's band on a iBook in the rehearsal studio, and would like to also do this type of recording on my iMac here at home, so how do I add more channels to my input source for simultaneous multi-track recording. Right now I am only getting 2 mono and 1 stereo channels.
    Ultimately I would like to add the maximum amount (probably 8 tracks), and still be able to record simultaneously with at least one guitar, one bass, one vocal mike, and the drums on one mike...
    According to Hangtimes/Garage Door website, this is a possibility, but first I must create more channels.
    Please help. THANKS...

    shidoobie wrote:
    My input source is a Tascam US-144 USB Interface that has 2 mic in's, and 2 line in's for guitar/bass.
    I would like to separately record each input on different channels simultaneously.
    You might also want to check out the M-Audio NRV10, which is a hybrid analog mixer + firewire audio interface (with I think around 10 simultaneously available separate channels), which makes it very "band friendly" for both rehearsal and recording.

  • How can I add a attachment field to my new form list

    I have the setting checked yes for attachments. Then I click on the edit tab above then attach file, once I attach the file, it disappears and I cant see it after the record is saved. So how would I add a attachment to a record?

    Hi Soupi,
    From your description, my understanding is that you want to show attachments in list view.
    By default, the list view only contain the Title column. If you want to show whether there is an attechment in an item, you can modify the view and show the Attachments column as Clicking List->Modify View, check "Attachments" in Columns section.
    After the above, the result is like:
    In the above image, test1 has an attachment, test1 doesn't have attachments.
    Thanks,
    Wendy
    TechNet Community Support
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact
    [email protected]

Maybe you are looking for

  • WBS assignment in Network

    Hi All, We have developed new report with copy of std report-KALR and the output is coming as excepted in business requirement but the report execution performance is very slow. So i have discussed with technical team about this performance issue and

  • Stop switching networks

    How do I get my Linksys WRT54G2 router from automatically switching networks? When it does this I get limited or no connectivity to the internet on my pc.

  • Copying videos back from Iphone 4 to laptop

    I have few videos that were copied to Iphone through iTunes using my laptop. Now the laptop HDD is gone bad and i had replaced with a new one. I want those videos copied back to my laptop from IPhone. How do i do that.

  • Production order with un expected changes

    Dear sir, i have created a production with issue method manual for quantity 20 (parent item) , then i issue components for production with status released, now if quantity that is issued is 100(child item) let us take 30 is consumed ,to produced some

  • Starting javaserver difficult problem

    I have installed j2se 1.3.1 and j2ee 1.3.1. I have followed and debugged the .bat files for starting the j2ee server. I am now at the point where I get the following errors: when executing the j2ee.bat: No local string for binding.datasource No local