Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Is anyone using SPF DNS records yet?
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Is anyone using SPF DNS records yet?

 Post Reply Post Reply
Author
dpyers View Drop Down
Senior Member
Senior Member


Joined: 12 May 2003
Status: Offline
Points: 3937
Post Options Post Options   Thanks (0) Thanks(0)   Quote dpyers Quote  Post ReplyReply Direct Link To This Post Topic: Is anyone using SPF DNS records yet?
    Posted: 01 August 2004 at 7:51pm

SPF = Sender Policy Framework - It's a DNS record to allow SMTP receivers to verify email envelope sender address (preventing domain spoofing and phishing), and can distinguish legitimate mail from spam before any message data is transmitted.
If you check out your domain at dnsreport.com, you'll probably see a warning that your domain needs to have one in place by Octber 1, 2004.

Microsoft - being Microsoft - wanted to do something different called Sender-ID - aka "Caller ID For Email"s. Apparently someone got to them because they decided to work with the SPF folk (pobox.com) to implement the functionality.

Bottom line is that MS will implement it for Hotmail within the next 30-60 days and I'm trying to figure out If I'll be able to send to Hotmail accounts if I don't have an SPF record in the domain DNS.

I've been told that many hosts will implement the check in such a fashion that If an incoming email fails the SPF check, it'll be passed to a blacklist checker and only be delivered if it passes that (like it works now). But I haven't been able to find anything saying that's the process Hotmail will use.

Also trying to figure out what this means for the iis smtp server set-up on my local pc.

If anyone has any info about the details behind the Hotmail or local iis smtp server setup, could you please post the info and/or links?

Thanks

EDIT: SPF Guidelines/wizard at http://spf.pobox.com



Edited by dpyers

Lead me not into temptation... I know the short cut, follow me.
Back to Top
the boss View Drop Down
Senior Member
Senior Member
Avatar

Joined: 19 January 2003
Location: Saudi Arabia
Status: Offline
Points: 1727
Post Options Post Options   Thanks (0) Thanks(0)   Quote the boss Quote  Post ReplyReply Direct Link To This Post Posted: 02 August 2004 at 5:08am
best would be to just send the mail to junk folder with a warnbing header that this mail didnt complied with SPF standards and might not be legimate

Back to Top
huwnet View Drop Down
Senior Member
Senior Member


Joined: 30 May 2003
Location: England
Status: Offline
Points: 1375
Post Options Post Options   Thanks (0) Thanks(0)   Quote huwnet Quote  Post ReplyReply Direct Link To This Post Posted: 02 August 2004 at 5:39am
does the ms dns server actually support these records?
What about the main dns server, bind.
Back to Top
huwnet View Drop Down
Senior Member
Senior Member


Joined: 30 May 2003
Location: England
Status: Offline
Points: 1375
Post Options Post Options   Thanks (0) Thanks(0)   Quote huwnet Quote  Post ReplyReply Direct Link To This Post Posted: 02 August 2004 at 5:50am
I am going to contact my host about these records.
Back to Top
Semikolon View Drop Down
Senior Member
Senior Member


Joined: 09 September 2003
Location: Norway
Status: Offline
Points: 1718
Post Options Post Options   Thanks (0) Thanks(0)   Quote Semikolon Quote  Post ReplyReply Direct Link To This Post Posted: 02 August 2004 at 6:40am
new records mean that DNS, SMTP, POP3 and IMAP servers have to be updated right? Damn, everything before 1st October? Damn someone have peed their pants now.. doubt all hosts manage to do it
Back to Top
dpyers View Drop Down
Senior Member
Senior Member


Joined: 12 May 2003
Status: Offline
Points: 3937
Post Options Post Options   Thanks (0) Thanks(0)   Quote dpyers Quote  Post ReplyReply Direct Link To This Post Posted: 02 August 2004 at 8:15am

What I've need able to find out is that initially, Hotmail will check for the SPF record. If it finds one, it'll assume the email is ok. If it doesn't find one, it'll check it against their spam list. Won't be until sometime later ture that they actually block email without an SPF record.

This has actually been in the works for quite some time now although I don't know where the October 1st date came from. Couldn't find any RFC covering it although itwill probably become a formal internet standard within the next 12-24 months.

I was also able to confirm that people using "localhost" as the smtp server for domains with shared ip's, or who use smtp from their local pc's, will be screwed. Going to need to use a mail server specified in the mx records for some domain in order for people to get the email. That's good thing though - it'll stop the spammers/hackers who grab peoples machines and use them to send spam.

It would be a good idea to start converting any code using localhost/127.0.0.1 to the appropriate mail server for your domains.


Lead me not into temptation... I know the short cut, follow me.
Back to Top
Semikolon View Drop Down
Senior Member
Senior Member


Joined: 09 September 2003
Location: Norway
Status: Offline
Points: 1718
Post Options Post Options   Thanks (0) Thanks(0)   Quote Semikolon Quote  Post ReplyReply Direct Link To This Post Posted: 02 August 2004 at 8:47am
I don't even use localhost for development, and at least, I don't send emails outside my local network with my own SMTP server.

but if I use the current version of Win2003, will my own emails be blocked or whatever when SPF is added in the next service pack or whatever if I run in workgroup mode and without a DNS server?
Back to Top
dpyers View Drop Down
Senior Member
Senior Member


Joined: 12 May 2003
Status: Offline
Points: 3937
Post Options Post Options   Thanks (0) Thanks(0)   Quote dpyers Quote  Post ReplyReply Direct Link To This Post Posted: 02 August 2004 at 9:09am

It looks like you'll be able to toggle spf off/on on your own servers, also allow/deny a list of ips/domains. Probably be different for every web/mail server.

Here's the info on SPF http://spf.pobox.com


Lead me not into temptation... I know the short cut, follow me.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.