Vic Uni Mail Admin about? SPF rec issue...
I do SPF checking. # grep $user mail.log Sep 10 09:05:48 mx tumgreyspf[13335]: 'SPF Permanent Error: Too many DNS lookups': QUEUE_ID=""; identity=mailfrom; client-ip=216.32.181.183; helo=ch1outboundpool.messaging.microsoft.com; envelope-from=$User(a)vuw.ac.nz; receiver=$user(a)tauatapu.net.nz; vuw.ac.nz IN TXT v=spf1 ip4:130.195.81.0/24 ip4:130.195.86.0/24 ip4:202.36.141.0/24 ip4:216.235.196.0/22 ip4:216.235.200.0/21 include:mcs.vuw.ac.nz include:mailprimer.com include:_spf.learningsourceapp.com include:spf.messaging.microsoft.com ~all 1. Is anyone else having this issue with vuw? 2. Should I be doing something to change my config or do others feel that the vuw spf record is to wide? D -- Don Gould 31 Acheson Ave Mairehau Christchurch, New Zealand Ph: + 64 3 348 7235 Mobile: + 64 21 114 0699
On Sun, Sep 9, 2012 at 5:44 PM, Don Gould
2. Should I be doing something to change my config or do others feel that the vuw spf record is to wide?
* SPF implementations MUST limit the number of mechanisms and modifiers that do DNS lookups to at most 10 per SPF check, including any lookups caused by the use of the "include" mechanism or the "redirect" modifier. If this number is exceeded during a check, a PermError MUST be returned. The "include", "a", "mx", "ptr", and "exists" mechanisms as well as the "redirect" modifier do count against this limit. The "all", "ip4", and "ip6" mechanisms do not require DNS lookups and therefore do not count against this limit. The "exp" modifier does not count against this limit because the DNS lookup to fetch the explanation string occurs after the SPF record has been evaluated. * Scott
Hi Scott, Sorry if I'm being blond, but that didn't answer my question. I am trying to figure out where to point the finger and I don't understand enough of what you posted for me to understand if this is my problem as the mail admin or the vic mail admin? I don't have a function to just whitelist the uni, so if people think that tinyspf is not working correctly then I'll just stop using it. Sorry that my initial question was not very clear. D On 10/09/2012 12:52 p.m., Scott Howard wrote:
On Sun, Sep 9, 2012 at 5:44 PM, Don Gould
mailto:don(a)bowenvale.co.nz> wrote: 2. Should I be doing something to change my config or do others feel that the vuw spf record is to wide?
From http://tools.ietf.org/html/rfc4408#section-10.1 :
/ SPF implementations MUST limit the number of mechanisms and modifiers that do DNS lookups to at most 10 per SPF check, including any lookups caused by the use of the "include" mechanism or the "redirect" modifier. If this number is exceeded during a check, a PermError MUST be returned. The "include", "a", "mx", "ptr", and "exists" mechanisms as well as the "redirect" modifier do count against this limit. The "all", "ip4", and "ip6" mechanisms do not require DNS lookups and therefore do not count against this limit. The "exp" modifier does not count against this limit because the DNS lookup to fetch the explanation string occurs after the SPF record has been evaluated. /
Scott
-- Don Gould 31 Acheson Ave Mairehau Christchurch, New Zealand Ph: + 64 3 348 7235 Mobile: + 64 21 114 0699
The recursive lookups in that SFP record come to 14 according to my
checking.
vuw.ac.nz IN TXT v=spf1 ip4:130.195.81.0/24
ip4:130.195.86.0/24 ip4:202.36.141.0/24 ip4:216.235.196.0/22
ip4:216.235.200.0/21 include:mcs.vuw.ac.nz include:mailprimer.com
include:_spf.learningsourceapp.com include:spf.messaging.microsoft.com ~all
· include:mcs.vuw.ac.nz
o mx
· include:mailprimer.com
o include:mailprimer.net.nz
§ include:mailprimer.co.nz
§ include:mailprimer.com
· include:mailprimer.net.nz (loop?)
· include:_spf.learningsourceapp.com
o include:sendgrid.net
§ include:sendgrid.biz
· include:spf.messaging.microsoft.com
o include:spfa.frontbridge.com
o include:spfb.frontbridge.com
o include:spfc.frontbridge.com
And in answer to your questions it would be the Vic mail admin or DNS
maintainer that needs to look at this.
From: nznog-bounces(a)list.waikato.ac.nz
[mailto:nznog-bounces(a)list.waikato.ac.nz] On Behalf Of Don Gould
Sent: Monday, September 10, 2012 1:06 PM
To: Scott Howard
Cc: nznog
Subject: Re: [nznog] Vic Uni Mail Admin about? SPF rec issue...
Hi Scott,
Sorry if I'm being blond, but that didn't answer my question.
I am trying to figure out where to point the finger and I don't understand
enough of what you posted for me to understand if this is my problem as the
mail admin or the vic mail admin?
I don't have a function to just whitelist the uni, so if people think that
tinyspf is not working correctly then I'll just stop using it.
Sorry that my initial question was not very clear.
D
On 10/09/2012 12:52 p.m., Scott Howard wrote:
On Sun, Sep 9, 2012 at 5:44 PM, Don Gould
SPF implementations MUST limit the number of mechanisms and modifiers that do DNS lookups to at most 10 per SPF check, including any lookups caused by the use of the "include" mechanism or the "redirect" modifier. If this number is exceeded during a check, a PermError MUST be returned. The "include", "a", "mx", "ptr", and "exists" mechanisms as well as the "redirect" modifier do count against this limit. The "all", "ip4", and "ip6" mechanisms do not require DNS lookups and therefore do not count against this limit. The "exp" modifier does not count against this limit because the DNS lookup to fetch the explanation string occurs after the SPF record has been evaluated. Scott -- Don Gould 31 Acheson Ave Mairehau Christchurch, New Zealand Ph: + 64 3 348 7235 Mobile: + 64 21 114 0699
On 10 September 2012 13:09, Tim Price
· include:mailprimer.com
o include:mailprimer.net.nz
§ include:mailprimer.co.nz
§ include:mailprimer.com
· include:mailprimer.net.nz (loop?)
Just a quick note to point out that you've misread 2 MX entries as includes in the SPF for mailprimer.net.nz. The SPF record is: "v=spf1 ip4:66.29.197.150/28 ip4:209.162.176.182/27 ip4:203.79.78.253/32 ip4:203.97.202.158/32 ip4:123.100.96.0/27 ip4:204.14.234.0/25 ip4:10.226.68.0/29 mx:mailprimer.co.nz mx:mailprimer.com ~all" On a related note, check the SPF for microsoft.com at http://www.kitterman.com/spf/validate.html - they're broken in the same way at the moment. Cheers, Mark
Hello to the mail team at the uni! :) They weren't aware that their spf was broken. Thanks to the on and off list help guys. D On 10/09/2012 12:44 p.m., Don Gould wrote:
I do SPF checking.
# grep $user mail.log Sep 10 09:05:48 mx tumgreyspf[13335]: 'SPF Permanent Error: Too many DNS lookups': QUEUE_ID=""; identity=mailfrom; client-ip=216.32.181.183; helo=ch1outboundpool.messaging.microsoft.com; envelope-from=$User(a)vuw.ac.nz; receiver=$user(a)tauatapu.net.nz;
vuw.ac.nz IN TXT v=spf1 ip4:130.195.81.0/24 ip4:130.195.86.0/24 ip4:202.36.141.0/24 ip4:216.235.196.0/22 ip4:216.235.200.0/21 include:mcs.vuw.ac.nz include:mailprimer.com include:_spf.learningsourceapp.com include:spf.messaging.microsoft.com ~all
1. Is anyone else having this issue with vuw?
2. Should I be doing something to change my config or do others feel that the vuw spf record is to wide?
D
-- Don Gould 31 Acheson Ave Mairehau Christchurch, New Zealand Ph: + 64 3 348 7235 Mobile: + 64 21 114 0699
On Mon, 10 Sep 2012, Don Gould wrote:
Hello to the mail team at the uni! :)
They weren't aware that their spf was broken.
Thanks to the on and off list help guys.
I don't think there is anyone from ITS on this list, so glad you got hold of someone. Ick that spf record is ugly. Of course due to their split DNS if you try to look at that from within the University you get % host -t txt vuw.ac.nz vuw.ac.nz descriptive text "" I'll note that the include:mcs.vuw.ac.nz has been "wrong" for the last 3.5 years and should be include:ecs.vuw.ac.nz but, in fact, the one place in the world I would expect to never see @vuw.ac.nz addresses being sent from is ecs.vuw.ac.nz - as we do sender rewriting. cheers mark
participants (5)
-
Don Gould
-
Mark Davies
-
Mark Wakefield
-
Scott Howard
-
Tim Price