SPF problems with nznog registration.
um..
This message was created automatically by mail delivery software (Exim).
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
richardn(a)cs.waikato.ac.nz
(generated from registration(a)nznog.org)
SMTP error from remote mailer after MAIL FROM:
The problem arises because your e-mail hit an alias on my mailserver which forwarded it to Richard's Computer Science primary address. There are two issues that arrise because of this. 1) You set an SPF hard failure on your domain, against spf.pobox.com's recommendation. 2) The Computer Science mailer (not in my control) drops hard failures, again, against spf.pobox.com's recommendation. In the middle sits my mail server that doesn't do anything to do with SPF at all. There are two things that I can do to fix this: 1) Install SRS on my mailserver (http://spf.pobox.com/srs.html) 2) Remove all aliases that point to CS's mail server, and host the mailboxes locally. As this is a production mailserver, I don't want to rush out and do (1) right now, but I accept that if SPF is to become widespread, I will have to do this eventually. So, in the meantime, I'll do (2) and people shouldn't have anymore problems. Jamie ----------------------------------------------------------------------- Jamie Curtis office: G.1.01 WAND Group, Dept of Computer Science phone: +64 7 838 4136 University of Waikato, mobile: +64 21 392 102 Hamilton, fax: +64 7 858 5095 New Zealand email: jamie(a)wand.net.nz ----------------------------------------------------------------------- On Thu, 16 Dec 2004, Steve Phillips wrote:
um..
This message was created automatically by mail delivery software (Exim).
A message that you sent could not be delivered to one or more of its recipients. This is a permanent error. The following address(es) failed:
richardn(a)cs.waikato.ac.nz (generated from registration(a)nznog.org) SMTP error from remote mailer after MAIL FROM:
SIZE=1986: host mail.cs.waikato.ac.nz [130.217.241.36]: 550 Please see http://spf.pobox.com/why.html?sender=steve%40focb.co.nz&ip=130.217.250.15&receiver=ghoul ------ This is a copy of the message, including all the headers. ------
Return-path:
Received: from [64.246.60.77] (helo=wibble.focb.co.nz) by warlock.cs.waikato.ac.nz with smtp (Exim 3.35 #1 (Debian)) id 1CegkR-0005mq-00 for ; Thu, 16 Dec 2004 10:31:51 +1300 Received: (qmail 10492 invoked by uid 501); 15 Dec 2004 21:31:49 -0000 Received: from localhost (sendmail-bs(a)127.0.0.1) by localhost with SMTP; 15 Dec 2004 21:31:49 -0000 Date: Wed, 15 Dec 2004 15:31:49 -0600 (CST) From: Steve Phillips To: registration(a)nznog.org Can you guys please fix your registration/mail system ? and someone really should be told that bouncing mail based on SPF records alone is a bad thing [tm] (sending here because I cant seem to mail them directly..)
-- Steve.
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
Sorry I have to disagree with 1. there, I used their wizard to setup my domains and every once and a while I get my mail rejected anyway. From the site for ~all: "SPF queries that do not match any other mechanism will return "softfail". Messages that are not sent from an approved server should still be accepted but may be subjected to greater scrutiny." People who drop/reject mail based on spf records make kittens cry. But I have ranted about that already. Daniel Many people would sooner die than think. In fact they do. Bertrand Russell --Quoted in Antony Flew's Thinking About Thinking Jamie Curtis wrote:
The problem arises because your e-mail hit an alias on my mailserver which forwarded it to Richard's Computer Science primary address.
There are two issues that arrise because of this.
1) You set an SPF hard failure on your domain, against spf.pobox.com's recommendation. 2) The Computer Science mailer (not in my control) drops hard failures, again, against spf.pobox.com's recommendation.
In the middle sits my mail server that doesn't do anything to do with SPF at all.
There are two things that I can do to fix this:
1) Install SRS on my mailserver (http://spf.pobox.com/srs.html) 2) Remove all aliases that point to CS's mail server, and host the mailboxes locally.
As this is a production mailserver, I don't want to rush out and do (1) right now, but I accept that if SPF is to become widespread, I will have to do this eventually.
So, in the meantime, I'll do (2) and people shouldn't have anymore problems.
Jamie
----------------------------------------------------------------------- Jamie Curtis office: G.1.01 WAND Group, Dept of Computer Science phone: +64 7 838 4136 University of Waikato, mobile: +64 21 392 102 Hamilton, fax: +64 7 858 5095 New Zealand email: jamie(a)wand.net.nz -----------------------------------------------------------------------
On Thu, 16 Dec 2004, Steve Phillips wrote:
um..
This message was created automatically by mail delivery software (Exim).
A message that you sent could not be delivered to one or more of its recipients. This is a permanent error. The following address(es) failed:
richardn(a)cs.waikato.ac.nz (generated from registration(a)nznog.org) SMTP error from remote mailer after MAIL FROM:
SIZE=1986: host mail.cs.waikato.ac.nz [130.217.241.36]: 550 Please see http://spf.pobox.com/why.html?sender=steve%40focb.co.nz&ip=130.217.250.15&receiver=ghoul ------ This is a copy of the message, including all the headers. ------
Return-path:
Received: from [64.246.60.77] (helo=wibble.focb.co.nz) by warlock.cs.waikato.ac.nz with smtp (Exim 3.35 #1 (Debian)) id 1CegkR-0005mq-00 for ; Thu, 16 Dec 2004 10:31:51 +1300 Received: (qmail 10492 invoked by uid 501); 15 Dec 2004 21:31:49 -0000 Received: from localhost (sendmail-bs(a)127.0.0.1) by localhost with SMTP; 15 Dec 2004 21:31:49 -0000 Date: Wed, 15 Dec 2004 15:31:49 -0600 (CST) From: Steve Phillips To: registration(a)nznog.org Can you guys please fix your registration/mail system ? and someone really should be told that bouncing mail based on SPF records alone is a bad thing [tm] (sending here because I cant seem to mail them directly..)
-- Steve.
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
Sorry I have to disagree with 1. there, I used their wizard to setup my domains and every once and a while I get my mail rejected anyway. From the site for ~all:
"SPF queries that do not match any other mechanism will return "softfail". Messages that are not sent from an approved server should still be accepted but may be subjected to greater scrutiny."
Steve didn't set a ~all though, he set -all. From the SPF whitepaper: "To Fail or not to Fail? If you look at other sites with spf records, you find that some of them end in ?all, some of them end in ~all, and some end in -all. What should you do? It depends. This is a tradeoff situation: you have to balance competing concerns. Conservative publishers might start with a ?all, move through ~all as conditions change, and (if all goes well) stabilize at -all. (Conditions change means users switch to the approved outbound smtp relay, forwarders start prepending headers and implementing srs, and you start signing with DomainKeys.) If you are very concerned about phishing, publish a -all right away and accept that there may be some false positives due to noncompliant forwarders who are slow to upgrade. Otherwise, use a ~all." So, I take some blame for being a "noncompliant forwarder" but, Steve also should accept if he sets -all then some messages will bounce.
People who drop/reject mail based on spf records make kittens cry. But I have ranted about that already.
I agree, and will talk to the people who administer CS as well. Jamie ----------------------------------------------------------------------- Jamie Curtis office: G.1.01 WAND Group, Dept of Computer Science phone: +64 7 838 4136 University of Waikato, mobile: +64 21 392 102 Hamilton, fax: +64 7 858 5095 New Zealand email: jamie(a)wand.net.nz -----------------------------------------------------------------------
Steve, Your records for focb.co.nz say: $ host -t txt focb.co.nz focb.co.nz text "v=spf1 a:wibble.focb.co.nz -all" Which basicly means *you* are telling everybody to drop any email where the SPF records don't match where the email is coming from. If you change the "-all" to a "?all" or perhaps "~all" then this shouldn't happen. See page 15 of: http://spf.pobox.com/whitepaper.pdf Simon. On Thu, 16 Dec 2004, Steve Phillips wrote:
um..
This message was created automatically by mail delivery software (Exim).
A message that you sent could not be delivered to one or more of its recipients. This is a permanent error. The following address(es) failed:
richardn(a)cs.waikato.ac.nz (generated from registration(a)nznog.org) SMTP error from remote mailer after MAIL FROM:
SIZE=1986: host mail.cs.waikato.ac.nz [130.217.241.36]: 550 Please see http://spf.pobox.com/why.html?sender=steve%40focb.co.nz&ip=130.217.250.15&receiver=ghoul ------ This is a copy of the message, including all the headers. ------
Return-path:
Received: from [64.246.60.77] (helo=wibble.focb.co.nz) by warlock.cs.waikato.ac.nz with smtp (Exim 3.35 #1 (Debian)) id 1CegkR-0005mq-00 for ; Thu, 16 Dec 2004 10:31:51 +1300 Received: (qmail 10492 invoked by uid 501); 15 Dec 2004 21:31:49 -0000 Received: from localhost (sendmail-bs(a)127.0.0.1) by localhost with SMTP; 15 Dec 2004 21:31:49 -0000 Date: Wed, 15 Dec 2004 15:31:49 -0600 (CST) From: Steve Phillips To: registration(a)nznog.org Can you guys please fix your registration/mail system ? and someone really should be told that bouncing mail based on SPF records alone is a bad thing [tm] (sending here because I cant seem to mail them directly..)
-- Steve.
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
-- Simon J. Lyall | Very Busy | Web: http://www.darkmere.gen.nz/ "To stay awake all night adds a day to your life" - Stilgar | eMT.
participants (4)
-
Daniel
-
Jamie Curtis
-
Simon Lyall
-
Steve Phillips