Mailing List Archive

strange SPF thing
Hello,

we (@maas-services.com) are publishing our SPF records for a couple of
months.


I Found this problem today:

example:

there are 3 domains / 3 users involved :
domainA with user1
domainB with user2
domainC with user3

domainA has a SPF-record that says something like "v=spf1 MX -all"
user2@domainB has a forward to user3@domainC

The folowing is happening:

user1@domainA is sending an email to user2@domainB
the forward mechanism of the mail-service @ domainB sends a copy to
user3@domainC
BUT the mail-server @ domainC does a SPF-check and rejects the message
because the mail-sender is not the MX of domainA

1) is this correct behaviour?
2) when yes: I think this can/should not be the intention of SPF


regards
Henrie Cuijpers



-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com
Re: strange SPF thing [ In reply to ]
Hi,

This is normal behaviour, see:

http://spf.pobox.com/faq.html#forwarding
http://spf.pobox.com/objections.html
http://www.libsrs2.org/docs/index.html

In short, the forwarder should do srs or the receiving end (party 3 in
your example) should whitelist the forwarder (provided that he trusts
the forwarder to do spf checking on the inbound side).

Koen


On Wed, Sep 22, 2004 at 12:04:16PM +0200, H.F.A.A. Cuijpers wrote:
> Hello,
>
> we (@maas-services.com) are publishing our SPF records for a couple of
> months.
>
>
> I Found this problem today:
>
> example:
>
> there are 3 domains / 3 users involved :
> domainA with user1
> domainB with user2
> domainC with user3
>
> domainA has a SPF-record that says something like "v=spf1 MX -all"
> user2@domainB has a forward to user3@domainC
>
> The folowing is happening:
>
> user1@domainA is sending an email to user2@domainB
> the forward mechanism of the mail-service @ domainB sends a copy to
> user3@domainC
> BUT the mail-server @ domainC does a SPF-check and rejects the message
> because the mail-sender is not the MX of domainA
>
> 1) is this correct behaviour?
> 2) when yes: I think this can/should not be the intention of SPF
>
>
> regards
> Henrie Cuijpers
>
>
>
> -------
> Archives at http://archives.listbox.com/spf-help/current/
> Donate! http://spf.pobox.com/donations.html
> To unsubscribe, change your address, or temporarily deactivate your subscription,
> please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com

--
K.F.J. Martens, Sonologic, http://www.sonologic.nl/
Networking, embedded systems, unix expertise, artificial intelligence.
Public PGP key: http://www.metro.cx/pubkey-gmc.asc
Wondering about the funny attachment your mail program
can't read? Visit http://www.openpgp.org/

-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com