Mailing List Archive

The SPF records on my domain
Hello

I have setup a SPF record on my domain whyall-systems.co.uk.

But it doesnt get picked up by the validator at
http://www.kitterman.com/spf/validate.html, it doesnt show an SPF record.

Can anyone else help explain why ?

Ben


-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com
Re: The SPF records on my domain [ In reply to ]
On Sun, Jan 24, 2010 at 21:22, Ben Whyall <ben@whyall-systems.co.uk> wrote:
> Hello
>
> I have setup a SPF record on my domain whyall-systems.co.uk.
>
> But it doesnt get picked up by the validator at
> http://www.kitterman.com/spf/validate.html, it doesnt show an SPF record.
>
> Can anyone else help explain why ?

At a random guess, you've either published it on your LAN's DNS
server, or you worked your way through the wizard to generate a record
and assumed that that somehow published it on your domain's DNS
server.

How did you create the record? How have you published it?

--
Please keep list traffic on the list.

Rob MacGregor
Whoever fights monsters should see to it that in the process he
doesn't become a monster. Friedrich Nietzsche


-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com
Re: The SPF records on my domain [ In reply to ]
On 24/01/2010 21:35, Rob MacGregor wrote:
> On Sun, Jan 24, 2010 at 21:22, Ben Whyall<ben@whyall-systems.co.uk> wrote:
>> Hello
>>
>> I have setup a SPF record on my domain whyall-systems.co.uk.
>>
>> But it doesnt get picked up by the validator at
>> http://www.kitterman.com/spf/validate.html, it doesnt show an SPF record.
>>
>> Can anyone else help explain why ?
>
> At a random guess, you've either published it on your LAN's DNS
> server, or you worked your way through the wizard to generate a record
> and assumed that that somehow published it on your domain's DNS
> server.
>
> How did you create the record? How have you published it?
>
I used the wizard to generate the relevant DNS entry for my domain.

I have then added it to the authorative DNS server for my domain
ns.awke.co.uk.

Bind has been restarted since I made the change.

I can post a link to a copy of the zone file if it is of any help ?

Thanks

Ben


-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com
Re: The SPF records on my domain [ In reply to ]
On 24/01/2010 21:35, Rob MacGregor wrote:
> On Sun, Jan 24, 2010 at 21:22, Ben Whyall<ben@whyall-systems.co.uk> wrote:
>> Hello
>>
>> I have setup a SPF record on my domain whyall-systems.co.uk.
>>
>> But it doesnt get picked up by the validator at
>> http://www.kitterman.com/spf/validate.html, it doesnt show an SPF record.
>>
>> Can anyone else help explain why ?
>
> At a random guess, you've either published it on your LAN's DNS
> server, or you worked your way through the wizard to generate a record
> and assumed that that somehow published it on your domain's DNS
> server.
>
> How did you create the record? How have you published it?
>
I should add as well that
http://network-tools.com/default.asp?prog=dnsrec&host=whyall-systems.co.uk

shows

Whois (IDN Conversion Tool)

Express
DNS Records (Advanced Tool)
Network Lookup
Spam Blacklist Check
Convert Base-10 to IP

URL Decode
URL Encode
HTTP Headers SSL
Email Verification

Retrieving DNS records for whyall-systems.co.uk...

DNS servers
ns.awke.co.uk

Answer records
whyall-systems.co.uk TXT v=spf1 mx ~all


Ben


-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com
Re: The SPF records on my domain [ In reply to ]
On Sun, Jan 24, 2010 at 21:42, Ben Whyall <ben@whyall-systems.co.uk> wrote:
> I used the wizard to generate the relevant DNS entry for my domain.
>
> I have then added it to the authorative DNS server for my domain
> ns.awke.co.uk.

Did you remember to increment the serial number? The current serial
number suggests the last change was 3 days ago.

--
Please keep list traffic on the list.

Rob MacGregor
Whoever fights monsters should see to it that in the process he
doesn't become a monster. Friedrich Nietzsche


-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com
Re: The SPF records on my domain [ In reply to ]
On 24/01/2010 21:47, Rob MacGregor wrote:
> On Sun, Jan 24, 2010 at 21:42, Ben Whyall<ben@whyall-systems.co.uk> wrote:
>> I used the wizard to generate the relevant DNS entry for my domain.
>>
>> I have then added it to the authorative DNS server for my domain
>> ns.awke.co.uk.
>
> Did you remember to increment the serial number? The current serial
> number suggests the last change was 3 days ago.
>
I thought I had, but to be absolutely sure I have incremented the
serial, I'd be grateful if you could check and see at some point, I
currently have a ttl of 300 on the dns records.

Thanks

Ben


-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com
Re: The SPF records on my domain [ In reply to ]
On Sun, Jan 24, 2010 at 22:11, Ben Whyall <ben@whyall-systems.co.uk> wrote:

> I thought I had, but to be absolutely sure I have incremented the serial,
> I'd be grateful if you could check and see at some point, I currently have a
> ttl of 300 on the dns records.

The TXT record is visible now.

--
Please keep list traffic on the list.

Rob MacGregor
Whoever fights monsters should see to it that in the process he
doesn't become a monster. Friedrich Nietzsche


-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com
Re: The SPF records on my domain [ In reply to ]
At 21:22 24/01/2010 Sunday, Ben Whyall wrote:
>Hello
>
>I have setup a SPF record on my domain whyall-systems.co.uk.
>
>But it doesnt get picked up by the validator at http://www.kitterman.com/spf/validate.html, it doesnt show an SPF record.
>
>Can anyone else help explain why ?
>
>Ben

ok looks like your spf issues are solved now the question everyone should be asking is WHY?

A you have only 1 dns server in your zone file when every registrar and BCP document insists {so you don't cause the rest up us grief when that server is down} that every domain has a minimum of 2 [how did you get past the .co.uk rules??]

B why do you have the SPF record of MX ~all {forcing receivers to perform at least {1 txt,1 mx,1 a} three lookups when you could have either gone with a:thetaserver.awke.co.uk ~all 2 lookups {but good if it could move ip with little notice}, or ip4?:212.13.216.213/32 ~all 1 lookup {3 times faster performance} {if movement unlikely}

C the domain yours depends on awke.co.uk has overboard {but better than none} DNS redundancy {but some of the free secondaries mentioned have shut down quite some time ago vcsweb for example, and should be removed for the sake of client resolvers}



-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com
Re: The SPF records on my domain [ In reply to ]
>
> ok looks like your spf issues are solved now the question everyone should be asking is WHY?
>
> A you have only 1 dns server in your zone file when every registrar and BCP document insists {so you don't cause the rest up us grief when that server is down} that every domain has a minimum of 2 [how did you get past the .co.uk rules??]
>
> B why do you have the SPF record of MX ~all {forcing receivers to perform at least {1 txt,1 mx,1 a} three lookups when you could have either gone with a:thetaserver.awke.co.uk ~all 2 lookups {but good if it could move ip with little notice}, or ip4?:212.13.216.213/32 ~all 1 lookup {3 times faster performance} {if movement unlikely}
>
> C the domain yours depends on awke.co.uk has overboard {but better than none} DNS redundancy {but some of the free secondaries mentioned have shut down quite some time ago vcsweb for example, and should be removed for the sake of client resolvers}
>

Interestingly the SPF validator still claims that my domain does not
have a SPF record.

The answer to B is that is what the wizard generated for me.

We are currently undertaking a sort out of the name resolution for all
of the domains we hold the registration of, but our registrar seems to
be slow in responding to our support request.


Ben


-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com
Re: The SPF records on my domain [ In reply to ]
On Mon, Jan 25, 2010 at 08:33, Ben Whyall <ben@whyall-systems.co.uk> wrote:
>
> Interestingly the SPF validator still claims that my domain does not have a
> SPF record.

Probably because your old record is still cached according to the TTL
that was in place at the time.

> The answer to B is that is what the wizard generated for me.

The wizard is a good starting point, but imperfect ;)

> We are currently undertaking a sort out of the name resolution for all of
> the domains we hold the registration of, but our registrar seems to be slow
> in responding to our support request.

Time for a new registrar?

--
Please keep list traffic on the list.

Rob MacGregor
Whoever fights monsters should see to it that in the process he
doesn't become a monster. Friedrich Nietzsche


-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com
Re: The SPF records on my domain [ In reply to ]
At 08:33 25/01/2010 Monday, Ben Whyall wrote:


>>ok looks like your spf issues are solved now the question everyone should be asking is WHY?
>>
>>A you have only 1 dns server in your zone file when every registrar and BCP document insists {so you don't cause the rest up us grief when that server is down} that every domain has a minimum of 2 [how did you get past the .co.uk rules??]
>>
>>B why do you have the SPF record of MX ~all {forcing receivers to perform at least {1 txt,1 mx,1 a} three lookups when you could have either gone with a:thetaserver.awke.co.uk ~all 2 lookups {but good if it could move ip with little notice}, or ip4?:212.13.216.213/32 ~all 1 lookup {3 times faster performance} {if movement unlikely}
>>
>>C the domain yours depends on awke.co.uk has overboard {but better than none} DNS redundancy {but some of the free secondaries mentioned have shut down quite some time ago vcsweb for example, and should be removed for the sake of client resolvers}
>
>Interestingly the SPF validator still claims that my domain does not have a SPF record.
>
>The answer to B is that is what the wizard generated for me.
>
>We are currently undertaking a sort out of the name resolution for all of the domains we hold the registration of, but our registrar seems to be slow in responding to our support request.

yup seeing same here, but guessing the last records were cached with your previous {sane} TTL not the current insanely short values {that will NOT speed up propagation}, [.or because your ttls are so insanely short the dns-caches ignore them and use the default 24h instead, pure guessing here]

[.TTL's only speed propagation if new ttl becomes part of zone record on all dns servers 1+old-TTL seconds before the actual propagated change happens]
ie i reduce my ttls on midnight thursday from 24 hours to one hour {sometimes 30mins never less} if i plan to make the dns change on saturday 1am {on sat 1am I put the ttls back to 24 hours if unlikely to reverse the change}

so the 5 minute ttl is doing you no good at all {and potentially making your servers busy enough some may fail to get timely updates} it will still take old TTL amount of time before my ISP or any other DNS-CACHE will see the changes, and may be causing everyone to ignore your ttl's altogether

>set type=txt

>whyall-systems.co.uk

whyall-systems.co.uk
primary name server = ns.awke.co.uk
responsible mail addr = dns.awke.co.uk
serial = 2010012101
refresh = 300 (5 mins)
retry = 300 (5 mins)
expire = 2419200 (28 days)
default TTL = 300 (5 mins)
> server ns.awke.co.uk
Default Server: ns.awke.co.uk
Address: 212.13.216.213

> whyall-systems.co.uk.
Server: ns.awke.co.uk
Address: 212.13.216.213

whyall-systems.co.uk text =

"v=spf1 mx ~all"
whyall-systems.co.uk nameserver = ns.awke.co.uk
ns.awke.co.uk internet address = 212.13.216.213
> set type=soa
> whyall-systems.co.uk.
Server: ns.awke.co.uk
Address: 212.13.216.213

whyall-systems.co.uk
primary name server = ns.awke.co.uk
responsible mail addr = dns.awke.co.uk
serial = 2010012402
refresh = 300 (5 mins)
retry = 300 (5 mins)
expire = 2419200 (28 days)
default TTL = 300 (5 mins)
whyall-systems.co.uk nameserver = ns.awke.co.uk
ns.awke.co.uk internet address = 212.13.216.213



-------------------------------------------
Sender Policy Framework: http://www.openspf.org [http://www.openspf.org]
Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]

Archives: https://www.listbox.com/member/archive/1020/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1020/
Powered by Listbox: http://www.listbox.com