Mailing List Archive

Help setting up my SPF listing
Hi all,

Okay, although I am generally familiar with SPF, as to the
task of setting up a text file, I am a new comer.

Here is what I have done so far. I have one domain,
learnsteps4profit.com. The IP address for this domain is
66.70.231.191.

Going through the wizard, I answered yes to the first two
questions and no to the third question.

The wizard picked up the MX server is with erato.host4u.net
and made the appropriate entries.

However, it did not pick up the PTR entry. I am a bit
confused with the PTR entry, but that's ok, I will treat
this as a black box and have faith:-)

Now in response to the question "Could mail from
learnsteps4profit.com originate through servers belonging
to some other domain? If you send mail through your ISP's
servers, name the ISP here," I entered my ISP's domain
which in this case is sympatico.ca.

Also, I use two list servers; sequential auto responders
with third parties to send mail for my domain to people who
have granted me affirmative consent to receive my online
publications.

So would I enter there domains here as well, being
aweber.com; goldbar.net?

This generates a text file for the domain
learnsteps4profit.com as follows:

v=spf1 a mx a:erato.host4u.net ip4:216.98.145.241
ip4:207.106.239.74 include:sympatico.ca;
include:aweber.com; include:goldbar.net ~all

Now, do I need to modify this by adding PTR, so the text
string would in fact read:

v=spf1 a mx a:erato.host4u.net ip4:216.98.145.241
ip4:207.106.239.74 include:sympatico.ca;
include:aweber.com; include:goldbar.net ptr ~all

And since I have been following the recent discussions, I
notice folks are recommending ?all as the last entry.

Therefore for the moment the text entry would like:

v=spf1 a mx a:erato.host4u.net ip4:216.98.145.241
ip4:207.106.239.74 include:sympatico.ca;
include:aweber.com; include:goldbar.net ptr ?all

As a result, the BIND entry would look like:

learnsteps4profit.com. IN TXT "v=spf1 a mx
a:erato.host4u.net ip4:216.98.145.241 ip4:207.106.239.74
include:sympatico.ca; include:aweber.com;
include:goldbar.net ptr ?all"

And also there should be the following entry in DNS for:
mail.learnsteps4profit.com. IN TXT "v=spf1 a -all"

Is it correct to use -all or should I be using ?all based
on the recent discussions?

And if my web host runs tinydns (djbdns)
'learnsteps4profit.com:v=spf1 a mx a\072erato.host4u.net
ip4\072216.98.145.241 ip4\072207.106.239.74
include\072sympatico.ca; include\072aweber.com;
include\072goldbar.net ptr ?all:3600
'mail.learnsteps4profit.com:v=spf1 a -all:3600

Now the wizard suggests after putting these records into
DNS, it is suggested I register at the SPF registry.

However I note the SPF registry is not working. Can someone
elaborate?

Also, if I send email from one of the list services I use,
with learnsteps4profit.com in the from line, does the list
service domain have to have an SPF listing in its DNS file
for the authentication process to work?

This is what I gleaned from reading through everything and
it makes sense, but I just want to make sure.

I appreciate any assistance. Thanks.

John

P.S. Please note, although I am subscribed through
john@learnsteps4profit.com, I am sending this from my
personal email address.

P.P.S I have sent inquiries to one of the list service
firms I use suggesting they set up SPF text files in their
DNS files, as suggested in the wizard:-)
 
John Glube
Toronto, Canada
 
voice: 416-535-6366; mailto:john@learnsteps4profit.com
 


---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.701 / Virus Database: 458 - Release Date: 07/06/2004


-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com
RE: Help setting up my SPF listing [ In reply to ]
I'm not an expert, but I think I can answer some of your questions.
Spf-help doesn't seem to get a lot of traffic. You might want to consider
posting on spf-discuss. It seems to be a lot more dynamic...

More below....
> -----Original Message-----
> From: owner-spf-help@v2.listbox.com
> [mailto:owner-spf-help@v2.listbox.com]On Behalf Of John Glube
> Sent: Monday, June 14, 2004 7:22 AM
> To: spf-help@v2.listbox.com
> Subject: [spf-help] Help setting up my SPF listing
>
>
> Hi all,
>
> Okay, although I am generally familiar with SPF, as to the
> task of setting up a text file, I am a new comer.
>
> Here is what I have done so far. I have one domain,
> learnsteps4profit.com. The IP address for this domain is
> 66.70.231.191.
>
> Going through the wizard, I answered yes to the first two
> questions and no to the third question.
>
> The wizard picked up the MX server is with erato.host4u.net
> and made the appropriate entries.
>
> However, it did not pick up the PTR entry. I am a bit
> confused with the PTR entry, but that's ok, I will treat
> this as a black box and have faith:-)

You may not need to have a PTR entry. I'd say don't add it unless you see a
reason to do so. IIRC the wizard doesn't do PTR, so any PTR mechanism you
needed would have to be figured out by hand.

>
> Now in response to the question "Could mail from
> learnsteps4profit.com originate through servers belonging
> to some other domain? If you send mail through your ISP's
> servers, name the ISP here," I entered my ISP's domain
> which in this case is sympatico.ca.
>
> Also, I use two list servers; sequential auto responders
> with third parties to send mail for my domain to people who
> have granted me affirmative consent to receive my online
> publications.
>
> So would I enter there domains here as well, being
> aweber.com; goldbar.net?
>
> This generates a text file for the domain
> learnsteps4profit.com as follows:
>
> v=spf1 a mx a:erato.host4u.net ip4:216.98.145.241
> ip4:207.106.239.74 include:sympatico.ca;
> include:aweber.com; include:goldbar.net ~all

The includes will only work if those domains publish SPF records. If they
don't, it will return error.

Using DigIt (http://us.mirror.menandmice.com/cgi-bin/DoDig)

sympatico.ca.
aweber.com. 3600 TXT "v=spf1 a mx ptr -all"
goldbar.net.

So, only aweber.com currently publishes SPF records. What you are going to
have to do for now for sympatico.ca and goldbar.net is try and figure out
what server(s) they use and guess what an appropriate SPF entry would be.
I've had to do the same for comcast.net and verizon.net (although they've
since published an SPF record).

>
> Now, do I need to modify this by adding PTR, so the text
> string would in fact read:

As I mentioned above, not sure what you want to add that (may be my
ignorance at work here).
>
> v=spf1 a mx a:erato.host4u.net ip4:216.98.145.241
> ip4:207.106.239.74 include:sympatico.ca;
> include:aweber.com; include:goldbar.net ptr ~all
>
> And since I have been following the recent discussions, I
> notice folks are recommending ?all as the last entry.
>
> Therefore for the moment the text entry would like:
>
> v=spf1 a mx a:erato.host4u.net ip4:216.98.145.241
> ip4:207.106.239.74 include:sympatico.ca;
> include:aweber.com; include:goldbar.net ptr ?all
>
> As a result, the BIND entry would look like:
>
> learnsteps4profit.com. IN TXT "v=spf1 a mx
> a:erato.host4u.net ip4:216.98.145.241 ip4:207.106.239.74
> include:sympatico.ca; include:aweber.com;
> include:goldbar.net ptr ?all"
>
> And also there should be the following entry in DNS for:
> mail.learnsteps4profit.com. IN TXT "v=spf1 a -all"
>
> Is it correct to use -all or should I be using ?all based
> on the recent discussions?

It depends on what you are doing. So far, I've only published -all for
domains that never send e-mail. You might want to start with ?all or ~all
until you are sure you understand all the implications.
>
> And if my web host runs tinydns (djbdns)
> 'learnsteps4profit.com:v=spf1 a mx a\072erato.host4u.net
> ip4\072216.98.145.241 ip4\072207.106.239.74
> include\072sympatico.ca; include\072aweber.com;
> include\072goldbar.net ptr ?all:3600
> 'mail.learnsteps4profit.com:v=spf1 a -all:3600
>
> Now the wizard suggests after putting these records into
> DNS, it is suggested I register at the SPF registry.
>
> However I note the SPF registry is not working. Can someone
> elaborate?

In my experince, it is often overloaded. The registry isn't required to
make SPF work, but it good for SPF to register (more domains=more interest).
Also, they have a validator that will double check your syntax.
>
> Also, if I send email from one of the list services I use,
> with learnsteps4profit.com in the from line, does the list
> service domain have to have an SPF listing in its DNS file
> for the authentication process to work?

I think you need to see how they send out mail and go from there. If they
say it's coming from you, then they need to be one of your permitted
senders.
>
> This is what I gleaned from reading through everything and
> it makes sense, but I just want to make sure.
>
> I appreciate any assistance. Thanks.
>
> John
>
> P.S. Please note, although I am subscribed through
> john@learnsteps4profit.com, I am sending this from my
> personal email address.
>
> P.P.S I have sent inquiries to one of the list service
> firms I use suggesting they set up SPF text files in their
> DNS files, as suggested in the wizard:-)
>  
> John Glube
> Toronto, Canada
>
Hope that helps.

Scott K

-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com
Re: Help setting up my SPF listing [ In reply to ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Monday 14 June 2004 12:22 pm, Steve Pirk wrote:
> Maybe I am a bit slow, and I missed the discussion,
> but what is ~all or ?all in:
> v=spf1 a mx ptr -all
> ?

The "?" "~" "-" and "+" characters stand for:

+ This is authorized, and if it matches this phrase, it is approved.
? This is unknown, if it matches, pretend you never saw any SPF stuff.
~ This is "softfail". If it matches, it may or may not be approved, and it
probably isn't.
- - This is "fail". If it matches, it isn't approved at all.

If there is no initial character, "+" is implied.

> DoDig for one of my domains returns:
> deathcon.com. 86400 TXT "v=spf1 a mx"
>
> Do I need the "all" if it is a single domain?

If you don't have an "all" terminating clause, I think it defaults to
something like "?all". You should have a terminating clause, however, that
will catch every other case.

> My other main mail domain returns:
> pirk.com. 86400 TXT "v=spf1 a -all"
>
> Are both correct (they are actually the same server, just
> 2 different domains that I send mail "from").

There is an SPF checker you can test. See spf.pobox.com. Also, the SPF RFC
on spf.pobox.com is straightforward and short. It may help if you read it.

- --
Jonathan M. Gardner
Mass Mail Systems Developer, Amazon.com
jonagard@amazon.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQFAzfpyBFeYcclU5Q0RAg16AKCYv2Q+j+vg6PJxBXdkNvH1UQx54wCgztIQ
k2ZM8ZLC6loVO1CoTtj2mXc=
=PVv1
-----END PGP SIGNATURE-----

-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com
RE: Help setting up my SPF listing [ In reply to ]
Maybe I am a bit slow, and I missed the discussion,
but what is ~all or ?all in:
v=spf1 a mx ptr -all
?
DoDig for one of my domains returns:
deathcon.com. 86400 TXT "v=spf1 a mx"

Do I need the "all" if it is a single domain?
My other main mail domain returns:
pirk.com. 86400 TXT "v=spf1 a -all"

Are both correct (they are actually the same server, just
2 different domains that I send mail "from").
--
Steve

On Mon, 14 Jun 2004 spf@kitterman.com wrote:

> I'm not an expert, but I think I can answer some of your questions.
> Spf-help doesn't seem to get a lot of traffic. You might want to consider
> posting on spf-discuss. It seems to be a lot more dynamic...
>
> More below....
>
> The includes will only work if those domains publish SPF records. If they
> don't, it will return error.
>
> Using DigIt (http://us.mirror.menandmice.com/cgi-bin/DoDig)
>
> sympatico.ca.
> aweber.com. 3600 TXT "v=spf1 a mx ptr -all"
> goldbar.net.
>
> So, only aweber.com currently publishes SPF records. What you are going to
> have to do for now for sympatico.ca and goldbar.net is try and figure out
> what server(s) they use and guess what an appropriate SPF entry would be.
> I've had to do the same for comcast.net and verizon.net (although they've
> since published an SPF record).
>

-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com
RE: Help setting up my SPF listing [ In reply to ]
> -----Original Message-----
> From: owner-spf-help@v2.listbox.com
> [mailto:owner-spf-help@v2.listbox.com]On Behalf Of Steve Pirk
> Sent: Monday, June 14, 2004 3:23 PM
> To: spf-help@v2.listbox.com
> Subject: RE: [spf-help] Help setting up my SPF listing
>
>
> Maybe I am a bit slow, and I missed the discussion,
> but what is ~all or ?all in:
> v=spf1 a mx ptr -all
> ?
> DoDig for one of my domains returns:
> deathcon.com. 86400 TXT "v=spf1 a mx"
>
> Do I need the "all" if it is a single domain?
> My other main mail domain returns:
> pirk.com. 86400 TXT "v=spf1 a -all"
>
> Are both correct (they are actually the same server, just
> 2 different domains that I send mail "from").
> --
> Steve
Here is the spec extract that is probably the place to start:

3.3 Default result

If none of the mechanisms match and there is no redirect modifier,
then the result of the SPF query is "neutral". If there is a
redirect modifier, the SPF client proceeds as defined in section 5.1.

Note that SPF records SHOULD always either use a redirect modifier or
an "all" mechanism to explicitly terminate processing.

http://spf.pobox.com/draft-mengwong-spf-01.txt

Scott K


-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com
RE: Help setting up my SPF listing [ In reply to ]
Scott,

I appreciate your taking the time to respond.

You wrote:

"The includes will only work if those domains
publish SPF records. If they don't, it will
return error."

...

"What you are going to have to do for now for
sympatico.ca and goldbar.net is try and figure
out what server(s) they use and guess what an
appropriate SPF entry would be. I've had to do
the same for comcast.net and verizon.net
(although they've since published an SPF record)."

Okay, I can probably do this. Just so I am clear,
I would then add the entry into the include:
sypatico.ca something like:

"include: sympatico.ca v=spf1 a ptr ~all;
include: Goldbar.net v=spf1 a mx ptr ~all;
include: aweber.com"

I just ran the stuff through the wizard and used
the material as generated, except changing the
last entry from -all to ~all.

As you note, since the wizard does not call for
ptr in my situation, it is probably best to leave
it out.

Thanks again for the help.

John

P.S. I gathered from the discuss list SPF was 1
year old on June 10, so thank you Meng Wong and
all the other folks who have been working with
Meng over the last year in bringing SPF to this
stage.

John Glube
Toronto, Canada

voice: 416-535-6366; mailto:john@learnsteps4profit.com

-----Original Message-----
From: owner-spf-help@v2.listbox.com
[mailto:owner-spf-help@v2.listbox.com] On Behalf Of
spf@kitterman.com
Sent: June 14, 2004 2:43 PM
To: spf-help@v2.listbox.com
Subject: RE: [spf-help] Help setting up my SPF listing

I'm not an expert, but I think I can answer some of your
questions.
Spf-help doesn't seem to get a lot of traffic. You might want to
consider
posting on spf-discuss. It seems to be a lot more dynamic...

More below....
> -----Original Message-----
> From: owner-spf-help@v2.listbox.com
> [mailto:owner-spf-help@v2.listbox.com]On Behalf Of John Glube
> Sent: Monday, June 14, 2004 7:22 AM
> To: spf-help@v2.listbox.com
> Subject: [spf-help] Help setting up my SPF listing
>
>
> Hi all,
>
> Okay, although I am generally familiar with SPF, as to the
> task of setting up a text file, I am a new comer.
>
> Here is what I have done so far. I have one domain,
> learnsteps4profit.com. The IP address for this domain is
> 66.70.231.191.
>
> Going through the wizard, I answered yes to the first two
> questions and no to the third question.
>
> The wizard picked up the MX server is with erato.host4u.net
> and made the appropriate entries.
>
> However, it did not pick up the PTR entry. I am a bit
> confused with the PTR entry, but that's ok, I will treat
> this as a black box and have faith:-)

You may not need to have a PTR entry. I'd say don't add it
unless you see a
reason to do so. IIRC the wizard doesn't do PTR, so any PTR
mechanism you
needed would have to be figured out by hand.

>
> Now in response to the question "Could mail from
> learnsteps4profit.com originate through servers belonging
> to some other domain? If you send mail through your ISP's
> servers, name the ISP here," I entered my ISP's domain
> which in this case is sympatico.ca.
>
> Also, I use two list servers; sequential auto responders
> with third parties to send mail for my domain to people who
> have granted me affirmative consent to receive my online
> publications.
>
> So would I enter there domains here as well, being
> aweber.com; goldbar.net?
>
> This generates a text file for the domain
> learnsteps4profit.com as follows:
>
> v=spf1 a mx a:erato.host4u.net ip4:216.98.145.241
> ip4:207.106.239.74 include:sympatico.ca;
> include:aweber.com; include:goldbar.net ~all

The includes will only work if those domains publish SPF records.
If they
don't, it will return error.

Using DigIt (http://us.mirror.menandmice.com/cgi-bin/DoDig)

sympatico.ca.
aweber.com. 3600 TXT "v=spf1 a mx ptr -all"
goldbar.net.

So, only aweber.com currently publishes SPF records. What you
are going to
have to do for now for sympatico.ca and goldbar.net is try and
figure out
what server(s) they use and guess what an appropriate SPF entry
would be.
I've had to do the same for comcast.net and verizon.net (although
they've
since published an SPF record).

>
> Now, do I need to modify this by adding PTR, so the text
> string would in fact read:

As I mentioned above, not sure what you want to add that (may be
my
ignorance at work here).
>
> v=spf1 a mx a:erato.host4u.net ip4:216.98.145.241
> ip4:207.106.239.74 include:sympatico.ca;
> include:aweber.com; include:goldbar.net ptr ~all
>
> And since I have been following the recent discussions, I
> notice folks are recommending ?all as the last entry.
>
> Therefore for the moment the text entry would like:
>
> v=spf1 a mx a:erato.host4u.net ip4:216.98.145.241
> ip4:207.106.239.74 include:sympatico.ca;
> include:aweber.com; include:goldbar.net ptr ?all
>
> As a result, the BIND entry would look like:
>
> learnsteps4profit.com. IN TXT "v=spf1 a mx
> a:erato.host4u.net ip4:216.98.145.241 ip4:207.106.239.74
> include:sympatico.ca; include:aweber.com;
> include:goldbar.net ptr ?all"
>
> And also there should be the following entry in DNS for:
> mail.learnsteps4profit.com. IN TXT "v=spf1 a -all"
>
> Is it correct to use -all or should I be using ?all based
> on the recent discussions?

It depends on what you are doing. So far, I've only published
-all for
domains that never send e-mail. You might want to start with
?all or ~all
until you are sure you understand all the implications.
>
> And if my web host runs tinydns (djbdns)
> 'learnsteps4profit.com:v=spf1 a mx a\072erato.host4u.net
> ip4\072216.98.145.241 ip4\072207.106.239.74
> include\072sympatico.ca; include\072aweber.com;
> include\072goldbar.net ptr ?all:3600
> 'mail.learnsteps4profit.com:v=spf1 a -all:3600
>
> Now the wizard suggests after putting these records into
> DNS, it is suggested I register at the SPF registry.
>
> However I note the SPF registry is not working. Can someone
> elaborate?

In my experince, it is often overloaded. The registry isn't
required to
make SPF work, but it good for SPF to register (more domains=more
interest).
Also, they have a validator that will double check your syntax.
>
> Also, if I send email from one of the list services I use,
> with learnsteps4profit.com in the from line, does the list
> service domain have to have an SPF listing in its DNS file
> for the authentication process to work?

I think you need to see how they send out mail and go from there.
If they
say it's coming from you, then they need to be one of your
permitted
senders.
>
> This is what I gleaned from reading through everything and
> it makes sense, but I just want to make sure.
>
> I appreciate any assistance. Thanks.
>
> John
>
> P.S. Please note, although I am subscribed through
> john@learnsteps4profit.com, I am sending this from my
> personal email address.
>
> P.P.S I have sent inquiries to one of the list service
> firms I use suggesting they set up SPF text files in their
> DNS files, as suggested in the wizard:-)
>  
> John Glube
> Toronto, Canada
>
Hope that helps.

Scott K

-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate
your subscription,
please go to
http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com

---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.701 / Virus Database: 458 - Release Date: 07/06/2004


---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.701 / Virus Database: 458 - Release Date: 07/06/2004


-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com
RE: Help setting up my SPF listing [ In reply to ]
> -----Original Message-----
> From: owner-spf-help@v2.listbox.com
> [mailto:owner-spf-help@v2.listbox.com]On Behalf Of John Glube
> Sent: Monday, June 14, 2004 7:57 PM
> To: spf-help@v2.listbox.com
> Subject: RE: [spf-help] Help setting up my SPF listing
>
>
> Scott,
>
> I appreciate your taking the time to respond.
>
> You wrote:
>
> "The includes will only work if those domains
> publish SPF records. If they don't, it will
> return error."
>
> ...
>
> "What you are going to have to do for now for
> sympatico.ca and goldbar.net is try and figure
> out what server(s) they use and guess what an
> appropriate SPF entry would be. I've had to do
> the same for comcast.net and verizon.net
> (although they've since published an SPF record)."
>
> Okay, I can probably do this. Just so I am clear,
> I would then add the entry into the include:
> sypatico.ca something like:
>
> "include: sympatico.ca v=spf1 a ptr ~all;
> include: Goldbar.net v=spf1 a mx ptr ~all;
> include: aweber.com"
>
> I just ran the stuff through the wizard and used
> the material as generated, except changing the
> last entry from -all to ~all.
>
> As you note, since the wizard does not call for
> ptr in my situation, it is probably best to leave
> it out.
>
> Thanks again for the help.
>
> John
>
No, you can do one of two things...

If they use a single server to send mail, you can use an a record, such as
(I'm making up the server name) - a:relay.sympatico.ca

If they use several servers within one or more defined IP ranges, you can
use something like - ip4:204.127.202.0/24

That BTW, is my guess for comcast.net. Don't know for sure if it's right.

The only time you use include is if the other domain has an SPF record that
you want included in your permitted senders definition. Your include for
aweber.com should be fine. For the other two, you just permit as part of
your record what you think they will be using to send mail.

Scott K

-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com