Mailing List Archive

spf, mail relay and internal mail forwarders
We have single dmz host (internet IP address) that will relay mail to the
internet from two internal (on 10.0.0.0/8 network) hosts. It also relays
mail from the internet to the internal hosts.

To get the dmz host to relay mail recieved from the two internal hosts, Ive
put the IP addresses with "RELAY" in /etc/mail/access - but with spf turned
on this is not enough - It seems I need to add them to the spf TXT dns
record. Im worried that our security architect will object to the internal
IPs being in an Internet DNS record. Is there a better way?

Thanks

BB

-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com
Re: spf, mail relay and internal mail forwarders [ In reply to ]
http://spf.pobox.com/faq.html#whitelist

On Wed, Aug 11, 2004 at 02:15:05PM +1000, Broun, Bevan wrote:
> We have single dmz host (internet IP address) that will relay mail to the
> internet from two internal (on 10.0.0.0/8 network) hosts. It also relays
> mail from the internet to the internal hosts.
>
> To get the dmz host to relay mail recieved from the two internal hosts, Ive
> put the IP addresses with "RELAY" in /etc/mail/access - but with spf turned
> on this is not enough - It seems I need to add them to the spf TXT dns
> record. Im worried that our security architect will object to the internal
> IPs being in an Internet DNS record. Is there a better way?
>
> Thanks
>
> BB
>
> -------
> Archives at http://archives.listbox.com/spf-help/current/
> Donate! http://spf.pobox.com/donations.html
> To unsubscribe, change your address, or temporarily deactivate your subscription,
> please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com

--
K.F.J. Martens, Sonologic, http://www.sonologic.nl/
Networking, embedded systems, unix expertise, artificial intelligence.
Public PGP key: http://www.metro.cx/pubkey-gmc.asc
Wondering about the funny attachment your mail program
can't read? Visit http://www.openpgp.org/

-------
Archives at http://archives.listbox.com/spf-help/current/
Donate! http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your subscription,
please go to http://v2.listbox.com/member/?listname=spf-help@v2.listbox.com