Educause Security Discussion mailing list archives
Re: Anyone using SPF/SRS/SenderID ?
From: Ed Gibson <egibson () UWO CA>
Date: Wed, 6 Jan 2010 14:49:39 -0500
Hi Andrew We set our SPF record to hard fail approximately 6 months ago. We have seen a significant decline as far as our email addresses being spoofed for the purposes of SPAM delivery as a result. This change has not been painless however, as we are stumbling across a number of web services that post email communications as from our domain. A example of this would be the online survey system SurveyMonkey http://www.surveymonkey.com When a user posts a survey through this service the resulting email notifications are posted as "from" our mail domain even though it originates from their mail servers, which of course fails the SPF test. We have made some inroads on getting these sites to change there configuration to adhere to SPF rules. SurveyMonkey would be an example were this change has been determined as a "feature enhancement" by there first line support. We have been utilizing SRS to address the forwarding issues that surface with the use of SPF. We are continuing to stick to our hard fail position... But are also bleeding as a result. Ed Gibson ITS Technical Services Manager University of Western Ontario Andrew Daviel wrote:
Following the hype a few years back, I created an SPF record for us. But because of the problems with road warriors and mail forwarding, it's still set to "neutral". I've had SRS on my to-do list for a while, and was just looking at a project which integrates SRS into sendmail. Is anyone actually using this, or is it a technology of interest only to bulk mailers ? (I understand that many universities are also bulk mailers, but I guess they may outsource this) If I understand this stuff correctly, our SPF record says "mail from example.com may or may not come from 192.168/16", because 1) some users are on sabbatical at example.ac.uk, and mail out via 172.16/12 as joe () example com 2) users from example.ac.uk on sabbatical here may forward mail from bert () example com to bert () example ac uk, which will see it coming from 192.168/16 instead of the original domain 3) users from Britain on sabbatical in Japan have mail for ann () example ac uk forwarded to ann () example ac jp. If fred () example com mails ann () example ac uk, example.ac.jp will see it coming from 172.16/12 not 192.168/16 #1 we can fix through education. Many people now use webmail which sidesteps the issue #2 we can fix with SRS which rewrites the return path #3 we have no control over. If we set our SPF record to "fail" then we need example.ac.uk to implement SRS otherwise example.ac.jp could reject mail from fred () example com as spam https://www.microsoft.com/presspass/press/2007/apr07/04-18SenderIDPR.mspx "Sender ID Framework Reaches Tipping Point" http://www.openspf.org/SRS http://www.openspf.org/ (I see that senderID and SPF are different but confused to the point of senderID potentially borking some SPF users :-( ) senderID I think requires forwarders to add a "Sender" or "Resent-From" header, but I haven't fully checked.
Current thread:
- Anyone using SPF/SRS/SenderID ? Andrew Daviel (Jan 05)
- <Possible follow-ups>
- Re: Anyone using SPF/SRS/SenderID ? Jesse Thompson (Jan 06)
- Re: Anyone using SPF/SRS/SenderID ? Ed Gibson (Jan 06)
- Re: Anyone using SPF/SRS/SenderID ? Jesse Thompson (Jan 07)
- Re: Anyone using SPF/SRS/SenderID ? Andrew Daviel (Jan 07)
- Re: Anyone using SPF/SRS/SenderID ? Jesse Thompson (Jan 08)
