Solved

E-mail DNS SPF records

Posted on 2016-09-02
7
64 Views
Last Modified: 2016-09-02
How important is a SPF record these days in reference to e-mail DNS?  We are running a SonicWall with the anti-spam filtering enabled which seems to work very well.  However, we have it set to block not just "definite spam" but also, "likely spam".  This being said, will blocking "likely spam" block e-mail that doesn't have an accurate SPF DNS record setup?
0
Comment
Question by:eitconsulting
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 94

Expert Comment

by:John Hurst
ID: 41782449
An SPF record is to show people that you send email to others. It is a list of servers that are allowed to send mail and can be looked up by the receiver. It is designed to help reduce spoofing. SPF records are not for incoming mail.
0
 

Author Comment

by:eitconsulting
ID: 41782464
The incoming e-mail messages that are being blocked by SonicWall's Anti-Spam filtering do not have valid SPF records (http://www.kitterman.com/spf/validate.html) behind their e-mail domains.
1. OURS (domain1.com)
2. VENDOR (domain2.com)
VENDOR is sending e-mail to OURS.  However, those vendors that do not have a proper SPF record (a handful of domain.coms do not reach our inboxes) established (domain2.com) are not making it past the SonicWall's anti-spam filter and into our inboxes.
0
 
LVL 94

Expert Comment

by:John Hurst
ID: 41782466
If I understand you correctly, you (your devices) are checking the sender to find out if they are valid and they do not reply (no SPF record). You have to decide whether to whitelist or not.
0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 

Author Comment

by:eitconsulting
ID: 41782470
It appears that our SonicWall Anti-spam filter is blocking incoming e-mail from domains that do not have valid SPF records hence, my question re: the Significance of SPF records in this day and age.
Ever since we renewed our Anti-spam filter through SonicWall, it seems to be enforcing a requirement for SPF validation and perhaps with good reason.
0
 
LVL 94

Assisted Solution

by:John Hurst
John Hurst earned 150 total points
ID: 41782472
SPF records are a reasonable thing to have (my first post here) but are only one tool in the spam arsenal. They cannot be relied upon as be-all and end-all. No tool can.

So you need to figure out how to bypass or you may lose a lot of valid mail.

You cannot tell anyone to have an SPF record or tell them they must take it out.
0
 
LVL 25

Accepted Solution

by:
-MAS earned 350 total points
ID: 41782473
Hi eitconsulting,
Just adding to the above. Here is a  logical diagram from Microsoft.
Mail flow.
0
 

Author Comment

by:eitconsulting
ID: 41782482
MAS, this is helpful.  Thank you.  It seems SPF records are being enforced by the SonicWall Anti-Spam filters and perhaps for very good reasons.  However, unless everyone else complies with SPF records, SonicWall's filter is going to continue blocking the non SPF record established e-mail domains.
0

Featured Post

Resolve Critical IT Incidents Fast

If your data, services or processes become compromised, your organization can suffer damage in just minutes and how fast you communicate during a major IT incident is everything. Learn how to immediately identify incidents & best practices to resolve them quickly and effectively.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Facebook question on friends 3 75
Handling abuse of email address 7 51
Exchange 2010 SP1 to SP3 + RU16 8 120
Exchange spam control - administration only 4 30
As tax season makes its return, so does the increase in cyber crime and tax refund phishing that comes with it
As cyber crime continues to grow in both numbers and sophistication, a troubling trend of optimization has emerged over the last year.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question