Solved

E-mail DNS SPF records

Posted on 2016-09-02
7
62 Views
Last Modified: 2016-09-02
How important is a SPF record these days in reference to e-mail DNS?  We are running a SonicWall with the anti-spam filtering enabled which seems to work very well.  However, we have it set to block not just "definite spam" but also, "likely spam".  This being said, will blocking "likely spam" block e-mail that doesn't have an accurate SPF DNS record setup?
0
Comment
Question by:eitconsulting
  • 3
  • 3
7 Comments
 
LVL 93

Expert Comment

by:John Hurst
ID: 41782449
An SPF record is to show people that you send email to others. It is a list of servers that are allowed to send mail and can be looked up by the receiver. It is designed to help reduce spoofing. SPF records are not for incoming mail.
0
 

Author Comment

by:eitconsulting
ID: 41782464
The incoming e-mail messages that are being blocked by SonicWall's Anti-Spam filtering do not have valid SPF records (http://www.kitterman.com/spf/validate.html) behind their e-mail domains.
1. OURS (domain1.com)
2. VENDOR (domain2.com)
VENDOR is sending e-mail to OURS.  However, those vendors that do not have a proper SPF record (a handful of domain.coms do not reach our inboxes) established (domain2.com) are not making it past the SonicWall's anti-spam filter and into our inboxes.
0
 
LVL 93

Expert Comment

by:John Hurst
ID: 41782466
If I understand you correctly, you (your devices) are checking the sender to find out if they are valid and they do not reply (no SPF record). You have to decide whether to whitelist or not.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:eitconsulting
ID: 41782470
It appears that our SonicWall Anti-spam filter is blocking incoming e-mail from domains that do not have valid SPF records hence, my question re: the Significance of SPF records in this day and age.
Ever since we renewed our Anti-spam filter through SonicWall, it seems to be enforcing a requirement for SPF validation and perhaps with good reason.
0
 
LVL 93

Assisted Solution

by:John Hurst
John Hurst earned 150 total points
ID: 41782472
SPF records are a reasonable thing to have (my first post here) but are only one tool in the spam arsenal. They cannot be relied upon as be-all and end-all. No tool can.

So you need to figure out how to bypass or you may lose a lot of valid mail.

You cannot tell anyone to have an SPF record or tell them they must take it out.
0
 
LVL 25

Accepted Solution

by:
-MAS earned 350 total points
ID: 41782473
Hi eitconsulting,
Just adding to the above. Here is a  logical diagram from Microsoft.
Mail flow.
0
 

Author Comment

by:eitconsulting
ID: 41782482
MAS, this is helpful.  Thank you.  It seems SPF records are being enforced by the SonicWall Anti-Spam filters and perhaps for very good reasons.  However, unless everyone else complies with SPF records, SonicWall's filter is going to continue blocking the non SPF record established e-mail domains.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
Local Continuous Replication is a cost effective and quick way of backing up Exchange server data. The following article describes the steps required to configure Local Continuous Replication. Also, the article tells you how to restore from a backup…
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question