Link to home
Start Free TrialLog in
Avatar of cindyfiller
cindyfillerFlag for United States of America

asked on

DNS spf record

Our website is done through an external vendor.  Part of this website allows us to send out email blasts.  The domain used is ours, but we do not have the domain set up for email.  Some of those emails are not going through certain providers so the vendor told us to add their information to our spf record.  Since we aren't using this for email we don't have an spf record...  I'm trying to figure out how to add their IP's that send the email into an spf record...  do I need to include the mx in it??  Wouldn't the mx point to mx records (that we don't have because we don't use this domain for email)?

Are one of these correct or do I need to do something else??

v=spf1 mx ip4:216.235.196.0/22 ip4:216.235.200.0/21 ip4:205.139.104.0/22 ip4:206.79.6.0/24 -all
v=spf1 ip4:216.235.196.0/22 ip4:216.235.200.0/21 ip4:205.139.104.0/22 ip4:206.79.6.0/24 -all
SOLUTION
Avatar of Jian An Lim
Jian An Lim
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Who hosts your public DNS records?
Avatar of cindyfiller

ASKER

Chris - network solutions does the public domain on this one

BTW, I called their support number to ask them this and they told me they couldn't help.  We did try both examples above and the email was bounced back with both of these spf records.  

Jian, I don't have an actual MX record for this domain.... I just wasn't sure if the mx was needed in the spf record.  Our webmaster and I were disagreeing on this.
Here's a basic guide to creating a spf record at network solutions
https://www.mail-tester.com/spf/network-solutions
Not having an mx record for the domain will most definitely increase you spam index score though. Not having a real return path or any way to send a reply doesn't look good to spam blockers.
We did try both examples above and the email was bounced back with both of these spf records.

What did the NDR say for one of those bounced messages? It should contain some information regarding the reason for the bounce.

Regarding your original question: if your domain has no MX records, there's no need for the "mx" mechanism to be in your SPF record; it won't do anything but cause an additional lookup.
Bounce Message: 550 5.1.0 <dsn.10208.68715435.144831@communitymail.undalumni.org> invalid from domain - sender rejected
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I'm not sure if my post deserved an assist.  Did it help any?
I did give you an assist....  I don't know how to check the points, but it does show the assist....
Yes, you gave me the assist, I'm just not sure if my post deserved it.

Did you solve your issue?
It turned out to be an issue with the vendor's setup of our email...  it wasn't associated with the right email server.  All of the pieces that people provided me made me push the vendor again and during that process they found their error.  I so appreciated the comments everyone made!
Great!  Thanks for the feedback.   Glad your problem is solved.