S
SwaJime
Guest
We have people sending us e-mails that appear to be from our domain, but are not. I am trying to block these e-mails.
I have not been able to get PLESK to check the SPF records of inbound e-mail. Any help will be much appreciated.
We have set up our SPF record in our DNS.
I am running a test case, wherein I am sending e-mail from john@oldradio.com to john@oldradio.com, with the originating computer in an unauthorized ip range.
I expect the test e-mail to be blocked when PLESK attempts to verify the SPF record for the sending address.
My results though are unpleasing. The e-mail appears to go through with no checks being performed at all.
I've included at the end of this post the headers of the received test e-mail. Also, the qmail log for the transaction is included after the e-mail here.
You can see that our SPF record in DNS appears to be set up correctly by opening http://www.openspf.org/Why?s=mfrom&id=john%40oldradio.com&ip=207.13.78.13&r=verifier.port25.com in a web browser.
If you need more information, please let me know what is needed and I will provide it.
I have followed these steps:
Setting Up Support for Sender Policy Framework System
To set up support for Sender Policy Framework on your server:
1. Click the Server shortcut in the navigation pane.
2. Click the Mail icon in the Services group. The server-wide mail preferences screen will open on the Preferences tab.
3. Select the Switch on SPF spam protection check box and specify how to deal with e-mail:
* To accept all incoming messages regardless of SPF check results, select the Create only Received SPF-headers, never block option from the SPF checking mode drop-down box. This option is recommended.
* To accept all incoming messages regardless of SPF check results, even if SPF check failed due to DNS lookup problems, select the In case of DNS lookup problems, generate temporary errors option from the SPF checking mode drop-down box.
* To reject messages from senders who are not authorized to use the domain in question, select the option Reject mail if SPF resolves to fail from the SPF checking mode drop-down box.
These are the headers of the received test e-mail:
Received: (qmail 3807 invoked by uid 110); 10 Nov 2008 10:51:46 -0600
Delivered-To: 8-john@oldradio.com
Received: (qmail 3800 invoked from network); 10 Nov 2008 10:51:46 -0600
Received: from mailscanner.virtbiz.com (208.77.216.59) by dallas.oldradio.com with SMTP; 10 Nov 2008 10:51:46 -0600
Received: from smtp.tstar.net (smtp.tstar.net [207.13.78.13]) by mailscanner.virtbiz.com (8.13.1/8.11.6) with ESMTP id mAAGpiUH019396 for <john@oldradio.com>; Mon, 10 Nov 2008 10:51:45 -0600
Received: from [192.168.1.10] (johnhibbs.wireless.tstar.net [205.247.111.216]) (authenticated bits=0) by smtp.tstar.net (8.13.6/8.13.6) with ESMTP id mAAGpkix003020 for <john@oldradio.com>; Mon, 10 Nov 2008 10:51:47 -0600
Subject: testing oldradio from (unauthorized) tstar to dallas
From: John W. Simpson <john@oldradio.com>
To: john@oldradio.com
X-MX01-VIRTBIZ-COM-MailScanner: Not scanned: please contact your Internet E-Mail Service Provider for details, Not scanned: please contact your Internet E-Mail Service Provider for details
Content-Type: text/plain
Organization: SwaJime's Cove
Date: Mon, 10 Nov 2008 10:51:40 -0600
Message-Id: <1226335900.7799.342.camel@Ezekiel>
Mime-Version: 1.0
X-Mailer: Evolution 2.22.3.1
Content-Transfer-Encoding: 7bit
X-MX01-VIRTBIZ-COM-MailScanner-Information: Please contact the ISP for more information
X-MX01-VIRTBIZ-COM-MailScanner-From: john@oldradio.com
X-Evolution-Source: imap://john%40swajime.com@mail.swajime.com/
testing oldradio from (unauthorized) tstar to dallas
And also, here is the qmail log of the event:
(note: a .qmail file redirects the message to john@swajime.com, so the sudden change in the recipient's e-mail address from 8-john@oldradio.com to john@swajime.com is appropriate)
08315:10:51:41 john@dallas # Nov 10 10:51:46 dallas relaylock: /var/qmail/bin/relaylock: mail from 208.77.216.59:56979 (mailscanner.virtbiz.com)
Nov 10 10:51:46 dallas qmail-queue[3798]: mail: all addreses are uncheckable - need to skip scanning (by deny mode)
Nov 10 10:51:46 dallas qmail-queue[3798]: scan: the message(drweb.tmp.tahTHb) sent by john@oldradio.com to john@oldradio.com should be passed without checks, because contains uncheckable addresses
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: Handlers Filter before-queue for qmail started ...
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: from=john@oldradio.com
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: to=john@oldradio.com
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: hook_dir = '/var/qmail//handlers/before-queue'
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: recipient[3] = 'john@oldradio.com'
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: handlers dir = '/var/qmail//handlers/before-queue/recipient/john@oldradio.com'
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: starter: submitter[3800] exited normally
Nov 10 10:51:46 dallas qmail: 1226335906.329419 new msg 7719692
Nov 10 10:51:46 dallas qmail: 1226335906.329593 info msg 7719692: bytes 1345 from <john@oldradio.com> qp 3800 uid 2020
Nov 10 10:51:46 dallas qmail: 1226335906.503507 starting delivery 12: msg 7719692 to local 8-john@oldradio.com
Nov 10 10:51:46 dallas qmail: 1226335906.503732 status: local 1/10 remote 0/200
Nov 10 10:51:46 dallas qmail-local-handlers[3801]: Handlers Filter before-local for qmail started ...
Nov 10 10:51:46 dallas qmail-local-handlers[3801]: from=john@oldradio.com
Nov 10 10:51:46 dallas qmail-local-handlers[3801]: to=john@oldradio.com
Nov 10 10:51:46 dallas qmail-queue[3805]: mail: all addreses are uncheckable - need to skip scanning (by deny mode)
Nov 10 10:51:46 dallas qmail-queue[3805]: scan: the message(drweb.tmp.2B3enL) sent by john@oldradio.com to john@swajime.com should be passed without checks, because contains uncheckable addresses
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: Handlers Filter before-queue for qmail started ...
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: from=john@oldradio.com
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: to=john@swajime.com
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: hook_dir = '/var/qmail//handlers/before-queue'
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: recipient[3] = 'john@swajime.com'
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: handlers dir = '/var/qmail//handlers/before-queue/recipient/john@swajime.com'
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: starter: submitter[3807] exited normally
Nov 10 10:51:46 dallas qmail: 1226335906.815188 new msg 7719924
Nov 10 10:51:46 dallas qmail: 1226335906.815356 info msg 7719924: bytes 1449 from <john@oldradio.com> qp 3807 uid 110
Nov 10 10:51:46 dallas qmail: 1226335906.886960 starting delivery 13: msg 7719924 to local 15-john@swajime.com
Nov 10 10:51:46 dallas qmail: 1226335906.887172 status: local 2/10 remote 0/200
Nov 10 10:51:46 dallas qmail: 1226335906.887321 delivery 12: success: did_0+1+2/qp_3805/
Nov 10 10:51:46 dallas qmail: 1226335906.887683 status: local 1/10 remote 0/200
Nov 10 10:51:46 dallas qmail: 1226335906.887856 end msg 7719692
Nov 10 10:51:46 dallas qmail-local-handlers[3808]: Handlers Filter before-local for qmail started ...
Nov 10 10:51:46 dallas qmail-local-handlers[3808]: from=john@oldradio.com
Nov 10 10:51:46 dallas qmail-local-handlers[3808]: to=john@swajime.com
Nov 10 10:51:46 dallas qmail: 1226335906.954353 delivery 13: success: did_0+0+2/
Nov 10 10:51:46 dallas qmail: 1226335906.954492 status: local 0/10 remote 0/200
Nov 10 10:51:46 dallas qmail: 1226335906.954567 end msg 7719924
08315:10:51:41 john@dallas #
I have not been able to get PLESK to check the SPF records of inbound e-mail. Any help will be much appreciated.
We have set up our SPF record in our DNS.
I am running a test case, wherein I am sending e-mail from john@oldradio.com to john@oldradio.com, with the originating computer in an unauthorized ip range.
I expect the test e-mail to be blocked when PLESK attempts to verify the SPF record for the sending address.
My results though are unpleasing. The e-mail appears to go through with no checks being performed at all.
I've included at the end of this post the headers of the received test e-mail. Also, the qmail log for the transaction is included after the e-mail here.
You can see that our SPF record in DNS appears to be set up correctly by opening http://www.openspf.org/Why?s=mfrom&id=john%40oldradio.com&ip=207.13.78.13&r=verifier.port25.com in a web browser.
If you need more information, please let me know what is needed and I will provide it.
I have followed these steps:
Setting Up Support for Sender Policy Framework System
To set up support for Sender Policy Framework on your server:
1. Click the Server shortcut in the navigation pane.
2. Click the Mail icon in the Services group. The server-wide mail preferences screen will open on the Preferences tab.
3. Select the Switch on SPF spam protection check box and specify how to deal with e-mail:
* To accept all incoming messages regardless of SPF check results, select the Create only Received SPF-headers, never block option from the SPF checking mode drop-down box. This option is recommended.
* To accept all incoming messages regardless of SPF check results, even if SPF check failed due to DNS lookup problems, select the In case of DNS lookup problems, generate temporary errors option from the SPF checking mode drop-down box.
* To reject messages from senders who are not authorized to use the domain in question, select the option Reject mail if SPF resolves to fail from the SPF checking mode drop-down box.
These are the headers of the received test e-mail:
Received: (qmail 3807 invoked by uid 110); 10 Nov 2008 10:51:46 -0600
Delivered-To: 8-john@oldradio.com
Received: (qmail 3800 invoked from network); 10 Nov 2008 10:51:46 -0600
Received: from mailscanner.virtbiz.com (208.77.216.59) by dallas.oldradio.com with SMTP; 10 Nov 2008 10:51:46 -0600
Received: from smtp.tstar.net (smtp.tstar.net [207.13.78.13]) by mailscanner.virtbiz.com (8.13.1/8.11.6) with ESMTP id mAAGpiUH019396 for <john@oldradio.com>; Mon, 10 Nov 2008 10:51:45 -0600
Received: from [192.168.1.10] (johnhibbs.wireless.tstar.net [205.247.111.216]) (authenticated bits=0) by smtp.tstar.net (8.13.6/8.13.6) with ESMTP id mAAGpkix003020 for <john@oldradio.com>; Mon, 10 Nov 2008 10:51:47 -0600
Subject: testing oldradio from (unauthorized) tstar to dallas
From: John W. Simpson <john@oldradio.com>
To: john@oldradio.com
X-MX01-VIRTBIZ-COM-MailScanner: Not scanned: please contact your Internet E-Mail Service Provider for details, Not scanned: please contact your Internet E-Mail Service Provider for details
Content-Type: text/plain
Organization: SwaJime's Cove
Date: Mon, 10 Nov 2008 10:51:40 -0600
Message-Id: <1226335900.7799.342.camel@Ezekiel>
Mime-Version: 1.0
X-Mailer: Evolution 2.22.3.1
Content-Transfer-Encoding: 7bit
X-MX01-VIRTBIZ-COM-MailScanner-Information: Please contact the ISP for more information
X-MX01-VIRTBIZ-COM-MailScanner-From: john@oldradio.com
X-Evolution-Source: imap://john%40swajime.com@mail.swajime.com/
testing oldradio from (unauthorized) tstar to dallas
And also, here is the qmail log of the event:
(note: a .qmail file redirects the message to john@swajime.com, so the sudden change in the recipient's e-mail address from 8-john@oldradio.com to john@swajime.com is appropriate)
08315:10:51:41 john@dallas # Nov 10 10:51:46 dallas relaylock: /var/qmail/bin/relaylock: mail from 208.77.216.59:56979 (mailscanner.virtbiz.com)
Nov 10 10:51:46 dallas qmail-queue[3798]: mail: all addreses are uncheckable - need to skip scanning (by deny mode)
Nov 10 10:51:46 dallas qmail-queue[3798]: scan: the message(drweb.tmp.tahTHb) sent by john@oldradio.com to john@oldradio.com should be passed without checks, because contains uncheckable addresses
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: Handlers Filter before-queue for qmail started ...
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: from=john@oldradio.com
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: to=john@oldradio.com
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: hook_dir = '/var/qmail//handlers/before-queue'
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: recipient[3] = 'john@oldradio.com'
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: handlers dir = '/var/qmail//handlers/before-queue/recipient/john@oldradio.com'
Nov 10 10:51:46 dallas qmail-queue-handlers[3799]: starter: submitter[3800] exited normally
Nov 10 10:51:46 dallas qmail: 1226335906.329419 new msg 7719692
Nov 10 10:51:46 dallas qmail: 1226335906.329593 info msg 7719692: bytes 1345 from <john@oldradio.com> qp 3800 uid 2020
Nov 10 10:51:46 dallas qmail: 1226335906.503507 starting delivery 12: msg 7719692 to local 8-john@oldradio.com
Nov 10 10:51:46 dallas qmail: 1226335906.503732 status: local 1/10 remote 0/200
Nov 10 10:51:46 dallas qmail-local-handlers[3801]: Handlers Filter before-local for qmail started ...
Nov 10 10:51:46 dallas qmail-local-handlers[3801]: from=john@oldradio.com
Nov 10 10:51:46 dallas qmail-local-handlers[3801]: to=john@oldradio.com
Nov 10 10:51:46 dallas qmail-queue[3805]: mail: all addreses are uncheckable - need to skip scanning (by deny mode)
Nov 10 10:51:46 dallas qmail-queue[3805]: scan: the message(drweb.tmp.2B3enL) sent by john@oldradio.com to john@swajime.com should be passed without checks, because contains uncheckable addresses
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: Handlers Filter before-queue for qmail started ...
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: from=john@oldradio.com
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: to=john@swajime.com
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: hook_dir = '/var/qmail//handlers/before-queue'
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: recipient[3] = 'john@swajime.com'
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: handlers dir = '/var/qmail//handlers/before-queue/recipient/john@swajime.com'
Nov 10 10:51:46 dallas qmail-queue-handlers[3806]: starter: submitter[3807] exited normally
Nov 10 10:51:46 dallas qmail: 1226335906.815188 new msg 7719924
Nov 10 10:51:46 dallas qmail: 1226335906.815356 info msg 7719924: bytes 1449 from <john@oldradio.com> qp 3807 uid 110
Nov 10 10:51:46 dallas qmail: 1226335906.886960 starting delivery 13: msg 7719924 to local 15-john@swajime.com
Nov 10 10:51:46 dallas qmail: 1226335906.887172 status: local 2/10 remote 0/200
Nov 10 10:51:46 dallas qmail: 1226335906.887321 delivery 12: success: did_0+1+2/qp_3805/
Nov 10 10:51:46 dallas qmail: 1226335906.887683 status: local 1/10 remote 0/200
Nov 10 10:51:46 dallas qmail: 1226335906.887856 end msg 7719692
Nov 10 10:51:46 dallas qmail-local-handlers[3808]: Handlers Filter before-local for qmail started ...
Nov 10 10:51:46 dallas qmail-local-handlers[3808]: from=john@oldradio.com
Nov 10 10:51:46 dallas qmail-local-handlers[3808]: to=john@swajime.com
Nov 10 10:51:46 dallas qmail: 1226335906.954353 delivery 13: success: did_0+0+2/
Nov 10 10:51:46 dallas qmail: 1226335906.954492 status: local 0/10 remote 0/200
Nov 10 10:51:46 dallas qmail: 1226335906.954567 end msg 7719924
08315:10:51:41 john@dallas #