v=spf1 ip4:198.22.123.0/24 mx ~all
indicates a “soft-fail” for email from
RewardZoneCerts.BestBuy.com (206.132.3.45)
Granted, Tom, but the Astaro failed the SPF based on the wrong address!
I just checked for both RewardZoneCerts.BestBuy.com and BestBuy.com, and I got the same one I did yesterday.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
So, you are saying this is not an Astaro error, but a limitation/feature of SPF. And, further, the implication would be that the burden for addressing this issue falls on the service that forwards the email.
However, according to openspf.org:
"Checking SPF On Forwarded Mail
"Mail forwarding is set up by the receiver and so for forwarded mail, the border mail server (at which SPF should be checked) is the forwarder's mail server. If you check SPF on your mail server it is coming from your forwarder and not from a mail server authorized by the sending domain. Technically this is similar to checking SPF against mail relayed from your secondary MX like discussed in the previous item. Authorized forwarders should be whitelisted against SPF checks to avoid this problem."
In the example I supplied earlier in this thread, there is no way to tell the Astaro not to reject mail forwarded from a specific IP, domain like alfson.org or email like Bob@Alfson.org.
I would have to list each individual, original sender like RewardZoneCerts.BestBuy.com - that seems impractical.
So, while this might not, technically, be an Astaro error, it does render the Astaro implemtation of SPF unusable for many organizations.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.