Hello I have an SPF record created in DNS for my domain. In my main.cf config file for Postfix I have the following SPF settings:
spf_received_header = yes spf_mark_only = no smtpd_recipient_restrictions = peject_spf_invalid_sender, permit_spf_valid_sender, smtpd_sender_restrictions = reject_spf_invalid_sender, permit_spf_valid_sender Is the above config correct to reject received emails that is NOT being delivered from the specified IP addresses in SPF? I basically want to reject/fail emails that are not coming from the correct IP address specified by the domains SPF record. Also, recently I received one of these: This is a spf/dkim authentication-failure report for an email message received from IP 14.16.26.208 on Sun, 11 Jan 2015 00:32:42 +0800. Below is some detail information about this message: 1. SPF-authenticated Identifiers: none; 2. DKIM-authenticated Identifiers: none; 3. DMARC Mechanism Check Result: Identifier non-aligned, DMARC mechanism check failures; For more information please check Aggregate Reports or mail to [hidden email]. Feedback-Type: auth-failure User-Agent: NtesDmarcReporter/1.0 Version: 1 Original-Mail-From: [hidden email] Arrival-Date: Sun, 11 Jan 2015 00:32:42 +0800 Source-IP: 14.16.26.208 Reported-Domain: mydomain.com Original-Envelope-Id: PMCowEApi0cjVLFUK2fmEQ--.1291S2 Authentication-Results: 163.com; dkim=none; spf=fail [hidden email] Delivery-Result: delivered Received: from qoeeisq (unknown [150.108.4.5]) by mydomain.com with SMTP id 1UqgGfirbN2SASB9.1 for [hidden email]; Sun, 11 Jan 2015 00:32:40 +0800 Message-ID: <2D836C2DA068C6B28993B9B4FEBCFF2D@qoeeisq> From: "---" [hidden email] To: [hidden email] Subject: =?big5?B?ru+sS6tC?= Date: Sun, 11 Jan 2015 00:32:35 +0800 MIME-Version: 1.0 Content-Type: text/plain; charset="big5" Content-Transfer-Encoding: base64 X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.5512 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512 Does this mean SPF has failed as it said that the delivery results says delivered? I didn't receive this email so maybe its fake? What is the above message? Thank you. -- View this message in context: http://postfix.1071664.n5.nabble.com/SPF-configurations-tp73872.html Sent from the Postfix Users mailing list archive at Nabble.com.