On 2020-04-28 14:17, Matus UHLAR - fantomas wrote:
however, SPF will not fail here. So, sender using DKIM and forwarder
using
SRS fill make both SPF and DMARC pass.
spf domain changes on next-hop, so its another domains spf that deside
if spf pass or not pass, might be why postfix maillist does not have spf
at all to reduce ignorants :)
dmarc can be tell to make both spf and dkim aligned to get dmarc pass,
but that is not the default dmarc
if srs was used it will never get spf pass, since origal sender ip is
outside of original sender ip allow, better let it die slowly