On Mon, 15 Nov 2010 11:50:50 -0500 Michael Scheidell <michael.scheid...@secnap.com> wrote:
> then don't use it: Our record follows the way I said SPF should work. It specifies only 4 hosts as authorized to send for us and has a hard -all at the end. That's because we took the time and trouble to set up our email infrastructure so roaming users could VPN in and send through our designated sending hosts. If you are not going to take the time and trouble to do that, then don't publish an SPF record. Unfortunately, that means about 90% of SPF records wouldn't be published. > add this to local.cf: We don't use SpamAssassin to evaluate SPF records. Regards, David. PS: How much backscatter do you think our SPF record has saved us from? Probably none...