Am 11.12.2015 um 08:56 schrieb Matus UHLAR - fantomas:
I don't understand why a message from tripadvisor.com would have
SPF_FAIL, and as part of trying to understand how SPF works, I'd like
to figure out what's happening.

Would someone be able to take a look at this message and figure out
why mail from tripadvisor.com fails SPF?

http://pastebin.com/36hzGcTs

the envelope sender seems to be
bounce-15_html-74319930-51788793-10834732...@bounce.e.tripadvisor.com

bounce.e.tripadvisor.com seems to have no SPF record, so I also don't
understand why SPF tests should hit at all, maybe SPF HELO tests...

how dou you come to that conclusion and what means "seems" in that context - there is a TXT record or there is none - it's has one

;; ANSWER SECTION:
bounce.e.tripadvisor.com. 3600 IN TXT "v=spf1 include:cust-spf.exacttarget.com -all"

there is a ton of recievd headres and pretty sure spamassassin is *not* running on the MTA and internal_netwroks / trusted_networks is not configured properly at all and in that case DNSBL/DNSWL are also not wokring properly

that is the last external hop
Received: from mta3.e.tripadvisor.com ([66.231.81.9])
by h03p02.smtp.routit.net with ESMTP; 11 Dec 2015 02:18:24 +0100
_____________________________________________________

who is that?
Received: from h03p02.smtp.routit.net (h03p02.smtp.routit.net [89.146.30.18]) by pop3.routit.net (Postfix) with ESMTP id D0A1B42463
for <wytze.vandenb...@example.nl>; Fri, 11 Dec 2015 02:18:21 +0100 (CET)

who is that?
Received: from pop3.routit.net ([213.144.235.7]) by h02p01.smtp.routit.net with ESMTP; 11 Dec 2015 02:18:26 +0100

who is that?
Received: from h02p01.smtp.routit.net (h02p01.smtp.routit.net [89.146.30.9]) by bwimail02.example.com (Postfix) with ESMTP id 0F8CA345F25 for <wytze.vandenb...@example.com>; Thu, 10 Dec 2015 20:18:38 -0500 (EST)

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to