Am 11.12.2015 um 08:56 schrieb Matus UHLAR - fantomas:
I don't understand why a message from tripadvisor.com would have SPF_FAIL, and as part of trying to understand how SPF works, I'd like to figure out what's happening. Would someone be able to take a look at this message and figure out why mail from tripadvisor.com fails SPF? http://pastebin.com/36hzGcTsthe envelope sender seems to be bounce-15_html-74319930-51788793-10834732...@bounce.e.tripadvisor.com bounce.e.tripadvisor.com seems to have no SPF record, so I also don't understand why SPF tests should hit at all, maybe SPF HELO tests...
how dou you come to that conclusion and what means "seems" in that context - there is a TXT record or there is none - it's has one
;; ANSWER SECTION:bounce.e.tripadvisor.com. 3600 IN TXT "v=spf1 include:cust-spf.exacttarget.com -all"
there is a ton of recievd headres and pretty sure spamassassin is *not* running on the MTA and internal_netwroks / trusted_networks is not configured properly at all and in that case DNSBL/DNSWL are also not wokring properly
that is the last external hop Received: from mta3.e.tripadvisor.com ([66.231.81.9]) by h03p02.smtp.routit.net with ESMTP; 11 Dec 2015 02:18:24 +0100 _____________________________________________________ who is that?Received: from h03p02.smtp.routit.net (h03p02.smtp.routit.net [89.146.30.18]) by pop3.routit.net (Postfix) with ESMTP id D0A1B42463
for <wytze.vandenb...@example.nl>; Fri, 11 Dec 2015 02:18:21 +0100 (CET) who is that?Received: from pop3.routit.net ([213.144.235.7]) by h02p01.smtp.routit.net with ESMTP; 11 Dec 2015 02:18:26 +0100
who is that?Received: from h02p01.smtp.routit.net (h02p01.smtp.routit.net [89.146.30.9]) by bwimail02.example.com (Postfix) with ESMTP id 0F8CA345F25 for <wytze.vandenb...@example.com>; Thu, 10 Dec 2015 20:18:38 -0500 (EST)
signature.asc
Description: OpenPGP digital signature