Re: [ietf-smtp] SPF DNS query limits

2016-05-25 03:33:45
On 24/05/2016 17:23, John Levine wrote:

Just as a matter of interest - wouldn't it be worth them using macros in
their includes? eg 'include:%{i4r}'. This could cut down
drastically on the level of nesting.
Yuck.  That feels really fragile.

Is it just that SPF macros aren't well implemented (despite them being a key part of SPF), or something else?

It seems to me that this is exactly the reason that macros are specifically allowed in include: mechanisms in RFC 7208.

A substantial proportion of the SPF checks our server does which include the Google/ SPF records go over the 10 query limit, so if/when people start failing on permerror results, it'll cause big issues.

