spf-discuss
[Top] [All Lists]

Re: txt SPF record with cname

2004-09-14 03:32:49
On Mon, Sep 13, 2004 at 10:40:39PM -0400, Stuart D. Gathman wrote:
On Mon, 13 Sep 2004, guy wrote:
watkins-home.com.           A       1.2.3.4
                            txt     "v=spf1 a -all"
www.watkins-home.com.       CNAME   watkins-home.com.
                            txt     "v=spf1 -all"

The txt record for "www.watkins-home.com." gives an error.

I get an error similar to this in the messages file:
named[16521]: dns_master_load: master/watkins-home.com.db:4:
www.watkins-home.com: CNAME and other data

Is this a problem?  Can "www.watkins-home.com." be forged?

Yes.  You cannot mix CNAME with other records for a name.  This is
a DNS restriction.

Wrong! The answer is 'no, www.watkins-home.com can not be forged', since the 
spf record for watkins-home.com will be used when checking spf on 
www.watkins-home.com. You are right of course that CNAME does not mix with 
other records.

Should I change the CNAME to A?

Yes.

Again, wrong! Unless you want a different TXT record on www.watkins-home.com 
compared to the one on watkins-home.com.

Koen

P.s.: to the original poster of this problem, please do not reply to an 
existing thread to start a new thread, since the new thread will effectively be 
part of the original thread, messing up the thread display.

-- 
K.F.J. Martens, Sonologic, http://www.sonologic.nl/
Networking, embedded systems, unix expertise, artificial intelligence.
Public PGP key: http://www.metro.cx/pubkey-gmc.asc
Wondering about the funny attachment your mail program
can't read? Visit http://www.openpgp.org/