spf-discuss
[Top] [All Lists]

Re: [spf-discuss] spf checks at MTA useless because of neutral records

2006-07-31 06:09:40
On Mon, 31 Jul 2006 18:22:47 +0530 Ramprasad 
<ram(_at_)netcore(_dot_)co(_dot_)in> wrote:
We process a large number of emails ( upto 3 million a day ) on a load
balanced array of servers for spam checking

The maximum number of spams we receive are from ( in sorted order ) from
singular domains in the envelope sender 
1) earthlink.net
2) hotmail.com
3) yahoo.com
4) netzero.com 

of these hotmail and netzero have SPF records. 
I have enabled spf policyd in postfix. But that is giving me no benefit
because all these big domains publish neutral records 

So what is the point in doing spf checks at the MTA.  I would better do
them at spamassassin and use them for scoring 

Or can I configure policyd to reject SPF_NEUTRAL for hotmail.com.
How can that be done, ( what about non compliance to SPF ) 

It's not compliant with RFC 4408, but sometimes the receiver has to do what 
the receiver has to do.

PyMilter with pySPF, I believe, implements a capability to do what you are 
asking.  As far as I know, it hasn't been integrated with Postfix before, 
but it is used in production with Sendmail.  The mainter is active on this 
list, so if you need help you should be able to get it.

Scott K

-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com

<Prev in Thread] Current Thread [Next in Thread>