I thought i had a
handle on this SPF stuff, but i think i've got something wrong in my
understanding.
I've set up my SPF
record for our domain with the following record:
choicenet1.com
v=spf1
ip4:207.170.239.11 ip4:207.170.239.4 a mx -all
From my
understanding of this, the ip4's are extra ip addy's that should be "allowed" to
send email AS this domain. The mx entry states that the ip addy of the mx
record(s) found for this domain are also "allowed" to send email AS this
domain.
Am I right so
far?
Now, my dialup
customers are on a different subnet and log into our imail server using smtp
auth. When they send emails out, shouldn't the ip addy of the email then
take on the ip addy of the email server in the eyes of the receiving mail
server? the reason i ask this is because of the following in my
spf.log:
216.64.178.28 [EMAIL PROTECTED] [dona]: FAIL: v=spf1
ip4:207.170.239.11 ip4:207.170.239.4 a mx -all
There are lots of
failures in the log and the ip address on the far left is an ip addy in the ip
pool of our max tnt for our dial up customers, not the ip addy of the email
server. I see this for just about every one of my users, so for now, i've
turned off SPF.
Can someone explain
why/where i am going wrong? Is this a case of standard version vs. pro
version and declude is just logging all "outbound" attempts and throwing me
off? that makes me wonder though, why am i even seeing these since they
are "leaving" my mail server to go to others. it should be in their log
files.....right?
thanks for any
help provided!
(running Junkmail
Standard version 1.79)
David Dresler
