Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: SpamAssassin: users

spamassassin or sendmail problems with SPF?

 

 

SpamAssassin users RSS feed   Index | Next | Previous | View Threaded


achen at harbourfrontcentre

Nov 20, 2009, 8:09 AM

Post #1 of 4 (696 views)
Permalink
spamassassin or sendmail problems with SPF?

Can somebody help me with this email headers: http://pastebin.com/m46bcaf59
I highlighted two lines which say:
spamassassin: ... SPF_HELO_PASS,SPF_PASS
sendmail: ....... may be forged

who is correct or wrong?

Thanks,

Allen


scheidell at secnap

Nov 20, 2009, 8:26 AM

Post #2 of 4 (651 views)
Permalink
Re: spamassassin or sendmail problems with SPF? [In reply to]

Allen Chen wrote:
> Can somebody help me with this email headers:
> http://pastebin.com/m46bcaf59
> I highlighted two lines which say:
> spamassassin: ... SPF_HELO_PASS,SPF_PASS
> sendmail: ....... may be forged
both are.

spf passes, but sendmail is telling you the FWD and RDNS don't match the
helo string.

from 123greetings.biz (listserv12.123greetings.biz [66.70.117.101]


host 66.70.117.101
101.117.70.66.in-addr.arpa domain name pointer listserv12.123greetings.biz.
mx2.secnap.com.ionspam.net# host listserv12.123greetings.biz
listserv12.123greetings.biz has address 66.70.117.94
listserv12.123greetings.biz has address 66.70.117.92
listserv12.123greetings.biz has address 66.70.117.93
listserv12.123greetings.biz has address 66.70.117.91
listserv12.123greetings.biz has address 66.70.117.90


>
> who is correct or wrong?
>
> Thanks,
>
> Allen
>
>

_________________________________________________________________________
This email has been scanned and certified safe by SpammerTrap(r).
For Information please see http://www.secnap.com/products/spammertrap/
_________________________________________________________________________


achen at harbourfrontcentre

Nov 20, 2009, 9:10 AM

Post #3 of 4 (660 views)
Permalink
Re: spamassassin or sendmail problems with SPF? [In reply to]

Michael Scheidell wrote:
> Allen Chen wrote:
>> Can somebody help me with this email headers:
>> http://pastebin.com/m46bcaf59
>> I highlighted two lines which say:
>> spamassassin: ... SPF_HELO_PASS,SPF_PASS
>> sendmail: ....... may be forged
> both are.
>
> spf passes, but sendmail is telling you the FWD and RDNS don't match
> the helo string.
>
> from 123greetings.biz (listserv12.123greetings.biz [66.70.117.101]
>
>
> host 66.70.117.101
> 101.117.70.66.in-addr.arpa domain name pointer
> listserv12.123greetings.biz.
> mx2.secnap.com.ionspam.net# host listserv12.123greetings.biz
> listserv12.123greetings.biz has address 66.70.117.94
> listserv12.123greetings.biz has address 66.70.117.92
> listserv12.123greetings.biz has address 66.70.117.93
> listserv12.123greetings.biz has address 66.70.117.91
> listserv12.123greetings.biz has address 66.70.117.90
>
>>
>> who is correct or wrong?
>>
>> Thanks,
>>
>> Allen
>>
>>

I see. thank you for your reply.


dbfunk at engineering

Nov 20, 2009, 10:33 AM

Post #4 of 4 (644 views)
Permalink
Re: spamassassin or sendmail problems with SPF? [In reply to]

On Fri, 20 Nov 2009, Michael Scheidell wrote:

>
> spf passes, but sendmail is telling you the FWD and RDNS don't match the
> helo string.
>
> from 123greetings.biz (listserv12.123greetings.biz [66.70.117.101]
>
>
> host 66.70.117.101
> 101.117.70.66.in-addr.arpa domain name pointer listserv12.123greetings.biz.
> mx2.secnap.com.ionspam.net# host listserv12.123greetings.biz
> listserv12.123greetings.biz has address 66.70.117.94
> listserv12.123greetings.biz has address 66.70.117.92
> listserv12.123greetings.biz has address 66.70.117.93
> listserv12.123greetings.biz has address 66.70.117.91
> listserv12.123greetings.biz has address 66.70.117.90

Actually to be pedandic, the "(may be forged)" label doesn't
say anything about the helo string, it just means that the FWD and RDNS
don't match for the IP address of the sending machine. This means
that the ISP's DNS service for that host/ip-addr aren't correct
(or somebody's trying to pull a forgery but in this particular
case SPF disproves that suspicion).

This has ramifications for things such as "whitelist_from_rcvd"
but SPF can work with out it.

--
Dave Funk University of Iowa
<dbfunk (at) engineering.uiowa.edu> College of Engineering
319/335-5751 FAX: 319/384-0549 1256 Seamans Center
Sys_admin/Postmaster/cell_admin Iowa City, IA 52242-1527
#include <std_disclaimer.h>
Better is not better, 'standard' is better. B{

SpamAssassin users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.