Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: SPF: Help

SPF for SubDoimains

 

 

SPF help RSS feed   Index | Next | Previous | View Threaded


daniel.thorpe at Communigator

Aug 15, 2007, 10:21 AM

Post #1 of 11 (2494 views)
Permalink
SPF for SubDoimains

Hi,



I have various domains that each send from a pool of IPs. One of these
being...



Gtml1.com

207.45.127.229

207.45.127.230

207.45.127.231

Etc...



I have setup the following SPF record...



v=spf1 ip4:207.45.127.224/27 ip4:207.45.127.216/29 ip4:207.45.127.208/29
~all



And when checking an outgoing email from sender [at] gtml1 all SPF checks
passed. I checked this via the website ->
http://www.deliverability.com/resources/emailAuthentication.php. If you
want to see the results go to this site and enter the following email
address for the VIEW SAMPLE...



Iov1h4X [at] www



However I am trying to send a test from a sub domain of
oneinteractive.gtml1.com. This test was sent to the sample address...



whjPh [at] www



The problem is all the SPF / Sender ID checks failed. The messages
being...



SPF-Method Result: none(oneinteractive.gtml1.com:
oneinteractive.gtml1.com does not designate permitted sender hosts)
SenderID-MFROM-Method Result: none(oneinteractive.gtml1.com:
oneinteractive.gtml1.com does not designate permitted sender hosts)
SenderID-PRA-Method Result: none(oneinteractive.gtml1.com:
oneinteractive.gtml1.com does not designate permitted sender hosts)



So I then altered my SPF record to include the PTR entry to authenticate
anything ending in gtml1.com. Here is the record which is actually the
current one in my DNS...



v=spf1 ptr ip4:207.45.127.224/27 ip4:207.45.127.216/29
ip4:207.45.127.208/29 ~all



However when I check this in the deliverability.com site it still
complains about the same thing.



Have I set this up incorrectly? What would I need to do to allow a sub
domain to be authenticated from the main domain SPF record?



Thanks for any replies! :-)



:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
: Daniel Thorpe
:
: Support Analyst / Network Administrator
: Communigator >';--;-'
:
:
: Tel: 01252 899599
: Email: daniel.thorpe [at] communigator
<mailto:rick.ingham [at] communigator>
: Web: www.communigator.co.uk <http://www.communigator.co.uk/>
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::





-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32275992-10a38a
Powered by Listbox: http://www.listbox.com


wendy.honeycutt at sonicfog

Aug 15, 2007, 11:04 AM

Post #2 of 11 (2421 views)
Permalink
RE: SPF for SubDoimains [In reply to]

-----Original Message-----
From: Daniel Thorpe [mailto:daniel.thorpe [at] Communigator]
Sent: Wednesday, August 15, 2007 1:21 PM
To: spf-help [at] v2
Subject: [spf-help] SPF for SubDoimains

> The problem is all the SPF / Sender ID checks failed. The messages
> being...
>
>
>
> SPF-Method Result: none(oneinteractive.gtml1.com:
> oneinteractive.gtml1.com does not designate permitted sender hosts)
> SenderID-MFROM-Method Result: none(oneinteractive.gtml1.com:
> oneinteractive.gtml1.com does not designate permitted sender hosts)
> SenderID-PRA-Method Result: none(oneinteractive.gtml1.com:
> oneinteractive.gtml1.com does not designate permitted sender hosts)
>

The message is telling you that it could not find an SPF record for the domain,
oneinteractive.gtml1.com. Each subdomain needs its own SPF record.

Sincerely,
Wendy Honeycutt
SonicFog Inc.


-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32285463-67d743
Powered by Listbox: http://www.listbox.com


daniel.thorpe at Communigator

Aug 15, 2007, 11:05 AM

Post #3 of 11 (2423 views)
Permalink
RE: SPF for SubDoimains [In reply to]

Hi,

Thanks for your reply.

Is there a way to get around this as I will soon have 50+ sub domains -
one for each customer - and the list will grow?

So can I create an SPF record that will work for any additional sub
domain without having to add a SPF record each time?

Ta,
Dan.


-----Original Message-----
From: SonicFog [mailto:wendy.honeycutt [at] sonicfog]
Sent: 15 August 2007 19:05
To: spf-help [at] v2
Subject: RE: [spf-help] SPF for SubDoimains

-----Original Message-----
From: Daniel Thorpe [mailto:daniel.thorpe [at] Communigator]
Sent: Wednesday, August 15, 2007 1:21 PM
To: spf-help [at] v2
Subject: [spf-help] SPF for SubDoimains

> The problem is all the SPF / Sender ID checks failed. The messages
> being...
>
>
>
> SPF-Method Result: none(oneinteractive.gtml1.com:
> oneinteractive.gtml1.com does not designate permitted sender hosts)
> SenderID-MFROM-Method Result: none(oneinteractive.gtml1.com:
> oneinteractive.gtml1.com does not designate permitted sender hosts)
> SenderID-PRA-Method Result: none(oneinteractive.gtml1.com:
> oneinteractive.gtml1.com does not designate permitted sender hosts)
>

The message is telling you that it could not find an SPF record for the
domain,
oneinteractive.gtml1.com. Each subdomain needs its own SPF record.

Sincerely,
Wendy Honeycutt
SonicFog Inc.


-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to
http://v2.listbox.com/member/?&
9
Powered by Listbox: http://www.listbox.com

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32299260-aeff1f
Powered by Listbox: http://www.listbox.com


steve at teamITS

Aug 15, 2007, 11:23 AM

Post #4 of 11 (2425 views)
Permalink
RE: SPF for SubDoimains [In reply to]

Daniel Thorpe wrote on 8/15/2007 1:05:13 PM:

> So can I create an SPF record that will work for any additional sub
> domain without having to add a SPF record each time?

No, but if they all use the same set of mail servers you can use
"include," for example:

v=spf1 include:gtml1.com -all

Then the only record you would have to maintain is the one for
gtml1.com.

-----
SPF FAQ: http://www.openspf.org/FAQ
Common mistakes: http://www.openspf.org/FAQ/Common_mistakes

- Steve Yates
- ITS, Inc.
- Good pings come in small packets

~ Taglines by Taglinator - www.srtware.com ~

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32324344-a54bd5
Powered by Listbox: http://www.listbox.com


michael at breton

Aug 15, 2007, 11:30 AM

Post #5 of 11 (2410 views)
Permalink
Re: SPF for SubDoimains [In reply to]

>----- Original Message -----
>From: "Daniel Thorpe" <daniel.thorpe [at] Communigator>
>To: <spf-help [at] v2>
>Sent: Wednesday, August 15, 2007 2:05 PM
>Subject: RE: [spf-help] SPF for SubDoimains
>
>Is there a way to get around this as I will soon have 50+ sub domains -
>one for each customer - and the list will grow?
>
>So can I create an SPF record that will work for any additional sub
>domain without having to add a SPF record each time?
>
>>The message is telling you that it could not find an SPF record for the
>>domain,
>>oneinteractive.gtml1.com. Each subdomain needs its own SPF record.

The other poster is correct, you will need to have a separate SPF record for
each subdomain that sends email.

You can, however, do it a bit easier this way:

If all of the subdomains will need the very same SPF record as the parent
domain, you could make all the subdomain SPF records the same, like this:

"v=spf1 include:gtml1.com -all"

....and have your parent domain, gtml1.com stay as it is right now, maybe
without the "ptr":

"v=spf1 ptr ip4:207.45.127.224/27 ip4:207.45.127.216/29
ip4:207.45.127.208/29 ~all"

In this way, if your email server configuration changes, you only need to
change one record (the parent) to make changes to all of them.

Michael Breton

p.s. If you run your own DNS servers, some DNS hosting softwares allow you
to create wildcard records that would allow you to specify a single SPF
record that would returned for EVERY TXT query for all subdomains of your
parent. Your mileage may vary.

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32338927-94a287
Powered by Listbox: http://www.listbox.com


daniel.thorpe at Communigator

Aug 16, 2007, 2:51 AM

Post #6 of 11 (2411 views)
Permalink
RE: SPF for SubDoimains [In reply to]

Cool thanks for your reply Michael and you also Steve. I will bite the
bullet and set this up for each sub domain - which considering I have to
create the sub domains anyway its not much of an overhead.

Ok second scenario now. A customer is hosted on gtml1.com or
customer.gtml1.com. And they are told sending from that address is
fully setup. However they want to send from their address. Lets use
another one of my domains as an example -> sgml2.com. (currently this
also has the same SPF record as gtml1.com but I can change this for
testing)

Anyway, the customer is on gtml1.com and wants to send from sgml2.com.
So I inform the customer it is possible if they add an spf record into
their domain to state we are a valid sender of their emails.

Is this the include:gtml1.com setting again? Or.....?

Thanks!
Dan.


-----Original Message-----
From: Michael Breton [mailto:michael [at] breton]
Sent: 15 August 2007 19:31
To: spf-help [at] v2
Subject: Re: [spf-help] SPF for SubDoimains

>----- Original Message -----
>From: "Daniel Thorpe" <daniel.thorpe [at] Communigator>
>To: <spf-help [at] v2>
>Sent: Wednesday, August 15, 2007 2:05 PM
>Subject: RE: [spf-help] SPF for SubDoimains
>
>Is there a way to get around this as I will soon have 50+ sub domains -
>one for each customer - and the list will grow?
>
>So can I create an SPF record that will work for any additional sub
>domain without having to add a SPF record each time?
>
>>The message is telling you that it could not find an SPF record for
the
>>domain,
>>oneinteractive.gtml1.com. Each subdomain needs its own SPF record.

The other poster is correct, you will need to have a separate SPF record
for
each subdomain that sends email.

You can, however, do it a bit easier this way:

If all of the subdomains will need the very same SPF record as the
parent
domain, you could make all the subdomain SPF records the same, like
this:

"v=spf1 include:gtml1.com -all"

....and have your parent domain, gtml1.com stay as it is right now,
maybe
without the "ptr":

"v=spf1 ptr ip4:207.45.127.224/27 ip4:207.45.127.216/29
ip4:207.45.127.208/29 ~all"

In this way, if your email server configuration changes, you only need
to
change one record (the parent) to make changes to all of them.

Michael Breton

p.s. If you run your own DNS servers, some DNS hosting softwares allow
you
to create wildcard records that would allow you to specify a single SPF
record that would returned for EVERY TXT query for all subdomains of
your
parent. Your mileage may vary.

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to
http://v2.listbox.com/member/?&
4
Powered by Listbox: http://www.listbox.com

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32553097-a415c4
Powered by Listbox: http://www.listbox.com


steve at teamITS

Aug 16, 2007, 7:42 AM

Post #7 of 11 (2408 views)
Permalink
RE: SPF for SubDoimains [In reply to]

Daniel Thorpe wrote on 8/16/2007 4:51:10 AM:

> Anyway, the customer is on gtml1.com and wants to send from sgml2.com.
> So I inform the customer it is possible if they add an spf record into
> their domain to state we are a valid sender of their emails.
>
> Is this the include:gtml1.com setting again? Or.....?

So sgml2.com is their own domain? They could use the same
include to send mail from that domain using your servers. If they send
through other servers they would add those to their SPF record only.

-----
SPF FAQ: http://www.openspf.org/FAQ
Common mistakes: http://www.openspf.org/FAQ/Common_mistakes

- Steve Yates
- ITS, Inc.
- It has recently been discovered that research causes cancer in rats.

~ Taglines by Taglinator - www.srtware.com ~

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32605560-36de5b
Powered by Listbox: http://www.listbox.com


daniel.thorpe at Communigator

Aug 16, 2007, 8:35 AM

Post #8 of 11 (2420 views)
Permalink
RE: SPF for SubDoimains [In reply to]

Hi Steve,

Sgml2.com is not an actual customer, its just another one of mine I am
using for an example. But basically if the customer does or does not
have a SPF record already. If they simply add the include:gtml1.com
flag it will be ok?

Thanks,
Dan.


-----Original Message-----
From: Steve Yates [mailto:steve [at] teamITS]
Sent: 16 August 2007 15:43
To: spf-help [at] v2
Subject: RE: [spf-help] SPF for SubDoimains

Daniel Thorpe wrote on 8/16/2007 4:51:10 AM:

> Anyway, the customer is on gtml1.com and wants to send from sgml2.com.
> So I inform the customer it is possible if they add an spf record into
> their domain to state we are a valid sender of their emails.
>
> Is this the include:gtml1.com setting again? Or.....?

So sgml2.com is their own domain? They could use the same
include to send mail from that domain using your servers. If they send
through other servers they would add those to their SPF record only.

-----
SPF FAQ: http://www.openspf.org/FAQ
Common mistakes: http://www.openspf.org/FAQ/Common_mistakes

- Steve Yates
- ITS, Inc.
- It has recently been discovered that research causes cancer in rats.

~ Taglines by Taglinator - www.srtware.com ~

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to
http://v2.listbox.com/member/?&
b
Powered by Listbox: http://www.listbox.com

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32643728-5f74a8
Powered by Listbox: http://www.listbox.com


steve at teamITS

Aug 16, 2007, 9:02 AM

Post #9 of 11 (2412 views)
Permalink
RE: SPF for SubDoimains [In reply to]

Daniel Thorpe wrote on 8/16/2007 10:35:57 AM:

> But basically if the customer does or does not
> have a SPF record already. If they simply add the include:gtml1.com
> flag it will be ok?

If their record only references "include:gtml1.com" they would
only be able to send through that server.

-----
SPF FAQ: http://www.openspf.org/FAQ
Common mistakes: http://www.openspf.org/FAQ/Common_mistakes

- Steve Yates
- ITS, Inc.
- Confucius say: Early worm have death wish

~ Taglines by Taglinator - www.srtware.com ~

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32651001-2dd8c1
Powered by Listbox: http://www.listbox.com


daniel.thorpe at Communigator

Aug 16, 2007, 9:28 AM

Post #10 of 11 (2433 views)
Permalink
RE: SPF for SubDoimains [In reply to]

Thanks man,

What if for example their SPF record said...

v=spf1 ip4:162.145.25.58 ~all

???

Which is a totally made up IP by the way. Im just trying to get my head
around the situation :)

Thanks again,
Dan.


-----Original Message-----
From: Steve Yates [mailto:steve [at] teamITS]
Sent: 16 August 2007 17:03
To: spf-help [at] v2
Subject: RE: [spf-help] SPF for SubDoimains

Daniel Thorpe wrote on 8/16/2007 10:35:57 AM:

> But basically if the customer does or does not
> have a SPF record already. If they simply add the include:gtml1.com
> flag it will be ok?

If their record only references "include:gtml1.com" they would
only be able to send through that server.

-----
SPF FAQ: http://www.openspf.org/FAQ
Common mistakes: http://www.openspf.org/FAQ/Common_mistakes

- Steve Yates
- ITS, Inc.
- Confucius say: Early worm have death wish

~ Taglines by Taglinator - www.srtware.com ~

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to
http://v2.listbox.com/member/?&
4
Powered by Listbox: http://www.listbox.com

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32663406-7982aa
Powered by Listbox: http://www.listbox.com


steve at teamITS

Aug 16, 2007, 9:47 AM

Post #11 of 11 (2415 views)
Permalink
RE: SPF for SubDoimains [In reply to]

Daniel Thorpe wrote on 8/16/2007 11:28:57 AM:

> What if for example their SPF record said...
>
> v=spf1 ip4:162.145.25.58 ~all

You can have it be anything you want. :) It should cover any
server(s) they use to send mail, whether that's yours, theirs, their
ISP's, etc.


-----
SPF FAQ: http://www.openspf.org/FAQ
Common mistakes: http://www.openspf.org/FAQ/Common_mistakes

- Steve Yates
- ITS, Inc.
- "Oh, a lesson in not changing history from "Mr. I'm-my-own-Grandpa!"
- Professor Farnsworth

~ Taglines by Taglinator - www.srtware.com ~

-------------------------------------------
-----------------------------------------------------------------------
Archives at http://archives.listbox.com/spf-help/current/ or
http://www.gossamer-threads.com/lists/spf/help/ (easier to search)
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=1311530&id_secret=32669301-1e7f45
Powered by Listbox: http://www.listbox.com

SPF help RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.