【问题标题】:SPF for site+mail server using single VPS使用单个 VPS 的站点+邮件服务器的 SPF
【发布时间】:2015-03-16 11:23:14
【问题描述】:

花了太多时间弄清楚如何在我的情况下配置 spf 记录:

domain: example.org x.x.x.x (using cloudflare y.y.y.y)
mx: mail.example.org x.x.x.x (cf proxy disabled)
vps: vps.company.com x.x.x.x

hostname: vps.company.com
smtp hello: vps.company.com
smtp from: <user>@vps.company.com

我的最后一个 spf 条目:“v=spf1 ip4:x.x.x.x a mx -all”,但它失败了...

这应该如何以适当的方式处理?我的情况应该是什么 spf 条目?

编辑: 这是 sendmail 从站点 example.org 发送的邮件标头:

Authentication-Results: mxs.mail.ru; spf=none () smtp.mailfrom=user@vps.company.com smtp.helo=vps.company.com
Received-SPF: none
Received: from [x.x.x.x] (port=35646 helo=vps.company.com)
    by mx188.mail.ru with esmtp (envelope-from <user@vps.company.com>)
    for user@mail.ru; Sun, 18 Jan 2015 11:01:33 +0300
Received: by vps.company.com (Postfix, from userid 100)
    id <value>; Sun, 18 Jan 2015 15:01:30 +0300
To: user@mail.ru
From: <admin@example.org>
Reply-To: <admin@example.org>
Sender: <admin@example.org>

【问题讨论】:

    标签: email vps spf


    【解决方案1】:

    你的记录应该是:"v=spf1 mx:mail.example.org -all"

    您不需要 ip4 或仅允许 mail.example.org 代表 vps.company.com 发送邮件。此外,请查看http://www.spfwizard.com/,Port 25 提供了一项出色的服务,可帮助解决 spf 和 dkim 问题http://www.port25.com/support/authentication-center/email-verification/,它会回复您的测试消息,并详细说明它如何解释策略以及拒绝该消息的原因。

    【讨论】:

    • 你能解释一下,为什么“v=spf1 ip4:x.x.x.x -all”会失败吗?我仍然不明白为什么 mx 不会故障转移 ip4。
    • 指定 mx:mailserver.example.com 通常是不正确的,除非您确实希望 SPF 验证查找所有接受“mailserver.example.com”域的邮件的主机。 (通常不会有任何这样的主机,因为“mailserver.example.com”本身就是主机,而不是域。)这不会显示为语法错误,但是,它根本不会匹配任何内容。 (c) openspf.org
    • 对不起@kill2kill 我从你的问题中假设你正试图授权 mailserver.example.com 为 vps.company.com 提供 - 它真的应该如此简单,没有理由 ip4 不会工作。仅供参考,所有这些机制都适用于“声称的负责地址”,通常是信封发件人,即“邮件发件人”命令中实际使用的地址
    • 嘿,看看我的答案 - 已经尝试过这个解决方案,而且效果很好。抱歉被误解的问题;)
    【解决方案2】:

    嗯,似乎我的问题出在哪里:不知道为什么,但我想,该 spf 记录检查了“来自”部分中指定的域,例如 qwerty@domain.com,可怜的我 =)

    解决我的问题:

    1. 添加一条记录 - vps.example.org -> x.x.x.x
    2. 更改 PTR 记录 - x.x.x.x -> vps.example.org
    3. 更改 SPF/TXT 记录 - “v=spf1 ip4:x.x.x.x -all”
    4. 将 MX 记录更改为目标 vps.example.org

    显然您需要更改(在我的情况下,因为我使用 php mail() 函数发送邮件) sendmail_path = /usr/sbin/sendmail -t -i -f user@example.org,之后,postfix 的设置应该也进行调整:myhostname = vps.example.org, mydomain = example.org(mydestination - 基于您的配置)。

    最终 spf 记录:“v=spf1 ip4:x.x.x.x -all”

    还有 - Use "mx" with domain names, not mailserver names

    【讨论】:

      猜你喜欢
      • 2012-05-01
      • 1970-01-01
      • 1970-01-01
      • 2015-03-12
      • 2012-02-09
      • 1970-01-01
      • 2015-12-21
      • 1970-01-01
      • 2011-06-09
      相关资源
      最近更新 更多