3 ms·
This part is interesting: Authentication-Results: mx.google.com; spf=pass (google.com: domain of reply@telus.com designates 69.64.35.11 as permitted
by bertjk 8y ago
This part is interesting:
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of reply@telus.com designates 69.64.35.11 as permitted sender) smtp.mailfrom=Reply@telus.com;
dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com
I had thought that as of early 2017 that had changed the DMARC policy to p=REJECT which would basically reject any attempts at spoofing gmail.com in the From: field. It seems as if someone suddenly (maybe accidentally) reverted that change?
- ryan-c 8y agoIt appears to be validating the envelope sender (reply@telus.com) rather than the from address, per the spec. The thing is, telus.com doesn't have a DMARC record, and thier SPF record doesn't include 69.64.35.11. This header might be fake. Gmail does currently have a DMARC record that says p=none sp=quarantine. The 'sp' value only applies to subdomains, so the "none" (no action) policy should be used. Edit: I just verified that gmail's dmarc has had p=none for a long time.
- deleted 8y ago[deleted]