4 ms·
I would suggest using the "-" ("reject") Life is too short to waste it on spam. If you can't set up proper SPF/DMARC/DKIM then I don't email me at all.
by nasredin 8y ago
I would suggest using the "-" ("reject")
Life is too short to waste it on spam.
If you can't set up proper SPF/DMARC/DKIM then I don't email me at all.
- flurdy 8y agoNo, that is the point, and mentioned in the article. "-"(Reject/Hard Fail) for SPF is broken and should be avoided. SPF only considers the sender and not the transport and recipient. It does not consider recipients' forwarding alias rules, backup MXs, multi relay domain setups, etc. I.e. normal email infrastructure and usage patterns. I have subset of users that uses Gmail as their client, SPF with "-" from a random valid sender would not allow me to redirect those emails to Google's servers. Also many aliases on my domains forwards to other addresses not on hosted by my servers (subsidiaries, personal accounts, mailing lists, etc), Spf with "-" will force the end SMTP server to block those emails as doubtful your SPF listing has listed my SMTP servers. And if a recipient domain has a more complex SMTP setup with mutiple SMTP servers acting as incomming, outgoing, bastions, backups, webmail, sharded storage, etc then any redirecting between them would again break with a strict SPF. As said before use: DKIM, DMARC but make sure SPF is set to not Fail as it is broken. Use Greylisting, Spamassassin etc to score spam to avoid false positives that are not obvious rubbish enough to reject on envelope details alone. Fastmail has a very good default recommendations: https://www.fastmail.com/help/technical/senderauthentication.html https://www.fastmail.com/help/technical/senderauthentication... My own Postfix doc's DKIM section: http://flurdy.com/docs/postfix/#ext_dkim http://flurdy.com/docs/postfix/#ext_dkim