4 ms·
I actually use both. I use a POP3 enabled account on my hosting provider, but because Gmail only polls for new mail from external accounts on its own schedule (
by Samon 8y ago
I actually use both. I use a POP3 enabled account on my hosting provider, but because Gmail only polls for new mail from external accounts on its own schedule (you can't specify the frequency, and when you're on the phone and someone says "I've emailed that through, is X correct?", waiting 5 or 15 minutes for it to appear in your inbox in Gmail isn't ideal, so I also have mail forwarding turned on. This means that for mail where the DKIM policy allows forwarding, you get the email almost instantly, but if the DKIM fails, you will still get it just a few minutes later. I've been doing it this way for years without an issue. I set a very strong password on my POP account (since I only have to enter it once into the Gmail interface to setup the account) and accept the security risk of no 2FA.
- deanmoriarty 8y agoThanks. What you are implying in your reply is that Google ignores its own SPF validation results for spam purposes/mail acceptance then? When you enable forwarding, even the emails that don't fail DKIM still show up in gmail with the SPF fail (under "Show Original"/"SPF"), and I'm sure they do in your setup as well since it's a logic consequence of doing the forwarding. I'm essentially trying to figure out if any of these conditions can happen with forwarding enabled: 1) SPF validation will fail, the Google mail server will refuse the forwarded message, so the Gandi mail server will bounce it back to the sender without me even knowing, rather than depositing it in the associated mailbox (especially with the domains set with SPF "-all", such as several of the financial institutions I use). So, no POP3 fallback even if it's enabled along with the forwarding. 2) SPF validation will fail, the Google mail server will still accept the forwarded message, but will be more inclined to mark it at spam. Thanks
- Samon 8y agoWhere Gmail refuses to accept the forwarded email (because the DMARC policy doesn't allow forwarding) I receive the 'Mail Forward Failure' notification but the email has been accepted into the original mailbox, so will be pulled into my Gmail mailbox the next time the POP3 check runs. I have a rule on the Gmail side to remove those failure notifications. I haven't noticed any impact to Gmail's actual spam filtering, either garbage slipping through or false positives. I've just checked a few random emails and Gmail shows "SPF: PASS with IP xxx.xxx.xxx.xxx". For most emails, the DKIM and DMARC checks also show PASS, but this is obviously dependent on the sender.
- deanmoriarty 8y agoLast question: do you use Gandi as a forwarder? If yes, I truly can't understand how it is possible that the forwarded emails (non POP3) can pass the spf on the google side, since your mail server acts as a forwarder and most definitely is not allowed to do so, according to the SPF records. Thanks for engaging!
- Samon 8y agoSorry, no, I'm not using Gandi, I actually have a legacy account in Zoho that I use (from back when POP3 was available on free accounts), but the logic is the same. The emails get accepted into the Zoho mailbox, then forwarded to Gmail. If Gmail rejects the forwarded email (due to DMARC policy) then I get the failure notification, not the original sender (as the failure is that Zoho was unable to forward the email to Gmail, not that Zoho didn't accept the original email from the sender), and that email will be retrieved by Gmail when it next does it's POP3 check.
- deanmoriarty 8y agoThanks. The part that I'm not understanding, and at this point I will put it in my todo list to sign up for a free forwarding account in Zoho to try it out, is how it is possible for the Zoho mail server to forward emails to Gmail without the messages being flagged as SPF fail, since your Zoho server is not authorized to dispatch emails from the sender domain when they have SPF records. In other words, this is a real example from an email that just got flagged on my Gmail from apple.com, as part of being forwarded: Received: from relay5-d.mail.gandi.net (relay5-d.mail.gandi.net. [217.70.183.197] by mx.google.com ... Received-SPF: softfail (google.com: domain of transitioning noreply@apple.com does not designate 217.70.183.197 as permitted sender) client-ip=217.70.183.197; Received: from nwk-txn-msbadger0502.apple.com (nwk-txn-msbadger0502.apple.com [17.151.1.69]) by spool.mail.gandi.net ... Date: Mon, 21 Jan 2019 03:18:35 +0000 (GMT) From: Apple <noreply@apple.com> Reply-To: noreply@apple.com You can see, from bottom to top: 1) The email is being sent from noreply@apple.com 2) The email is received by the Gandi mail server from Apple mail server 3) The email is received by the Google mail server from Gandi mail server Step 3 is where the forwarding happens but, since the Gandi mail server is not supposed to originate emails from apple.com (according to the SPF records on the apple.com domain), then it gets marked as SPF fail, and the Google mail server tells why (ip address of the Gandi mail server is not allowed to generate mail from noreply@apple.com). I don't understand how that cannot happen with Zoho, and I'll study it asap.