3 ms·
Does the script handle macros in SPF? I've had a couple of other-company-IT-admins tell me that my MX is jacked because I use hosted SPF via proofpoint, and wh
by hug 2y ago
Does the script handle macros in SPF?
I've had a couple of other-company-IT-admins tell me that my MX is jacked because I use hosted SPF via proofpoint, and when they look up my SPF it looks like this:
"v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all"
A surprising number of mail admins don't understand SPF macros.
- velcrovan 2y agoIf I’m reaching for the script, it's because I’m already in a scenario where Proofpoint has quarantined legitimate email for failing SPF checks (we use Proofpoint too). So the script itself doesn’t do any analysis of the existing SPF record. It just shows them the existing record and tells them how to fix it based on the sender's IP for the email in question.
- TheNewsIsHere 2y agoIn defense of those who haven’t read the RFCs personally — I can count on one hand the number of times I’ve seen SPF macros in the wild, which holds true if I included yours. Interestingly all Proofpoint customers too. I’ve seen it more common to isolate services to subdomains and specify subdomain SPF records rather than use macros. This is my preferred approach. I’m not hating on the macros. They’re just seemingly very rarely used. I know they’re on the table but I haven’t found a compelling use case in my own deployments.