Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Nov 2006
    Location
    GB
    Posts
    44

    Unhappy Forwarding broken by SPF - need SRS to mend it

    Sites prematurely imposing SPF compliance, e.g. waitrose.com, can cause a big nuisance by rejecting emails sent to them using forwarding.

    I have rDNS already, and have created an SPF record on my DNS, and so these have satisfied the basic SPF problem on our server. Emails sent from accounts on our server are getting through OK even if forwarded.

    Email sent from elsewhere which use forwarding via our server is still a problem, and isn't satisfied by SPF compliance.

    There appears to be consensus amongst lots of sites that the solution for servers which need to use forwarding, is to have Sender Rewriting Scheme (SRS) support in the MTA.

    Exim supports this as from v4.50 and we are using v4.63. However this "support" seems to be a bit of an exaggeration.

    I have found a lot of instructions on SRS and how to activate it in the Exim config, including:

    http://www.openspf.org/SRS
    http://www.libsrs2.org/overview.html

    I can't find an actual code and config patch, except in a file from Brazil, where I do not understand the comments, and I am not competent to write my own without spending a lot of time. It appears to be a minor addition, which must be in use at lots of Exim sites.

    Any pointers please?
    Last edited by wemail; 02-23-2008 at 03:34 PM. Reason: tidy up wording

  2. #2
    Member
    Join Date
    Aug 2002
    Posts
    1,118

    Default

    One question to ask is why are you using e-mail forwarders?

    If you are just going to be checking your AOL address, then you should advertise your AOL address as your e-mail address. Does it look less professional? Probably, but its just a price you have to pay if you are only willing to check your AOL address.

    If you want to use your domain name based e-mails, then consider setting up real POP accounts and using an e-mail program, like Thunderbird, to check those mail accounts for messages. This way you don't run into an issue with the SPF records.

  3. #3
    Member
    Join Date
    Nov 2006
    Location
    GB
    Posts
    44

    Default

    Quote Originally Posted by sparek-3 View Post
    One question to ask is why are you using e-mail forwarders?
    This is organization policy. Forwarding is essential for several reasons and has been in use for years.

    Quote Originally Posted by sparek-3 View Post
    If you are just going to be checking your AOL address, then you should advertise your AOL address as your e-mail address. Does it look less professional? Probably, but its just a price you have to pay if you are only willing to check your AOL address.
    Sorry, this isn't relevant to our problem.

    Quote Originally Posted by sparek-3 View Post
    If you want to use your domain name based e-mails, then consider setting up real POP accounts and using an e-mail program, like Thunderbird, to check those mail accounts for messages. This way you don't run into an issue with the SPF records.
    We cannot impose this on the users. I suggested it occasionally but users wish to stay with their service provider. If everybody would use the local addresses on our server with either the built-in webmail or a good client like Pegasus Mail, it would be easier. But they won't.

    So, we need to use SRS.
    --
    Wemail ServerAdmin
    (GB)

  4. #4
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Feb 2003
    Location
    Gothenburg, Sweden
    Posts
    323

    Default

    Has anyone looked into more deeply? Just got a case where this is happening

    twitter: oderland_david

  5. #5
    Member
    Join Date
    Jun 2006
    Posts
    212

    Default

    wemail:

    I would be more than glad to take a look at the brazilian file. I know a thing or two about portuguese.

    We are working on getting SRS support on the Exim RPM.

    internetfab:

    Could you please contact me directly: alex@cpanel.net or open a support ticket (ATTN Alex). Would like to look into the forwarding/spf issue you are experiencing.

    Thank you.
    Alex Villegas

  6. #6
    Member
    Join Date
    Mar 2004
    Posts
    710

    Default

    If you rewrite the headers - besides violating the RFC's - any email that you send that is spam - you are now the spammer as your server sent the spam message because you removed the "real" sender.
    Lloyd F Tennison

  7. #7
    Member
    Join Date
    Nov 2006
    Location
    GB
    Posts
    44

    Thumbs up

    SPF/SRS is documented on its own site.

    There is good news on availability in "SPF Implementation" thread.
    --
    Wemail ServerAdmin
    (GB)

Similar Threads & Tags
Similar threads

  1. Adding SPF Records (spf_installer broken!)
    By methamp in forum E-mail Discussions
    Replies: 2
    Last Post: 09-03-2008, 11:24 PM
  2. SPF and forwarding mail to a Gmail-account
    By kservik in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 07-18-2008, 07:08 AM
  3. SPF validation & SRS support - what is going on please?
    By wemail in forum E-mail Discussions
    Replies: 0
    Last Post: 06-13-2008, 03:32 AM
  4. SRS SPF Exim - build with experimental SRS?
    By internetfab in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 03-31-2008, 10:28 AM
  5. E-mail forwarding now broken 11.2.11-C12008
    By Bruce in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-15-2007, 10:13 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube