Re: email spoof

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Rob Bordwell (atomicdawg_at_smtd.com)
Date: 11/12/04


Date: Thu, 11 Nov 2004 17:44:52 -0800

At the moment, you cannot stop spoofing on all mail servers throughout
the Internet. However, there is a push right now to get administrators
to support SPF (Sender Policy Framework). In a nutshell, here is how
SPF works:

The owner of a domain adds a specially formatted TXT record to his DNS
server. This text record lists what servers are allowed to send mail
for the given domain. Now, when a mail server receives email, the one
thing it knows for certain is the IP address of the server sending the
mail. So, when a server receives an email claiming to be from
jowblow@yourdomain.com, the mail server checks the SPF TXT record for
yourdomain.com. Is the IP address of the sending server listed as a
server that can send mail for yourdomain.com? If not, then it can be
considered a spoof.

So you ask, "What's the problem? How come everyone doesn't use SPF?"
The problem is that it is new and hasn't been embraced by everyone yet.
Not everyone has created SPF records for their domains. Most email
server software doesn't support SPF out of the box. Even if it did, you
wouldn't want to reject every email from a domain without a SPF record
because not everyone knows about SPF and most people haven't taken the
time to set up a SPF record for their domain.

But as time goes on, SPF will reach critical mass. Users will find
their email being rejected more times than not if their domain does not
have a SPF record. When that time comes, everybody will start getting
with the program.

For more information, check out the following:

spf.pobox.com

http://www.microsoft.com/mscorp/twc/privacy/spam/senderid/default.mspx

Microsoft has something called Sender ID. I think it used to be called
Email Caller ID. It adds something to SPF but I'm not sure how it
works. I suppose I should read my own link!

In article <1B17EFCF-6A64-45A1-8075-BED64E883A0F@microsoft.com>,
joe@discussions.microsoft.com says...
> Is there a way to prevent email spoofing. My user complaint about people are
> calling them and asking why she send certain message. She confirmed with me
> that she never sent those message. I think this is a case of email spoofing
> right? I confirmed that her machine does not have virus. I spoke with
> Trendmicro and Symantec and they their is no way to avoid email spoofing? Are
> they correct? Is there any thing I can do?



Relevant Pages

  • Re: Reverse DNS and mail server
    ... my receiving server to do this. ... True it checks for the registration of the servers host DNS name (which ... It may also be checking SPF records but it would foolish to ... Joe User respond to sender - email goes out and is reaching mail server ...
    (microsoft.public.win2000.dns)
  • Re: Spoofed Emails
    ... I setup the SPF record in my local DNS server. ...
    (microsoft.public.exchange.admin)
  • Re: How to disable SPF in Win2003 DNS?
    ... the mail server of his recipients provider. ... I called the ISP of the recipient, and they said they do have SPF ... This will NOT stop others from checking the SPF record and possible ...
    (microsoft.public.windows.server.dns)
  • [SLE] SPF plugin for postfix
    ... IMHO the proper answer is, among other, SPF. ... So, I created an SPF record for my site in my DNS server, (after changing ... Wietse Venema, the creator of postfix, recommends to implement this ... The postfix plugin package is named 'postfix-policyd-SPF'. ...
    (SuSE)
  • Re: Undeliverable Mail
    ... Well adding an spf record is out of the question. ... Yes, our large, cluster-based DNS system is compliant with RFC 1035. ... while EHLO is an Enhanced command. ... > on the properties of the Default SMTP Virtual server. ...
    (microsoft.public.exchange.admin)