Re: publishing SPF record to DNS

Tech-Archive recommends: Fix windows errors by optimizing your registry



It was strange that I did not receive any email notification as replies were
posted to my initial query. Or is it that I forgot to check the NOTIFY ME
box. Anyway .....

I have gone thru the links in Bharat's & Rich's reply. But there are a few
doubts/queries ahead as follows. Please correct me if my understanding is
wrong

1] A single in-house hosted Ex2007 that is using an reserved IP with either
ISA or non Microsoft Firewall at the edge of the network. The SPF record
would eventually consider the IP of a valid mail server for our domain as the
IP of the external - public IP of our firewall - is that right?

2] Suppose our single in-house hosted Ex2007 server is configured from
sending & receiving mails for multiple email domains, then we will need to
create an SPF -txt record for all the email domains in each of public DNS for
the respective domain - is that right?

3] Some MS Ex2007 documentation reference talks about creating SPF records
only for the EDGE transport server & not the hub Transport. But in a scenario
where one does not use a edge transport & only relies on the Hub transport in
an internal network a SPF record can still be created for the email domain -
is that right?




"Bharat Suneja [MVP]" wrote:

- You don't need to publish SPF records in DNS to use SenderID on your
Exchange server. Your server looks up SPF records of other domains for
SenderID Filtering.
- Publishing SPF records in extneral DNS for your domains provides
protection from your domains being used in spoofed headers (if the
recipient's mail system has SenderID/SPF enabled)
- Sender ID Framework SPF Record Wizard
http://www.microsoft.com/mscorp/safety/content/technologies/senderid/wizard/


--
Bharat Suneja
MVP - Exchange
www.zenprise.com
NEW blog location:
exchangepedia.com/blog
----------------------------



"Vicky" <Vicky@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:879F2746-BD68-49AD-8257-FE6D7C42D9D4@xxxxxxxxxxxxxxxx
We have an Ex2007 deployed inhouse with ISA 2006 at the edge of our
network.
We do not have Ex2007 edge transport role but only rely on the hub
transport.
Ocassionally our domain/IP get listed in the blocked list on the public
network.

We have enabled Ex2007 SP1 Antispam-SenderID/Sender Reputation but we
belive
we need to have the SPF record published in our public DNS zone as a TXT
record. [We hope our understanding is right, Please correct us]

Now how do we do this i.e.
- publishing SPF record of our Inhouse hosted Ex 2007 in our public DNS
zone




.



Relevant Pages

  • Re: SPF record question
    ... My MX record is in public DNS. ... PTR in an SPF record because of "expensive DNS lookups." ... filtering enabled on my Exchange server and some other domain has an SPF ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • MAIL.mydomain.com #5.5.0 smtp;550-mail.mydomain.com [x.x.x.122] is currently not permitted to re
    ... just started receiving ndr's for bounced emails like the following: ... this Client's site or in their public DNS. ... The Exchange server is not ... that ourdomain.com does not have an SPF record. ...
    (microsoft.public.exchange2000.admin)
  • SPF - Record Found but no Outgoing Servers.... ???
    ... just to be sure that my outgoing server ip reputation will be safe I created ... SPF Record Found ... I am not understanding why it's doing it, my public dns includes 2 mx ...
    (microsoft.public.exchange.admin)
  • Re: Undeliverable Mail
    ... nonsense, unless their server is totally non-RFC compliant, in which case, ... AOL adding your IP to *their* whitelist shouldn't be a big deal. ... > add an SPF record applies to our domain hosted by interland. ... > I enabled logging of the exchange server. ...
    (microsoft.public.exchange.admin)
  • Re: Undeliverable Mail
    ... Well I'm still on a quest to send email to aol and yahoo. ... Unfortunately, at this time, we are unable to create an SPF record for the ... I contacted AOL and they wanted me to submit our IP to there whitelist. ... I enabled logging of the exchange server. ...
    (microsoft.public.exchange.admin)