我正在我们的域上设置 SPF 记录,但我不确定应该使用什么 SPF 记录。
我们将 Exchange 2013 设置为使用我们的电子邮件过滤公司作为智能主机发送,并且他们的主机是电子邮件标题中出现的最新主机,但标题中也提到的是我们自己的服务器 - 我们的 SPF 记录应该是什么样的?
我从公司向我的个人 iCloud 帐户发送了一封电子邮件,其标题如下:
Received:from mr28p00im-smtpin034.me.com ([17.110.71.33]) by ms02592.mac.com (Oracle Communications Messaging Server 7.0.5.36.0 64bit (built Sep 8 2015)) with ESMTP id <[email protected]> for [email protected]; Tue, 02 Aug 2016 16:36:41 +0000 (GMT)
Original-recipient:rfc822;[email protected]
Received:from smtp001.apm-internet.net (smtp001-out.apm-internet.net [85.119.248.222]) by mr28p00im-smtpin034.me.com (Oracle Communications Messaging Server 7.0.5.38.0 64bit (built Feb 26 2016)) with ESMTPS id <[email protected]> for [email protected] (ORCPT [email protected]); Tue, 02 Aug 2016 16:36:40 +0000 (GMT)Authentication-results:mr28p00im-smtpin038.me.com; spf=none (mr28p00im-smtpin038.me.com: [email protected] does not designate permitted sender hosts) [email protected];
Received-SPF:none (mr28p00im-smtpin038.me.com: [email protected] does not designate permitted sender hosts) receiver=mr28p00im-smtpin038.me.com; client-ip=85.119.248.222; helo=smtp001.apm-internet.net; [email protected];
Received:(qmail 98779 invoked from network); 2 Aug 2016 16:36:36 -0000
Received:from unknown (HELO mail.company.com) (185.75.105.226) by smtp001.apm-internet.net with SMTP; 2 Aug 2016 16:36:36 -0000
Received:from Exchange.company.local (192.168.100.34) by Exchange.company.local (192.168.100.34) with Microsoft SMTP Server (TLS) id 15.0.847.32; Tue, 2 Aug 2016 17:36:33 +0100
Received:from Exchange.company.local ([fe80::2525:838f:2ff6:72]) by Exchange.company.local ([fe80::2525:838f:2ff6:72%12]) with mapi id 15.00.0847.030; Tue, 2 Aug 2016 17:36:33 +0100
答案1
如果您的电子邮件过滤公司是电子邮件从您的 Exchange 服务器发送到外部收件人的唯一途径,即您的服务器从不直接发送,那么 SPF 记录应该只提及过滤公司。
最简单情况下的 SPF 记录被目的地用作验证“哪些服务器被允许直接联系我并发送声称来自给定域的电子邮件”的一种手段,尽管它可能之前已经遍历了几个跳数但这并不重要。
答案2
就像是:
company.com. IN TXT "v=spf1 a:smtp001.apm-internet.net"
答案3
Smarthostsmtp001.apm-internet.net
可能会轮换 IP,您应该要求提供商向您提供他们在 Smarthost 服务器上使用的 IP 范围。没有它,您就无法创建“完美”的 spf。
应该做的是
company.com. in TXT "v=spf1 mx a:smtp001.apm-internet.net/24 ~all"