Spam -> SPF realization?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ZYV
    Senior Member
    • Sep 2005
    • 315

    #1

    Spam -> SPF realization?

    Hello,

    Actually, I've got a tricky problem this morning. Some jerk sent out a spam mailing and forged the FROM and REPLY-TO addresses with the contact info of some of my domains hosted here at Dathorn. As the result, I had to download about ~600-700 bounces and auto-replies.

    I know that the Internet is like this: you can fill in any junk in those FROM and REPLY-TO headers and it will work. Anyway, I have heard about SPF ( http://www.openspf.org/ ) and it's Yahoo-analog. This is a special stuff we should put in the domain's TXT DNS records and SPF-enabled mail server like mine will check the FROM and REPLY-TO fields against those records and if the IPs doesn't match it will refuse the message, because the contact info was obviousely forged.

    Is there any chance we can benefit from this (still not so widespread) technology on Dathorn servers? I think that implementing a limited SPF support should only involve the editing of the cPanel's default zone files (adding needed TXT records) and a bind reload, but still will be very beneficient to all of us: this will protect our e-mails from being used by spammers (think of it "Dathorn is the only host around that protects you from mail forgery!").

    P.S. I am afaird of probable Andrew's reply: "We don't plan to offer anything like that at this time" Getting SPF implemented sounds so good
  • AndrewT
    Administrator
    • Mar 2004
    • 3655

    #2
    SPF is not fully supported by cPanel and Exim at this time. SPF is still very much out there as far as being even remotely close to a "standard".

    Comment

    • sdjl
      Senior Member
      • Mar 2004
      • 502

      #3
      I wrote this how-to a little while back:

      I thought i'd give something back to the community here at Dathorn and what better to give than a basic tutorial on how to setup an SPF record for any of your accounts that you're hosting :) In a nutshell, what does SPF do? (link (http://www.openspf.org/faq.html#howworks)) Suppose a spammer forges a hotmail.com address and


      Nobody replied to it, so i'm guessing no one has used it.
      It works for my VPS server running cPanel.

      David
      -----
      Do you fear the obsolescence of the metanarrative apparatus of legitimation?

      Comment

      • ZYV
        Senior Member
        • Sep 2005
        • 315

        #4
        I don't think we can implement this ourselves via Dathorn's WHM. This should work only on VPS/dedicated...

        Comment

        • sdjl
          Senior Member
          • Mar 2004
          • 502

          #5
          It can be implemented on WHM here at Dathorn.
          Just ask for the DNS tools to be enabled on your account.

          David
          -----
          Do you fear the obsolescence of the metanarrative apparatus of legitimation?

          Comment

          • ZYV
            Senior Member
            • Sep 2005
            • 315

            #6
            WOW! I didn't know I could! Hey, this is really a great hint, thanks a buch! In fact, I need some custom DNS records for some of my domains and thus I am using my own DNS (surely less stable than Dathorn's). If I can get the DNS tools enabled thatd' solve all those problems...

            Going to open a TT ASAP.

            Comment

            Working...