Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


dimsim

848 posts

Ultimate Geek

Trusted
Lifetime subscriber

#201914 9-Sep-2016 11:58
Send private message

Having some issues with email sent via Amazon SES failing SPF and being rejected by my Exchange Server.

 

The From address is @<senderdomain> and the return path is @..amazonses.com

 

The Amazon documentation says nothing needs to be done to SPF with this configuration as the return path will get checked for SPF and will pass as the sending server will be within the AMazon SPF records.

 

I think where it is failing is that the FROM address (@<senderdomain>) also has an SPF record and Exchange is checking that first, finds an SPF which doesnt include Amazon and subsequently fails the message.

 

Has anyone encountered this or know the acutal process exchange uses to validate SPF e.g FROM address then Return-Path address?

 

My guess is that if you have gone to the trouble of creating an SPF record for your domain then ALL hosts that send mail should be listed in that record.


Create new topic
timmmay
20578 posts

Uber Geek

Trusted
Lifetime subscriber

  #1626460 9-Sep-2016 12:01
Send private message

Are you sure the from SPF is correctly marking the Amazon IP/domain as an authorised sender? Paste in some headers. If you want to share the details, here or by PM, I can poke about and have a look tonight.

 

I set up SPF and DKIM for all my domains, and I've just started with dmark.




dimsim

848 posts

Ultimate Geek

Trusted
Lifetime subscriber

  #1626463 9-Sep-2016 12:08
Send private message

timmmay:

 

Are you sure the from SPF is correctly marking the Amazon IP/domain as an authorised sender? Paste in some headers. If you want to share the details, here or by PM, I can poke about and have a look tonight.

 

I set up SPF and DKIM for all my domains, and I've just started with dmark.

 

 

 

 

The FROM SPF doesnt mention Amazon at all, which is my point. See below.

 

 

The sending servers are in the 54.240.27.xxx range. which are Amazon's

 

 


timmmay
20578 posts

Uber Geek

Trusted
Lifetime subscriber

  #1626466 9-Sep-2016 12:12
Send private message

Well there's your problem. Follow the instructions on this page to add appropriate TXT SPF records and it should resolve once the DNS cache refreshes (also known as DNS propagation).




Inphinity
2780 posts

Uber Geek


  #1626482 9-Sep-2016 12:24
Send private message

I believe difference is that Sender ID validates the sender address, whereas the SPF standard validates the MAIL FROM domain header in the envelope. As such, Sender ID performs more checks than the SPF standard framework, but uses SPF records to do it, resulting in issues requiring both the MAIL FROM domain and the senders domain to include:amazonses.com in their SPF records. 


ArcticSilver
729 posts

Ultimate Geek


  #1626501 9-Sep-2016 12:33
Send private message

dimsim:

 

timmmay:

 

Are you sure the from SPF is correctly marking the Amazon IP/domain as an authorised sender? Paste in some headers. If you want to share the details, here or by PM, I can poke about and have a look tonight.

 

I set up SPF and DKIM for all my domains, and I've just started with dmark.

 

 

 

 

The FROM SPF doesnt mention Amazon at all, which is my point. See below.

 

 

The sending servers are in the 54.240.27.xxx range. which are Amazon's

 

 

 

 

The from domain will NEED to have Amazon's ip's in a SPF record. SPF is all about validating where the mail came from, rather than the reply to address (by my understanding).


dimsim

848 posts

Ultimate Geek

Trusted
Lifetime subscriber

  #1626503 9-Sep-2016 12:37
Send private message

timmmay:

 

Well there's your problem. Follow the instructions on this page to add appropriate TXT SPF records and it should resolve once the DNS cache refreshes (also known as DNS propagation).

 

 

 

 

That's what I thought, but despite multiple attempts to inform them of this problem, this rather large online store doesn't want to listen, hence their marketing emails constantly get rejected.

 

I would have thought that Amazon SNS notifications would be notifying them of these constant rejections? Is that what happens when the Return-Path is @...amazonses.com


timmmay
20578 posts

Uber Geek

Trusted
Lifetime subscriber

  #1626511 9-Sep-2016 12:43
Send private message

I think emails that don't pass SPF are dropped, therefore no notification is possible. The domain after the @ needs to set up the SPF record - so if it's from bob@bob.com then the DNS for bob.com has to publish a TXT SPF record that specifies AWS SES as an allowed sender.

 

I think marketing emails being dropped is a good thing for the internet...


 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Note that to use Quic Broadband you must be comfortable with configuring your own router.
wazzageek
1093 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1627152 10-Sep-2016 19:31
Send private message

timmmay:

 

I think emails that don't pass SPF are dropped, therefore no notification is possible. The domain after the @ needs to set up the SPF record - so if it's from bob@bob.com then the DNS for bob.com has to publish a TXT SPF record that specifies AWS SES as an allowed sender.

 

I think marketing emails being dropped is a good thing for the internet...

 

 

Emails that dont pass SPF will be handled as per the receiving email servers setup.

 

Some servers may bounce the email, some may tag for analysis by a spam filter, some may just drop the email on the floor.


timmmay
20578 posts

Uber Geek

Trusted
Lifetime subscriber

  #1627184 10-Sep-2016 21:24
Send private message

True, but the key point there is there's no reliable notification that can be given to the sender. Actually, nothing about email is reliable.


  #1627246 11-Sep-2016 07:56
Send private message

This is where having setup DMARC is helpful.

 

 

 

You'll receive a report listing all the servers that sent email on behalf of your domain, and what their SPF and DKIM status was.

 

 

 

I've used it when a customer has a website that sends mail directly for example. I saw the IP in the dmarc report and realised what was happening (ie it hadn't been realised that the website did that) so added the IP to the SPF record.

 

 

 

I use the services at https://www.dmarcian.com/login/?next=/mcontrol/


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.