SV: Spoofing and SPF

Mark Sapiro mark at
Mon Sep 12 12:52:51 UTC 2016

On September 12, 2016 1:50:29 AM PDT, "Trond M. Markussen" <markussen at> wrote:
>Yes, FROM_CUSTOMERDOMAIN is based on from: but in these cases that rule
>triggered. However, the emails seem to have passed  the SPF check even
>though the senders were not listed in the SPF record for that domain.

That's because SPF is not based on the domain of From:. It is based on the domain of the envelope sender which is not necessarily the From: domain.

Mark Sapiro <mark at>
Sent from my Not_an_iThing with standards compliant, open source software.

More information about the MailScanner mailing list