SV: Spoofing and SPF

Mark Sapiro mark at msapiro.net
Mon Sep 12 12:52:51 UTC 2016


On September 12, 2016 1:50:29 AM PDT, "Trond M. Markussen" <markussen at media24.no> wrote:
>Yes, FROM_CUSTOMERDOMAIN is based on from: but in these cases that rule
>was
>triggered. However, the emails seem to have passed  the SPF check even
>though the senders were not listed in the SPF record for that domain.


That's because SPF is not based on the domain of From:. It is based on the domain of the envelope sender which is not necessarily the From: domain.



-- 
Mark Sapiro <mark at msapiro.net>
Sent from my Not_an_iThing with standards compliant, open source software.


More information about the MailScanner mailing list