About Me

Chris Barton

Chris Barton
Having been with "big red" since the Dr Solomons acquisition Chris has seen many come and go but is never content to be ...

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Spammers got a free pass?

Monday, September 10, 2007 at 6:15am by Chris Barton
Chris Barton

Terry Zink has found a spammer that had a valid SPF record and managed to get his advertisement into his field of attention. I don’t buy the “not that it helps” bit since it got as far as his blog ;) and after all anyone sending from this domain would get an SPF PASS when tested and would require further testing of its legitimacy and content.

I’ll get back to my point; This is not an “odd” thing!…

Schalk did a study some time ago on SPF but neglected to point out one important statistic that Terrys post reminded me about. Nearly 9% of the SPF records in his study were +all records. An SPF record of +all means anyone can send email for a domain, and the study covered what we term “domains in focus” (basically domains that we’ve seen used pretty recently and kept an eye on). We’ve kept an eye on this sort of thing for a long time since spammers were the first to adopt SPF for obvious reasons (+all loophole being the main one).

So for anyone that has got this far and doesn’t see the point yet… +all SPF records mean “I don’t care” :evil:

I firmly believe that not enough domain owners publish SPF records, so here is a quick guide to SPF for the-little-guy (All you big companies already have them right?).

Situation 1 – Your domain is hosted on a cpanel account (other $5/month hosting products are available) or your a single server company handling your own inbound mail :

"v=spf1 mx -all"

This SPF record says: Only my mail server can send mail for my domain.

Situation 2 – Mail is routed out (smarthosted) by your ISP:

"v=spf1 mx a:smtp.example.com -all"

This SPF record says: Only my mail server and the host smtp.example.com can send mail for my domain.
or

"v=spf1 mx ip4:172.16.25.25 -all"

This SPF record says: Only my mail server and the host with the IP address 172.16.25.25 can send mail for my domain.
or

"v=spf1 mx redirect:example.com -all"

This SPF record says: Only my mail server and any SPF host for example.com can send mail for my domain.

So there you go. That’s how you can help protect your domain from being forged by spammers. All we need to do now is have the rest of the world check them. Shoot anyone with a +all record type and convince any online auction and payment processing sites to make theirs less broken, so it actually works too (RFC 4408,10.1/6) ;-) .

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (1)

  • miles September 10, 2007 9:36AM

    The description of both situations needs to also say, “and we don’t send email to users with North American ISP, university, or large publicly available email addresses (or don’t mind if the email we do send them don’t reach their destination).”