Messaging Gateway

 View Only
  • 1.  Sender Authentication Failed on valid emails

    Posted May 28, 2014 12:07 PM
      |   view attached

    We have a couple users who are having valid emails blocked.  Our Messaging Gateway (version 10.5.2) is configured to authenticate both SPF and Sender ID.

     

    The emails are requested weekly rate updates, and the Accepted from and Logical IP when I view the message audit details are valid within listed addresses when I SPF lookups.  domain/IP does not show up on the common blacklists.

     

    Failed Verdicts are "Sender Authentication Failed", with Filter Policy of "Static senderauth fail".

     

    Attaching a screenshot of the log for one of these messages.

     

    Any thoughts or ideas?



  • 2.  RE: Sender Authentication Failed on valid emails

    Posted May 30, 2014 08:35 AM

    No one?



  • 3.  RE: Sender Authentication Failed on valid emails

    Broadcom Employee
    Posted May 30, 2014 11:20 PM

    Hi Ryan,

    it looks like they have a problem with their SPF records.

    I tried two external sites to test and looks like there is some kind of issue with the SPF record for that domain.

    RESULTS FROM FIRST TEST:

    =========================

    Connecting from 64.94.177.111
    220 box4.bevhost.com ESMTP Postfix
    HELO msgbsvc.com
    250 box4.bevhost.com
    MAIL FROM: <mail@msgbsvc.com>
    250 2.1.0 Ok
    RCPT TO: <nobody@tools.bevhost.com>
    450 4.7.1 <nobody@tools.bevhost.com>: Recipient address rejected: Policy Rejection- Your message has been delayed because you are sending from an email address with no SPF record or a server that is NOT set up correctly (eg missing/mismatching PTR).
    QUIT
    221 2.0.0 Bye</nobody@tools.bevhost.com>

    Results from Second test:

    ===========================

    Input accepted, querying now...
    evaluating v=spf1 a mx ptr ip4:64.95.41.128/25 ip4:64.94.177.0/24 ip4:64.94.164.0/24 ip4:74.201.124.0/25 ~all ...
    Results - record processed without error.

    The result of the test (this should be the default result of your record) was, ambiguous . The explanation returned was, SPF Ambiguity Warning: No A records found for: msgbsvc.com

    ==========================

    Successful TEST for Symantec:

    ==============

    Input accepted, querying now...
    evaluating v=spf1 include:spf.symantec.com ip4:207.38.45.154 include:spf.messagelabs.com include:spf-ilg.symantec.com include:spf-mtv.symantec.com ip4:63.245.193.25 ip4:63.245.197.25 ip4:63.245.201.25 ~all ...
    SPF record passed validation test

    ==============

    Please use this website to check differnet allowed syntax for SPF records.

    http://www.openspf.org/SPF_Record_Syntax

    I hope that helps.



  • 4.  RE: Sender Authentication Failed on valid emails

    Broadcom Employee
    Posted Jun 04, 2014 02:31 AM

    Hi Ryan,

    Do you require any further assistance?

    Please let us know if any further assistance is required.

     



  • 5.  RE: Sender Authentication Failed on valid emails

    Posted Jun 04, 2014 12:26 PM

    Sorry, I have been out the past 2 days with a sick child.

     

    I do see what you mean, I was only using the kitterman.com tools and just did the Get SPF record, I guess I didn't proceed far enough to actually check it.

     

    Thanks for all the help, I am kicking this back to the email sender then! :)