• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Question SPF checking mode

Yaniv Zahavi

New Pleskian
Hi,

I was hoping someone could help me make the right decision on which SPF checking mode we should use under the Server-Wide Mail Settings. Our host provider is recommending to use the softfail option basically explaining that any email that fail the SPF check will be marked as spam but will still get delivered. When I'm reading the option description it says: "Reject mail when SPF resolves to softfail" which doesn't sound like it would let the emails through on softfail but actually reject them. I requested the host provider to verify that this is the option to choose even though the description sort of contradicts what I am being explained by host provider and they did confirm that the emails won't get rejected.

I wanted to check here to make sure I'm getting the correct answer form our host provider, base on what they telling me and what the option says I have some doubts. Can someone please clarify?

thx.
 

Attachments

  • spfmode.png
    spfmode.png
    39.5 KB · Views: 19
"Reject mail when SPF resolves to softfail" will definitely reject the emails with a softfail.

The one you are looking for is "Reject mail when SPF resolves to fail". Than one will reject the emails that hard fail the SPF check, but will allow the ones with softfail.

Up to late February/early March this year I was using the latter, but due to the ammount of SPAM and spoofing attempts was force to go to a more restricttive settings.
 
Hey Akrolis,

Thank you for that respond and it does make sense base on the description of the option but I had to ask here because of the explanation I was getting from our host provider that didn't make sense so I wasn't sure and so thank you for clarifying that.

Would you know if any of the available options would mark emails that meet the option conditions as spam but still deliver them?

Our host provider suggested to use the softfail option to have emails that fail the SPF check be marked as spam but still get delivered. Base on my understanding this is not how it works with the softfail option as it would reject all the emails. Is there an option that would mark the emails as spam but still deliver them if they fail the SPF check?

I attached an image of all the available options in case it helps.

thx.
 

Attachments

  • spfoptions.png
    spfoptions.png
    57.9 KB · Views: 13
None of the options of SPF checking mode will mark messages as spam. It's only used for SPF checking and will block incoming messages according to the selected option. If you don't want any messages to get blocked when the SPF check fails, chose the "Only create Received-SPF headers, never block" option.

It's up to the Spam filter (SpamAssassin) to mark any messages as spam. Which functions independently of the SPF checking mode. The Spam filter may or may not mark messages that fail the SPF check as spam depending on the total spam score configured.
 
Last edited:
Thank you for confirming that.

I was chasing my tail looking for an option that does not exists. I'm not sure my host provider was insisting there is an option for that, it didn't make sense to me because of the options descriptions so thank you for confirming.
 
Back
Top