Slashdot Mirror


Does SPF Really Help Curtail Forged Email Headers?

Intelopment asks: "My Domain name has recently been used a lot in the 'Reply' field by some inconsiderate spammer, and my ISP has suggested that I consider using the Open SPF service as a way to stop spammers from using my domain name for in their mail headers field. From what I can tell, it requires the receiving mail server to actually participate in the SPF service, which is where I have my doubts. Does anyone have any experience with this service? Does it work? Are many ISPs using Open SFP?"

4 of 90 comments (clear)

  1. drastically reduced mail server bounces by SkunkPussy · · Score: 4, Interesting

    I used to receive 30 bouncebacks a day due to spam. I switched to SPF, and it didnt immediately make a difference. After several weeks I noticed I was receiving maybe 1 or 2 bouncebacks a day.

    I cannot be certain whether this is due to the spammer observing my implementation of SPF and no longer using my domain as a return address, or whether the spammer still uses my domain but mail servers have stopped sending me the bouncebacks.

    Either way I+internet won, spammer lost.

    --
    SURELY NOT!!!!!
  2. Not worth the complaints by braddeicide · · Score: 3, Interesting

    We checked SPF on all incoming mail to our ISP, it worked for a while, but eventually it wasn't worth the effort of dealing with legit mis-configured companies. Not to mention the fact customers wouldn't believe it wasn't our fault. Yes even banks make mistakes.

  3. It Improves Your Fun by chromatic · · Score: 3, Interesting

    The best part of using SPF, for me, is responding to automated mailers that send me messages saying "Your message to us failed an SPF check!" I always have great fun explaining that failing an SPF check means that they would have a better chance of reaching the person who actually sent the message by picking a random address on a random other domain.

  4. It worked for me! by mophab · · Score: 4, Interesting

    I think the spammers check the SPF records, and if there is one they don't forge your address.
    I had lots of problems with my e-mail address being forged by spammers.
    When I put in an SPF record, it stopped immediatly.