Re: [Tools-discuss] SPF issues & relaying on zinfandel.ietf.org

Lars Eggert <lars.eggert@nokia.com> Mon, 19 July 2010 12:56 UTC

Return-Path: <lars.eggert@nokia.com>
X-Original-To: tools-discuss@core3.amsl.com
Delivered-To: tools-discuss@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4443D3A6895 for <tools-discuss@core3.amsl.com>; Mon, 19 Jul 2010 05:56:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.386
X-Spam-Level:
X-Spam-Status: No, score=-6.386 tagged_above=-999 required=5 tests=[AWL=0.212, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pwuAJhb+-7KE for <tools-discuss@core3.amsl.com>; Mon, 19 Jul 2010 05:56:18 -0700 (PDT)
Received: from mgw-mx06.nokia.com (smtp.nokia.com [192.100.122.233]) by core3.amsl.com (Postfix) with ESMTP id 355C23A6896 for <tools-discuss@ietf.org>; Mon, 19 Jul 2010 05:56:17 -0700 (PDT)
Received: from vaebh106.NOE.Nokia.com (vaebh106.europe.nokia.com [10.160.244.32]) by mgw-mx06.nokia.com (Switch-3.3.3/Switch-3.3.3) with ESMTP id o6JCuRuR029650; Mon, 19 Jul 2010 15:56:27 +0300
Received: from vaebh104.NOE.Nokia.com ([10.160.244.30]) by vaebh106.NOE.Nokia.com with Microsoft SMTPSVC(6.0.3790.4675); Mon, 19 Jul 2010 15:56:26 +0300
Received: from mgw-sa01.ext.nokia.com ([147.243.1.47]) by vaebh104.NOE.Nokia.com over TLS secured channel with Microsoft SMTPSVC(6.0.3790.4675); Mon, 19 Jul 2010 15:56:25 +0300
Received: from mail.fit.nokia.com (esdhcp030222.research.nokia.com [172.21.30.222]) by mgw-sa01.ext.nokia.com (Switch-3.3.3/Switch-3.3.3) with ESMTP id o6JCuOlU006188 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 19 Jul 2010 15:56:24 +0300
X-Virus-Status: Clean
X-Virus-Scanned: clamav-milter 0.96.1 at fit.nokia.com
Mime-Version: 1.0 (Apple Message framework v1081)
Content-Type: text/plain; charset="windows-1252"
From: Lars Eggert <lars.eggert@nokia.com>
In-Reply-To: <4C44498C.7000509@levkowetz.com>
Date: Mon, 19 Jul 2010 15:56:13 +0300
Content-Transfer-Encoding: quoted-printable
Message-Id: <873B833C-F8E7-4124-BC20-F61D5F6B5170@nokia.com>
References: <CF402606-DB12-4D79-9506-18FAAA2C360E@nokia.com> <4C44498C.7000509@levkowetz.com>
To: Henrik Levkowetz <henrik@levkowetz.com>, Barry Leiba <barryleiba@computer.org>, Marocco Enrico <enrico.marocco@telecomitalia.it>
X-Mailer: Apple Mail (2.1081)
X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.2.5 (mail.fit.nokia.com); Mon, 19 Jul 2010 15:56:13 +0300 (EEST)
X-OriginalArrivalTime: 19 Jul 2010 12:56:25.0139 (UTC) FILETIME=[CB8A5830:01CB2741]
X-Nokia-AV: Clean
Cc: Tools Team Discussion <tools-discuss@ietf.org>
Subject: Re: [Tools-discuss] SPF issues & relaying on zinfandel.ietf.org
X-BeenThere: tools-discuss@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF Tools Discussion <tools-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/tools-discuss>, <mailto:tools-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tools-discuss>
List-Post: <mailto:tools-discuss@ietf.org>
List-Help: <mailto:tools-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tools-discuss>, <mailto:tools-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jul 2010 12:56:20 -0000

CC'ing Barry, who may have the expertise. (And also Enrico, whom I thought I had CC'ed earlier already. Hm.)

On 2010-7-19, at 15:48, Henrik Levkowetz wrote:

> Hi Lars,
> 
> On 2010-07-19 12:49 Lars Eggert said:
>> Hi,
>> 
>> Enrico and me are trying to debug a mail delivery issue that occurs when he sends email to a @tools.ietf.org alias that forwards to me (e.g., draft-eggert-tcpm-historicize@tools.ietf.org).
>> 
>> What happens is that the Nokia MX drops the incoming email:
>> 
>> lars.eggert@nokia.com
>>   (generated from draft-eggert-tcpm-historicize@tools.ietf.org)
>>   SMTP error from remote mail server after end of data:
>>   host mx2.nokia.com [147.243.177.56]: 551 5.0.0 DKIM or SPF failed
>> 
>> This is because telecomitalia.it publishes an SPF record with 
>> 
>> “Found v=spf1 record for _spf.telecomitalia.it:
>> v=spf1 ip4:156.54.232.99 ip4:156.54.232.100 ip4:217.169.121.4 ip4:217.169.121.5 ip4:156.54.233.200 ip4:156.54.233.201 ip4:217.169.121.20 ip4:217.169.121.21 –all”
>> 
>> and relay=zinfandel.tools.ietf.org [64.170.98.42] does of course not appear in that SPF record for the envelope sender enrico.marocco@telecomitalia.it.
>> 
>> I'm not super knowledgable about SPF, so it may well be that the Nokia MX is misconfigured, but at least our admins claim that it isn't. Is this a configuration issue on zinfandel?
> 
> Me neither; but I remember that somebody who is knowledgeable about this
> wrote about this problem in an IETF mail thread not too long ago.  I'll
> see if I can find it.
> 
> From what I remember, my impression is that this is partially a configuration
> error (not on zinfandel, possibly on telecom italia's server) but also
> partially a weakness of SPF in that it's not really up to handling the
> current situation correctly.  But I'll try to find the earlier thread,
> and see if that brings more enlightenment.
> 
> Alternatively maybe someone else on the list has more clue.
> 
> 
> Best,
> 
> 	Henrik