ORF Forum  >  ORF Technical Support  >  Sonicwall | Related IP | Failed SPF Checks

Sonicwall | Related IP | Failed SPF Checks

 
I installed a sonicwall nsa2400 firewall and I'm nating the public IP to our email server. On all emails coming in ORF is reporting the "Related IP" as our public IP for the mail server which I'm guessing is why emails are failing the SPF checks.

Does anyone know exactly whats happening?

Thanks,
Jean
Jean Davis (February 28, 2011)
I got a fix from Sonicwalls forums on this already. The firewall was changing the IP on the email header to our public IP.
Jean Davis (February 28, 2011)
in response to
Glad to hear the problem has been solved.

In case the firewall (or any relaying hosts between ORF and the internet) adds its on delivery information to the MIME email headers (as a Received: from line) instead of allowing emails thru "transparently", then it should be added to the Intermediate Host List of ORF, so ORF will skip them when analyzing the headers.

We often see such issues with secondary MXs: if ORF is unaware of them, it will consider the secondary MX IP (which relays to the primary where ORF runs) as the sender, and all emails will be blocked by the SPF test if the domain owner has an SPF policy ending with "-all" published:

http://blog.vamsoft.com/2010/05/26/spf-test-and-intermediate-hosts/
Krisztian Fekete (March 1, 2011)
in response to

1. Your name:

2. Your email address (will not be published):

3. Your comment:

4. Please enter the words below: (must be completed only once)