What is SPF (Sender Policy Framework)?
http://customer.convio.com/whatisspf
What is SPF?
Sender Policy Framework (SPF) is one of a number of proposed standards which will enable owners of Internet domains to publish information which other people's email systems can use to help decide whether an email is legitimate or forged. SPF has now emerged as the clear winner and is actively supported by major email services such as Google, Yahoo and AOL.
The general umbrella acronym for such techniques and proposals is MARID - Mail Authentication via Records In DNS - and the IETF has had a number of MARID working groups over the years.
Other MARID proposals of note include a proprietary one from Microsoft, called "Email Caller ID", and one contributed by Yahoo! called Domain Keys.
Why does SPF matter to organizations doing email marketing?
Major consumer ISPs such as AOL, Hotmail Yahoo! and Google Gmail have started to perform SPF checks on inbound mail. These checks are merely one part of a comprehensive, mutli-layered strategy to combat spam, but a positive confirmation via SPF that the email is legitimate and authorized is an important element in maximizing the likelihood of successful deliveries, and one under the organizations' control.
How do SPF and similar systems work?
The common theme in all these systems is that the owner of an internet domain, for example foo.org, will publish records in the DNS zone for foo.org that determine which servers on the internet are allowed to send email on behalf of addresses in that domain. A mail server receiving email which claims to be from foo.org can look up these records, if they exist, and determine if the sending server is authorized to send email for that domain.
Yahoo! Domain Keys takes things one step further; instead of just identifying authorized mailservers, its process involves applying a digital signature to the email headers. This is more complex to deploy since it is not a one-time publication of static data, the capability to calculate the digital signatures must be added to the email sending software, and PKI infrastructure must be managed. Domain Keys is currently being protoyped by Yahoo! Mail and Google Gmail.
Convio anticipates that we may in the future add support to our software for Domain Keys based on need, but there is currently no timeline to do so.
What are the recent technical developments in SPF?
The SPF committee sat down with Microsoft in 2004 to try to unify SPF and Caller-ID ... the merged proposal was an awkward hybrid called Sender ID, which Vinton Cerf, the "father of the Internet" described to the author of this FAQ as "a bit of a camel", and was unpopular and derided in many communities as it would require implementors to license Microsoft's Caller ID patent to fully use it - to ensure interoperability, Internet and network technology standards are traditionally open and unencumbered by intellectual property, even ones originated by vendors such as NFS (Sun Microsystems) or SMB/CIFS (Microsoft).
The good news is that SPF version 2.0 has emerged from the ashes of Sender ID, and is becoming popular, and it has subsumed some nice features from the Microsoft Caller ID proposal, of note the ability to define SPF for the "From" address more familiar to end users, as well as the return path (envelope sender) known only to email system administrators.
How does SPF need to be set up for an organization using Convio?
To get full benefit from SPF, there need to be two sets of records, for the return path and the From address.
The return path address on Convio system-generated email is a convio.net one, so SPF records for that are Convio's responsibility. The records for the "From" address will need to be published in the organization's DNS.
The SPF term which maps to "From address" (modulo some small print) is "Purported Responsible Authority" or PRA. An SPF PRA record defines which servers are allowed to send email with the organization's domain name in the From address, and must be published in the DNS for that domain.
Determining what the SPF policy should be for a domain is a matter for each organizations' IT team; Convio offers the following guidance:
If an organization publishes a PRA record for a domain used in the "From" address of Convio emails, it MUST contain a rule which explicitly authorizes Convio's servers as legitimate email sources for that domain. To do this, include the following rule:
+autboundmail.convio.net
I just have a simple setup, can you recommend a PRA setting for me?
For 95% of our clients, an appropriate policy for which servers can send email is "our mail inbound server(s), plus Convio's" - to determine if this right for your organization, make sure the following conditions are met:
1. Convio is the only ASP-hosted service that sends email on the organization's behalf
2. Employees are not sending email with organization "From" addresses using external services such as Yahoo! Mail, Blackberry, T-mobile or their home ISP's mail servers; if they are, it will be necessary to curb the practice before deploying a PRA record (whether you use Convio or not).
3. Your email setup is symmetrical, in the sense that the only server(s) which deliver(s) your outbound office email are the same one(s) that accept(s) inbound mail. If you are using an ISP to manage your office email inboxes instead of having your own mail server(s) on the premises, you'll need to confirm that their setup is symmetrical in this way.
Provided the above conditions are met, the following PRA record will work:
spf2.0/pra +mx +autboundmail.convio.net ?all
This translates as: "Servers specifically allowed to send mail are our inbound server(s), and (ii) Convio's servers. For mail from any other source, treat it as SPF neutral, as if we had never published this PRA record."
What review steps should I take before publishing my PRA record?
In addition to making sure it correctly encompasses the way email is being used within your organization, it is recommended that you have Convio Support review your proposed record before you publish it, to confirm it correctly authorizes our servers. Open a Support Desk ticket.
What is the syntax for putting SPF records in DNS?
An SPF record is published as the TXT record type, for the domain itself. SPF-checking email servers can differentiate it from other TXT records using the fact that it starts with "spf2.0....".
An example of the DNS syntax used in a zone file for the BIND (named) DNS server software (presuming the example foo.org domain name) would be:
foo.org. 86400 IN TXT "spf2.0/pra +mx +autboundmail.convio.net ?all"
Note the trailing dot after foo.org - tthis indicates to BIND that this record has an absolute name and not relative to the zone domain name (SOA). The other syntax for specifying domain-level records to omit the name field entirely, but it is arguably less clear.
Other DNS software uses different input formats - if you are using an offsite vendor, perhaps your office ISP, to host your DNS for you they will typically provide a web interface, where you will need to select the record type "TXT" and supply the SPF string as the value.
Where can I learn more about SPF?
There are numerous online forums, mailing lists, etc. - the best general resource website and a great starting point is http://spf.pobox.com/.
Resources
Email Sender Verification and setup
Yahoo DomainKeys: Configuration Pitfalls, Tips, and Comments
Categories
- All Categories
- Shannon parent
- shannon 2
- shannon 1
- 21 Advocacy DC Users Group
- 14 BBCRM PAG Discussions
- 89 High Education Program Advisory Group (HE PAG)
- 28 Luminate CRM DC Users Group
- 8 DC Luminate CRM Users Group
- Luminate PAG
- 5.9K Blackbaud Altru®
- 58 Blackbaud Award Management™ and Blackbaud Stewardship Management™
- 409 bbcon®
- 2K Blackbaud CRM™ and Blackbaud Internet Solutions™
- donorCentrics®
- 1.1K Blackbaud eTapestry®
- 2.8K Blackbaud Financial Edge NXT®
- 1.1K Blackbaud Grantmaking™
- 527 Education Management Solutions for Higher Education
- 1 JustGiving® from Blackbaud®
- 4.6K Education Management Solutions for K-12 Schools
- Blackbaud Luminate Online & Blackbaud TeamRaiser
- 16.4K Blackbaud Raiser's Edge NXT®
- 4.1K SKY Developer
- 547 ResearchPoint™
- 151 Blackbaud Tuition Management™
- 1 YourCause® from Blackbaud®
- 61 everydayhero
- 3 Campaign Ideas
- 58 General Discussion
- 115 Blackbaud ID
- 87 K-12 Blackbaud ID
- 6 Admin Console
- 949 Organizational Best Practices
- 353 The Tap (Just for Fun)
- 235 Blackbaud Community Feedback Forum
- 124 Ninja Secret Society
- 32 Blackbaud Raiser's Edge NXT® Receipting EAP
- 55 Admissions Event Management EAP
- 18 MobilePay Terminal + BBID Canada EAP
- 36 EAP for New Email Campaigns Experience in Blackbaud Luminate Online®
- 109 EAP for 360 Student Profile in Blackbaud Student Information System
- 41 EAP for Assessment Builder in Blackbaud Learning Management System™
- 9 Technical Preview for SKY API for Blackbaud CRM™ and Blackbaud Altru®
- 55 Community Advisory Group
- 46 Blackbaud Community Ideas
- 26 Blackbaud Community Challenges
- 7 Security Testing Forum
- 1.1K ARCHIVED FORUMS | Inactive and/or Completed EAPs
- 3 Blackbaud Staff Discussions
- 7.7K ARCHIVED FORUM CATEGORY [ID 304]
- 1 Blackbaud Partners Discussions
- 1 Blackbaud Giving Search™
- 35 EAP Student Assignment Details and Assignment Center
- 39 EAP Core - Roles and Tasks
- 59 Blackbaud Community All-Stars Discussions
- 20 Blackbaud Raiser's Edge NXT® Online Giving EAP
- Diocesan Blackbaud Raiser’s Edge NXT® User’s Group
- 2 Blackbaud Consultant’s Community
- 43 End of Term Grade Entry EAP
- 92 EAP for Query in Blackbaud Raiser's Edge NXT®
- 38 Standard Reports for Blackbaud Raiser's Edge NXT® EAP
- 12 Payments Assistant for Blackbaud Financial Edge NXT® EAP
- 6 Ask an All Star (Austen Brown)
- 8 Ask an All-Star Alex Wong (Blackbaud Raiser's Edge NXT®)
- 1 Ask an All-Star Alex Wong (Blackbaud Financial Edge NXT®)
- 6 Ask an All-Star (Christine Robertson)
- 21 Ask an Expert (Anthony Gallo)
- Blackbaud Francophone Group
- 22 Ask an Expert (David Springer)
- 4 Raiser's Edge NXT PowerUp Challenge #1 (Query)
- 6 Ask an All-Star Sunshine Reinken Watson and Carlene Johnson
- 4 Raiser's Edge NXT PowerUp Challenge: Events
- 14 Ask an All-Star (Elizabeth Johnson)
- 7 Ask an Expert (Stephen Churchill)
- 2025 ARCHIVED FORUM POSTS
- 322 ARCHIVED | Financial Edge® Tips and Tricks
- 164 ARCHIVED | Raiser's Edge® Blog
- 300 ARCHIVED | Raiser's Edge® Blog
- 441 ARCHIVED | Blackbaud Altru® Tips and Tricks
- 66 ARCHIVED | Blackbaud NetCommunity™ Blog
- 211 ARCHIVED | Blackbaud Target Analytics® Tips and Tricks
- 47 Blackbaud CRM Higher Ed Product Advisory Group (HE PAG)
- Luminate CRM DC Users Group
- 225 ARCHIVED | Blackbaud eTapestry® Tips and Tricks
- 1 Blackbaud eTapestry® Know How Blog
- 19 Blackbaud CRM Product Advisory Group (BBCRM PAG)
- 1 Blackbaud K-12 Education Solutions™ Blog
- 280 ARCHIVED | Mixed Community Announcements
- 3 ARCHIVED | Blackbaud Corporations™ & Blackbaud Foundations™ Hosting Status
- 1 npEngage
- 24 ARCHIVED | K-12 Announcements
- 15 ARCHIVED | FIMS Host*Net Hosting Status
- 23 ARCHIVED | Blackbaud Outcomes & Online Applications (IGAM) Hosting Status
- 22 ARCHIVED | Blackbaud DonorCentral Hosting Status
- 14 ARCHIVED | Blackbaud Grantmaking™ UK Hosting Status
- 117 ARCHIVED | Blackbaud CRM™ and Blackbaud Internet Solutions™ Announcements
- 50 Blackbaud NetCommunity™ Blog
- 169 ARCHIVED | Blackbaud Grantmaking™ Tips and Tricks
- Advocacy DC Users Group
- 718 Community News
- Blackbaud Altru® Hosting Status
- 104 ARCHIVED | Member Spotlight
- 145 ARCHIVED | Hosting Blog
- 149 JustGiving® from Blackbaud® Blog
- 97 ARCHIVED | bbcon® Blogs
- 19 ARCHIVED | Blackbaud Luminate CRM™ Announcements
- 161 Luminate Advocacy News
- 187 Organizational Best Practices Blog
- 67 everydayhero Blog
- 52 Blackbaud SKY® Reporting Announcements
- 17 ARCHIVED | Blackbaud SKY® Reporting for K-12 Announcements
- 3 Luminate Online Product Advisory Group (LO PAG)
- 81 ARCHIVED | JustGiving® from Blackbaud® Tips and Tricks
- 1 ARCHIVED | K-12 Conference Blog
- Blackbaud Church Management™ Announcements
- ARCHIVED | Blackbaud Award Management™ and Blackbaud Stewardship Management™ Announcements
- 1 Blackbaud Peer-to-Peer Fundraising™, Powered by JustGiving® Blogs
- 39 Tips, Tricks, and Timesavers!
- 56 Blackbaud Church Management™ Resources
- 154 Blackbaud Church Management™ Announcements
- 1 ARCHIVED | Blackbaud Church Management™ Tips and Tricks
- 11 ARCHIVED | Blackbaud Higher Education Solutions™ Announcements
- 7 ARCHIVED | Blackbaud Guided Fundraising™ Blog
- 2 Blackbaud Fundraiser Performance Management™ Blog
- 9 Foundations Events and Content
- 14 ARCHIVED | Blog Posts
- 2 ARCHIVED | Blackbaud FIMS™ Announcement and Tips
- 59 Blackbaud Partner Announcements
- 10 ARCHIVED | Blackbaud Impact Edge™ EAP Blogs
- 1 Community Help Blogs
- Diocesan Blackbaud Raiser’s Edge NXT® Users' Group
- Blackbaud Consultant’s Community
- Blackbaud Francophone Group
- 1 BLOG ARCHIVE CATEGORY
- Blackbaud Community™ Discussions
- 8.3K Blackbaud Luminate Online® & Blackbaud TeamRaiser® Discussions
- 5.7K Jobs Board