<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : SPF filter should be higher up in the order</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : SPF filter should be higher up in the order]]></description>
  <pubDate>Wed, 11 Mar 2026 15:43:33 +0000</pubDate>
  <lastBuildDate>Sun, 24 Jun 2012 04:57:10 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=7013</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[SPF filter should be higher up in the order : That is a very sweet solution...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14408&amp;title=spf-filter-should-be-higher-up-in-the-order#14408</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104">yapadu</a><br /><strong>Subject:</strong> 7013<br /><strong>Posted:</strong> 24 June 2012 at 4:57am<br /><br />That is a very sweet solution for those who pass email through spamassassin after spamfilter.]]>
   </description>
   <pubDate>Sun, 24 Jun 2012 04:57:10 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14408&amp;title=spf-filter-should-be-higher-up-in-the-order#14408</guid>
  </item> 
  <item>
   <title><![CDATA[SPF filter should be higher up in the order :   Found a solution. I have spamassassin...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14405&amp;title=spf-filter-should-be-higher-up-in-the-order#14405</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=102">WebGuyz</a><br /><strong>Subject:</strong> 7013<br /><strong>Posted:</strong> 09 June 2012 at 7:57am<br /><br /><pre>Found a solution. I have spamassassin check after the SFE and the ability to do a <br>content check of each email. Realized that in the header of each email that was whitelisted<br>there a rejection reason as well:</pre><pre>X-SF-WhiteListedReason: AutoWhiteList Force DeliveryX-Rejection-Reason: 15 - 550 The sender did not meet Sender Policy Framework rules. Please see http://spf.pobox.com - This email was rejected by our spamfilter. To notify the recipient go to http://spam.webguyz.net/freeme.aspX-Return-Path: <a href="mailto:&#111;nlinebanking@e&#097;lerts.bankofamerica.com" target="_blank" rel="nofollow">onlinebanking@ealerts.bankofamerica.com</a></pre><pre>Going to do a filter check if whitelistesd &amp;  rejection reason 'did not meet Sender Policy Framework Rules'</pre><pre>That should fix the problem quite elegantly.</pre>]]>
   </description>
   <pubDate>Sat, 09 Jun 2012 07:57:05 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14405&amp;title=spf-filter-should-be-higher-up-in-the-order#14405</guid>
  </item> 
  <item>
   <title><![CDATA[SPF filter should be higher up in the order : You can keep after Roberto and...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14404&amp;title=spf-filter-should-be-higher-up-in-the-order#14404</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104">yapadu</a><br /><strong>Subject:</strong> 7013<br /><strong>Posted:</strong> 09 June 2012 at 3:16am<br /><br />You can keep after Roberto and see if he changes the system for you, but I have another suggestion.<br><br>It does not fix the issue 100% but it certainly should help.<br><br>Your situation may be different, but we allow users to view messages in quarantine via a web interface.&nbsp; They can click a message and view the message details, including to options:<br><br>* Release from quarantine<br>* Release from quarantine and whitelist sender<br><br>You could do your own SPF lookup when someone is looking at the message online.&nbsp; If the message fails the SPF check the whitelist sender option would not be available.<br><br>As mentioned how well this works would depend on your setup.&nbsp; I think in our situation that would probably work quite well.<br><br>Users could still manually whitelist the sender on our website, but it should reduce the instances of false whitelisting.<br><br>Your mileage may vary...<br>]]>
   </description>
   <pubDate>Sat, 09 Jun 2012 03:16:36 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14404&amp;title=spf-filter-should-be-higher-up-in-the-order#14404</guid>
  </item> 
  <item>
   <title><![CDATA[SPF filter should be higher up in the order :   How do I respond to customers...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14403&amp;title=spf-filter-should-be-higher-up-in-the-order#14403</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=102">WebGuyz</a><br /><strong>Subject:</strong> 7013<br /><strong>Posted:</strong> 01 June 2012 at 3:20pm<br /><br /><span style='color: rgb31, 73, 125; font-family: "Calibri","sans-serif"; font-size: 11pt;'><div>How do I respond to customers like this who get Bank of America phishing attempts all the time because the scammers are using the same exact email address as what BofA uses. These was an official looking email asking them to log into their account and of course the links were somewhere overseas</div><div>&nbsp;</div><div>Customers Email:</div><p ="Ms&#111;normal">"This is the third one of these I’ve gotten.&nbsp; I’ve confirmed they are not legit.&nbsp; While I forward them to the real BOA, now I’m sending them to my e-mail provider to black-list them."</p><div><o:p>How do I explain to customer that I can't do a thing about it.</o:p></div><div><o:p></o:p>&nbsp;</div><div><o:p>Whitelisting by IP should be before SPF but whitelisting by name before SPF is a problem. Looked at my logfile and had over 300 emails from bankofamerica.com and all but 4 had failed the spf test, but they were forwarded to my customers because they use BofA and have it in their whitelist. heck I have BofA in my whitelist and I get the same crap and can't stop it. Doesn't do any good to remove all the entries from whitelists and hard code the IPs because the first authentic looking email from them that ends up in quarantine will be retrieved (and whitelisted)&nbsp;by customers who don't know any better.</o:p></div><div><o:p></o:p>&nbsp;</div><div><o:p>Can't beleive I'm the only one having this issue. I swear the spammers are targeting my customers because I use SFE.</o:p></div><div><o:p></o:p>&nbsp;</div><div><o:p></o:p></span>&nbsp;</div><p ="Ms&#111;normal"><span style='color: rgb31, 73, 125; font-family: "Calibri","sans-serif"; font-size: 11pt;'><?: prefix = o /><o:p>&nbsp;</o:p></span></p>]]>
   </description>
   <pubDate>Fri, 01 Jun 2012 15:20:41 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14403&amp;title=spf-filter-should-be-higher-up-in-the-order#14403</guid>
  </item> 
  <item>
   <title><![CDATA[SPF filter should be higher up in the order :   Webguyz, i think you are not...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14393&amp;title=spf-filter-should-be-higher-up-in-the-order#14393</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=905">AndrewD</a><br /><strong>Subject:</strong> 7013<br /><strong>Posted:</strong> 04 May 2012 at 9:51am<br /><br />Webguyz, i think you are not thinking of the alternative.<div>a user receives an email from <a href="mailto:spoofed@legit.com" target="_blank" rel="nofollow">spoofed@legit.com</a> however legit.com havnt implemented SPF correctly so the message goes to quarrantine. Everything good.</div><div>then the user receives a valid email from legit.com but it goes to their quarrantine. So they whitelist legit.com - Thats how it works now but the spoofed will come through as they are in the whitelist.</div><div>&nbsp;</div><div>if we enforce SPF prior to whitelist then regardless of whitelisting then all the emails from legit.com will get quarantined and you will have users screaming "how come this always gets quarantined... I added it to my whitelist." This to me would b e a bigger problem.</div><div>&nbsp;</div><div>1. The users should only be whitelisting the email (<a href="mailto:user@legit.com" target="_blank" rel="nofollow">user@legit.com</a>) not the domain (<a href="mailto:*@legit.com" target="_blank" rel="nofollow">*@legit.com</a>). I know this doesnt always help as some companies (constant contacts) utilize random users.</div><div>&nbsp;</div><div>2. As has been said add the IP to the whitelist, and run a script to remove all email whitelist entries for the domain. I know the email servers may change their IP address but from the CIDR given above they have listed a large range of IP's so you could add them all. (i have written an app to convert CIDR to valid list of addresses if you want. I did this for greylisting companies like gmail.) Then if some time down the track they suddenly start getting caught again you know that the IP has gone outside the original SPF CIDR range and you simply adjust your script to include all the new CIDR's.</div><div>&nbsp;</div><div>then as long as legit.com keep their network secure and dont allow spammers to open relay through them you should not have any problem.</div><div>&nbsp;</div><div>Cheers.</div>]]>
   </description>
   <pubDate>Fri, 04 May 2012 09:51:24 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14393&amp;title=spf-filter-should-be-higher-up-in-the-order#14393</guid>
  </item> 
  <item>
   <title><![CDATA[SPF filter should be higher up in the order : I don&amp;#039;t think I&amp;#039;m over...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14370&amp;title=spf-filter-should-be-higher-up-in-the-order#14370</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104">yapadu</a><br /><strong>Subject:</strong> 7013<br /><strong>Posted:</strong> 18 April 2012 at 3:42am<br /><br />I don't think I'm over thinking this, but I don't think SPF should overrule a white list.<br><br>You come across as a bit hostile, so I will shut up now.&nbsp; Hopefully you come up with a solution.<br>]]>
   </description>
   <pubDate>Wed, 18 Apr 2012 03:42:55 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14370&amp;title=spf-filter-should-be-higher-up-in-the-order#14370</guid>
  </item> 
  <item>
   <title><![CDATA[SPF filter should be higher up in the order :    yapadu wrote:If someone is...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14369&amp;title=spf-filter-should-be-higher-up-in-the-order#14369</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=102">WebGuyz</a><br /><strong>Subject:</strong> 7013<br /><strong>Posted:</strong> 18 April 2012 at 12:53am<br /><br /><table width="99%"><tr><td class="BBquote"><img src="forum_images/quote_box.png" title="Originally posted by yapadu" alt="Originally posted by yapadu" style="vertical-align: text-bottom;" /> <strong>yapadu wrote:</strong><br /><br /><br>If someone is spoofing paypal it would be rejected.&nbsp; You would also need a way to prevent someone from whitelisting paypal email addresses at the user level...<br><br>Gets complex quick.<br></td></tr></table><div></div><div></div>But once they retrieve it from quarantine paypal.com is back in the whitelist and your blacklist entry is meaningless.<div>&nbsp;</div><div>Your overthinking this. The idea is to whitelist a REAL actual domain, not a faked domain</div>]]>
   </description>
   <pubDate>Wed, 18 Apr 2012 00:53:09 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14369&amp;title=spf-filter-should-be-higher-up-in-the-order#14369</guid>
  </item> 
  <item>
   <title><![CDATA[SPF filter should be higher up in the order :    IP addresses change. Most...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14368&amp;title=spf-filter-should-be-higher-up-in-the-order#14368</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=102">WebGuyz</a><br /><strong>Subject:</strong> 7013<br /><strong>Posted:</strong> 18 April 2012 at 12:50am<br /><br /> IP addresses change. Most major companies do NOT want to be spoofed and know what a SPF record is and how to add one.<div></div><div></div>Not sure what your talking about confusing end users, they have no clue how it works now. All they know is they are getting phishing spam and sending it to me the admin to stop it and I have to tell them I can't without deleteing their autowhitelistentry's and then they next time they retrieve their paypal.com emails from quarantine they will be autowhitelisted again and that they&nbsp;will be&nbsp;allowing the same phishing email from faux paypal.com addresses.]]>
   </description>
   <pubDate>Wed, 18 Apr 2012 00:50:13 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14368&amp;title=spf-filter-should-be-higher-up-in-the-order#14368</guid>
  </item> 
  <item>
   <title><![CDATA[SPF filter should be higher up in the order : So, expanding on that line of...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14367&amp;title=spf-filter-should-be-higher-up-in-the-order#14367</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104">yapadu</a><br /><strong>Subject:</strong> 7013<br /><strong>Posted:</strong> 18 April 2012 at 12:44am<br /><br />So, expanding on that line of thought a bit more.<br><br>1) Blacklist paypal<br>2) Whitelist paypal domain, if SPF also validates.<br><br>If someone is spoofing paypal it would be rejected.&nbsp; You would also need a way to prevent someone from whitelisting paypal email addresses at the user level...<br><br>Gets complex quick.<br>]]>
   </description>
   <pubDate>Wed, 18 Apr 2012 00:44:06 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14367&amp;title=spf-filter-should-be-higher-up-in-the-order#14367</guid>
  </item> 
  <item>
   <title><![CDATA[SPF filter should be higher up in the order : They could be calculated from...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14366&amp;title=spf-filter-should-be-higher-up-in-the-order#14366</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104">yapadu</a><br /><strong>Subject:</strong> 7013<br /><strong>Posted:</strong> 18 April 2012 at 12:40am<br /><br />They could be calculated from the SPF records.&nbsp; Here is PayPal.<br><br>ip4:216.113.188.96/27 ip4:66.211.168.230/31 ip4:173.0.84.224/28<br>ip4:208.201.241.163 ip4:67.72.99.26 ip4:206.165.246.80/29<br>ip4:64.127.115.252 ip4:194.64.234.129 ip4:65.110.161.77<br>ip4:204.13.11.48/29 ip4:63.80.14.0/23 ip4:208.64.132.0/22 ip4:81.223.46.0/27<br><br>etc. etc.<br><br>In reality though monitoring where real email comes from would give you a much smaller subset.<br><br>The ability to whitelist things in a different manner, one that the end users can not see would be good.&nbsp; For example if we could whitelist an email address and put a condition that is MUST also validate with SPF, then allow it through.<br><br>That would be way to confusing for end users but we we had the power to add server wide whitelisting with a more advanced rule-set that would be be powerful.<br><br>]]>
   </description>
   <pubDate>Wed, 18 Apr 2012 00:40:59 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7013&amp;PID=14366&amp;title=spf-filter-should-be-higher-up-in-the-order#14366</guid>
  </item> 
 </channel>
</rss>