<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : SPF return unknown</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : SPF return unknown]]></description>
  <pubDate>Sun, 19 Jul 2026 07:58:57 +0000</pubDate>
  <lastBuildDate>Wed, 06 Oct 2010 19:13:34 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=6879</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[SPF return unknown : Yes a smart spammer will not pick...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6879&amp;PID=13821&amp;title=spf-return-unknown#13821</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104">yapadu</a><br /><strong>Subject:</strong> 6879<br /><strong>Posted:</strong> 06 October 2010 at 7:13pm<br /><br />Yes a smart spammer will not pick a domain with valid SPF rules, a much higher % of spam will be stopped when a domain publishes SPF. <br><br>By publishing SPF records the domain owner is protecting themselves from spammers trying to forge email from their domain.<br><br>It is almost like a lock on a bike or house.&nbsp; Just because you have a lock does not mean you can't get broken into but a thief is probably just going to hit the house next door that does not have an alarm.<br><br>Thanks for the new release Roberto, a couple of nice new additions in there!<br>]]>
   </description>
   <pubDate>Wed, 06 Oct 2010 19:13:34 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6879&amp;PID=13821&amp;title=spf-return-unknown#13821</guid>
  </item> 
  <item>
   <title><![CDATA[SPF return unknown : ok ...  If I understand well,...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6879&amp;PID=13820&amp;title=spf-return-unknown#13820</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1295">vbourbeau</a><br /><strong>Subject:</strong> 6879<br /><strong>Posted:</strong> 06 October 2010 at 8:06am<br /><br />ok ...<DIV>&nbsp;</DIV><DIV>If I understand well, wise spamer can use domain name who don't respect the&nbsp;SPF RFC and bypass most of the SPF rules. </DIV>]]>
   </description>
   <pubDate>Wed, 06 Oct 2010 08:06:45 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6879&amp;PID=13820&amp;title=spf-return-unknown#13820</guid>
  </item> 
  <item>
   <title><![CDATA[SPF return unknown :  SpamFilter will return an &amp;#034;unknown&amp;#034;...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6879&amp;PID=13818&amp;title=spf-return-unknown#13818</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 6879<br /><strong>Posted:</strong> 05 October 2010 at 10:42pm<br /><br />SpamFilter will return an "unknown" if the SPF record is malformed, and will skip the SPF filter check to avoid blocking valid emails.<div><br></div><div>As a side-note, in your specific example, hallmark.com does indeed have what appears as an improperly formatted SPF record, since it contains two v=spf1 mechanisms:</div><div><br></div><div>hallmark.com. &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1 &nbsp; &nbsp; &nbsp; IN &nbsp; &nbsp; &nbsp;TXT &nbsp; &nbsp; "<b>v=spf1</b> ip4:208.1.139.0/24 ip4:129.33.92.0/24 ip4:65.116.50.141 ip4:65.116.50.144 ip4:65.116.50.142 ip4:65.116.50.143 ip4:162.94.28.0/24 <b>v=spf1</b> ip4:209.176.191.124 ip4:209.176.191.121 ip4:209.176.191.123 ip4:209.176.191.122 ip4:193.132.80.20 mx ~all"</div><div><br></div><div>while this does appear to violate the SPF RFC, we do see that the online verifier for openspf.org themselves marks that SPF record as legitimate. Due to this, we've just uploaded int he registered user area an updated build of SpamFilter (4.2.4.836) that ignores the duplicate v=spf1 mechanisms and continues to validate the remaining of the SPF record for further analysis.</div>]]>
   </description>
   <pubDate>Tue, 05 Oct 2010 22:42:04 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6879&amp;PID=13818&amp;title=spf-return-unknown#13818</guid>
  </item> 
  <item>
   <title><![CDATA[SPF return unknown : Hi  Lot of spam pass spamfilter...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6879&amp;PID=13817&amp;title=spf-return-unknown#13817</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1295">vbourbeau</a><br /><strong>Subject:</strong> 6879<br /><strong>Posted:</strong> 05 October 2010 at 2:23pm<br /><br /><DIV>Hi</DIV><DIV>&nbsp;</DIV><DIV>Lot of spam pass spamfilter and when I look in log the SPF result return "unknown". What mean this result? </DIV><DIV>&nbsp;</DIV><DIV>The spam is clearly not the domain owners. Example: <a href="mailto:e-cards@hallmark.com" target="_blank">e-cards@hallmark.com</A>&nbsp;with 65.166.169.23</DIV><DIV>&nbsp;</DIV>]]>
   </description>
   <pubDate>Tue, 05 Oct 2010 14:23:33 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6879&amp;PID=13817&amp;title=spf-return-unknown#13817</guid>
  </item> 
 </channel>
</rss>