SPF Record Error = No Email Received [RESOLVED]

Hello,

I never received any emails from your system when I signed up for both a wildcard and a single site certificates. The reason is that your system and even the support site is not included in your domain’s SPF records. So my server rejects them because that’s the correct policy when a site has SPF records set that don’t match the sending domain. Here is your SPF setting:

v=spf1 mx include:psoft.od.ua include:blackberryv.comodo.com include:spf1.comodo.com include:spf2.comodo.com include:spf3.comodo.com include:spf4.comodo.com -all

It looks like it’s not including your mail servers:

comodo.com mail is handled by 30 mail2.comodogroup.com.
comodo.com mail is handled by 10 mail1.comodogroup.com.
comodo.com mail is handled by 20 mail3.comodogroup.com.

nor your website:

comodo.com has address 91.199.212.132

Here is more info about SPF:

Thanks,

-Dave Bullock

  • Note I have also opened a trouble ticket, to which I received a canned response about making sure that my spam filters aren’t deleting your email. My spam filters only tag email, never delete. The email is never being received by my server because it checks your SPF record, sees that your IP doesn’t match it and rejects the message.

Dave,
Perhaps you can give us some more details to help us find the cause of this problem.
What IP address did you see as originating the mail?
What MTA do you use that is rejecting our mail?

I had the system send a test message to me, and it appeared to be from noreply_support@comodo.com and the headers included
Received: from mail1.comodogroup.com (HELO mcmail2.mcr.colo.comodo.net) (91.199.212.133)

As you said, the SPF record on comodo.com is
“v=spf1 mx include:psoft.od.ua include:blackberryv.comodo.com include:spf1.comodo.com include:spf2.comodo.com include:spf3.comodo.com include:spf4.comodo.com -all”

recursing into spf1.comodo.com I see an SPF of
“v=spf1 ip4:81.187.167.48/28 ip4:82.109.38.200/29 ip4:91.199.212.128/26 -all”

So checking the originating IP, I see that 91.199.212.133 is within the IP range given by the final element given in the SPF record for spf1.comodo.com (91.199.212.128/26).

Where do you see an error in our SPF config?

Regards
Robin Alden
Comodo

I have fixed the problem, it was on my end.

I am running qmail. The server that received the mail was forwarding it to my other server, which checked the SPF records again and rejected it (as my first server isn’t in your SPF list). I have no whitelisted my other server so it won’t be a problem anymore.

Can you resend my invoices?

Thanks!

-Dave