Howto: Installing SPF plugin for Postfix in Ubuntu Gutsy in 4 simple steps
Posted on September 8, 2007 by Chris @ 8:18 am

Just a quick ‘n’ simple howto on installing SPF tests in postfix on ubuntu:

  1. Get the policy plugin and perl modules
  2. sudo apt-get install postfix-policyd-spf-perl libmail-spf-perl libversion-perl libnetaddr-ip-perl

  3. sudo vim /etc/postfix/master.cf and insert the following at the bottom
  4. policy  unix  -       n       n       -       -       spawn
     user=nobody argv=/usr/bin/perl /usr/sbin/postfix-policyd-spf-perl
    
  5. sudo vim /etc/postfix/main.cf and insert “heck_policy_service unix:private/policy,” somewhere after the reject_unauth_destination or you’ll become a open-relay for anyon with a valid spf (think +). Mine looks like this:
  6. smtpd_recipient_restrictions = permit_mynetworks, check_client_access hash:/var/lib/pop-before-smtp/hosts, reject_unauth_destination, check_helo_access regexp:/etc/postfix/helo_checks, check_policy_service unix:private/policy, permit

  7. Then simply sudo /etc/init.d/postfix restart (and check your mail log in case you made a typo!)

That’s it!

Here is a citezns bank phish soft failing in the log:

Sep 8 08:45:51 localhost postfix/policy-spf[31433]: : Policy action=PREPEND Received-SPF: softfail (citizensbank.com: Sender is not authorized by default to use 'clientcare.refUD44983558.gps@citizensbank.com' in 'mfrom' identity, however domain is not currently prepared for false failures (mechanism '~all' matched)) receiver=localhost.localdomain; identity=mfrom; envelope-from="clientcare.refUD44983558.gps@citizensbank.com"; helo=190.Red-88-27-224.staticIP.rima-tde.net; client-ip=88.27.224.190

Now how can I convince the banks to use -all records?? ;)

/* */
Filed under: ~/
Comments:
This is a j.u.n.k.m.a.i.l. t.r.a.p. - please ignore. From bawg twap blogsnow.com Technorati Profile

No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URI

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)



cd /pub; more beer; play music; more crap_news

Main Menu
Home
  • Hardware Feed for all posts filed under Hardware
  • Knee Jerk Feed for all posts filed under Knee Jerk
  • News Feed for all posts filed under News
  • PhotoBlog Feed for all posts filed under PhotoBlog
  • Spam Feed for all posts filed under Spam
  • ~/ Feed for all posts filed under ~/

  • Search


    Syndication
    RSS 2.0
    Comments RSS 2.0
    Add to Google

    Copyright
    All content © 2004-2008 blog.iloaf.com

    Archives
    July 2008
    June 2008
    May 2008
    April 2008
    January 2008
    December 2007
    November 2007
    September 2007
    August 2007
    July 2007
    June 2007
    May 2007
    April 2007
    March 2007
    February 2007
    January 2007
    December 2006
    November 2006
    October 2006
    September 2006
    July 2006
    April 2006
    March 2006
    January 2006
    November 2005
    September 2005
    August 2005
    July 2005
    May 2005
    April 2005
    March 2005
    February 2005

    del.icio.us stuff
  • Data transfer rate calculator Megabits Gigabits per second Megabytes per minute units - sengpielaudio
  • Rip DVD's with VLC
  • remiq.net : (cat), (confidence), (disaster), (eagle), (lol), (motivator), (photo), (photoshop), (text)
  • Dear Mom or Dad | Found, Funny Notes, Sex Humor
  • dear mom.jpg (JPEG Image, 600x343 pixels)
  • Rich Wolski, "EUCALYPTUS - Elastic Utility Computing Architecture for Linking Your Programs To Useful Systems" - Velocity Conference on blip


  • µblog

    • Sneaky beer with Mr Outlaw before dinners cooked ;) - 2 hours ago
    • Getting dinner ready and catching up on time-shifted TV whilst the outlaws are on a road trip. Wife is having too much fun on the loaner R6! - 5 hours ago
    • Gotta love gif status bars : link ;) - 8 hours ago
    • @Scobleizer The twitter population desperately(?) want twitter to succeed. Community spirit is a powerful thing ;) SMS & ~IM is cool too. - 9 hours ago
    • @Scobleizer I bet Richter & co are already on the case ;) - 13 hours ago
    • Ferret racing was a hoot... I was so good at picking the looser!!! - 22 hours ago



    Recent Entries
    Firefox 3 - Is it really quicker?
    Ubuntu update improves network performance
    Mailchannels TrafficControl update
    UK doctors ripping off the ill
    Coolest advert of the spring
    Mailchannels first impressions & its feedback loop
    Wogan to quit over eurovision voting?
    MailChannels "free beer" edition
    Nine Inch Nails 100% free and DRM free album
    Bad blogger
    cottages4you (aka VRG) suck
    Stupid "Security" Questions. Get a clue Insurance companies.
    Bloody Banks! Phone line quality is worth paying for.
    Stop Motion Haircut
    eBay, Paypal and their SPF own goal!