1 |
On 12/06/2016 03:09 PM, Robin H. Johnson wrote: |
2 |
> On Mon, Dec 05, 2016 at 08:32:25PM +0000, Robin H. Johnson wrote: |
3 |
>> Hi, |
4 |
>> |
5 |
>> I'd like to remind all developers that there is an LDAP field to allow |
6 |
>> you to customize SPF entries for how you send email. |
7 |
>> |
8 |
>> If, for example, you wanted to strictly try to block people forging mail |
9 |
>> as you, and you send ONLY via your own mailservers, you can set SPF to |
10 |
>> '-all'. |
11 |
> A longer, easier to parse correctly explanation follows: |
12 |
> |
13 |
> 1. Are you sending ONLY via Gentoo mail servers, and want to block |
14 |
> forgery? |
15 |
> Set "gentooSPF: -all" |
16 |
> |
17 |
> 2. Are you using other servers as well, and want to block forgery? |
18 |
> Set "gentooSPF: include:myspf.example.com -all" |
19 |
> |
20 |
> 3. You don't have complete control over your sending environment (this |
21 |
> is the default). |
22 |
> Set "gentooSPF: ~all" |
23 |
> |
24 |
> The wiki page for developer email was updated prior to sending the |
25 |
> previous email, and I suggest reading it: |
26 |
> https://wiki.gentoo.org/wiki/Project:Infrastructure/Developer_E-Mail#To_permit_mail_from_GMail.2C_Gentoo.2C_and_nowhere_else |
27 |
> |
28 |
Thanks for setting this up for us. I may decide to go to '-all' when I |
29 |
decide on a "Gentoo-dev-only" machine setup to add a hint of security to |
30 |
things. :) |
31 |
|
32 |
-- |
33 |
Daniel Campbell - Gentoo Developer |
34 |
OpenPGP Key: 0x1EA055D6 @ hkp://keys.gnupg.net |
35 |
fpr: AE03 9064 AE00 053C 270C 1DE4 6F7A 9091 1EA0 55D6 |