Check SPF on outgoing mails

anoniempje

Member
Jun 10, 2020
11
0
21
32
Hi,

I was wondering if its possible to have PMG scan outgoing mails and check the SPF of its even allowed.
This because we see a lot of mail where the from address has changed or set by PHP and they are not even allowed to send mail from that given domain. I have been searching but i cant really find a good solution to his.
 
Hi,

PMG is a Proxy. Outgoing mails came from your internal Mailserver and normally incoming mails came across PMG to your internal Mailserver. SPF Records are for the public site. So they should point to the PMG if it is used for outgoing mails and not to your internal mailserver. So you have to check the config of your internal mailserver why it is allowed to spoof mail addresses. Normally you could lock to only send with addresses which belongs to the logged in user. Don't allow any php or other scripts to directly send from the mailserver without authetication. So I think it must be solved on your internal mailserver.
 
Hi,

While I do agree with you on that, disabling PHP-mail and forcing our users to use SMTP on their forms is simple a no-go on the current environment. The impact of making such change is simple to big.

I have installed a new env. to test stuff on and i notice that it does work there so I'll do some more digging to see what is going on on the prod env.

Thanks
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!