Showing results for 
Search instead for 
Did you mean: 
Level 9

SPF Record Evaluation


with MEG7, we noticed a strange behaviour when the system is evaluating the SPF record of senders.

We have incoming mails being dropped with the following error:


Application=smtp, Event='Sender Policy Framework (SPF) triggered', status='Reject and close the connection', From=<[sender]@[domainname].com>, source=[host].[domainname].com([ip.address]), msgid=xxxxx, convid=xxxxx

SPF Record:

  [domainname].com           20      IN      TXT     "v=spf1 include:spf.[domainname].com ?all"


According to what we saw in the SPF RFCs, a record with "?all" should be evaluated as "neutral" and always be accepted.

Something we missunderstood?

Thanks for any info. (We turned off SPF checking for the time being.......)



0 Kudos
2 Replies
Level 10

Re: SPF Record Evaluation

We have the same issue in EWS 5.6 patch3.

Check this out:

There exists a KB for this issue:

I strongly suggest opening a support case with McAfee, mentioning this KB.

On the support case we have opened, we were told PAtch2 for MEG7 (out in august) would solve this problem.

Message was edited by: malware-alerts on 12/07/12 11:07:39 CDT
0 Kudos
Level 9

Re: SPF Record Evaluation

Hi! just to let you know you may have encounter the SPF logic bomb validation 

Check this other related post

0 Kudos