with MEG7, we noticed a strange behaviour when the system is evaluating the SPF record of senders.
We have incoming mails being dropped with the following error:
Application=smtp, Event='Sender Policy Framework (SPF) triggered', status='Reject and close the connection', From=<[sender]@[domainname].com>, source=[host].[domainname].com([ip.address]), msgid=xxxxx, convid=xxxxx
[domainname].com 20 IN TXT "v=spf1 include:spf.[domainname].com ?all"
According to what we saw in the SPF RFCs, a record with "?all" should be evaluated as "neutral" and always be accepted.
Something we missunderstood?
Thanks for any info. (We turned off SPF checking for the time being.......)
We have the same issue in EWS 5.6 patch3.
Check this out:
There exists a KB for this issue: https://kc.mcafee.com/corporate/index?page=content&id=KB75047
I strongly suggest opening a support case with McAfee, mentioning this KB.
On the support case we have opened, we were told PAtch2 for MEG7 (out in august) would solve this problem.Message was edited by: malware-alerts on 12/07/12 11:07:39 CDT