Most automatic Out of Office (OOO) or Out of Facility (OOF) messages will fail SPF-DMARC due to a null MailFrom.
Out of Office notification is commonly sent from a null sender as the Env Sender (RFC5321.MailFrom) and the users mail address as a Body sender (RFC5322.From). When Symantec delivers mails to recipients, HELO/EHLO identity is Symantecs host name, which is used as the Env Sender in SPF/DMARC authentication instead of a null sender.
Example:
Env Sender (RFC5321.MailFrom) |
<> |
Body sender (RFC5322.From) |
user@yourdomain.com |
HELO/EHLO identity |
mailx.bemtann.messagelabs.com |
The reason for DMARC failure is SPF alignment check; The Env Sender (null) and the Body Sender (yourdomain.com) do not match. The DKIM signature, which is an alternative way to verify the authenticity of the message, is not in the mail header.
Comments
0 comments
Please sign in to leave a comment.