Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

SMTP using wrong IP - Causing SPF Softfail?

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 General ] >> Server Publishing >> SMTP using wrong IP - Causing SPF Softfail? Page: [1]
Login
Message << Older Topic   Newer Topic >>
SMTP using wrong IP - Causing SPF Softfail? - 18.May2007 5:51:15 AM   
bjblackmore

 

Posts: 80
Joined: 9.Aug.2005
Status: offline
Hi,
 
About a year ago I setup an SMPT relay on our ISA server, using the following article: http://www.isaserver.org/articles/2004smtprelayinoutisa.html
Everything seems to have been working fine since, however I just setup an SPF record in our external DNS, to try and stop some of the spoofing, and I noticed that the test emails I'm sending to hotmail are returning a softfail.
The SMTP service is running under IIS6 on the ISA server, with 2 IP address, one for internal relay, and one for external. Externally we have a range of 5 IPs, we use one for OWA, one for CWA, one for VPN, and the last for SMTP. So our range would be xx.xx.xx.1 - xx.xx.xx.5, with our SMTP server configured to use .5, this is the IP that I've setup in DNS as mail.ourdomain.com, which is added as an MX record, and SPF is setup to allow the MX record to send mail.
 
However, I've noticed that when I send a test to hotmail, the follwoing is in the header:
 
X-SID-Result: SoftFail
X-Message-Info: LsUYwwNt0FrW4AMsDonCQPn7R/UwInRZYjOy8HI2eZFHI01mD2YAW
Received: from mail.ourdomain.com ([xx.xx.xx.1]) by bay0-mc3-f23.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2668);
Fri, 18 May 2007 02:05:33 -0700

 
As you can see, mail is being received from mail.ourdomain.com on IP xx.xx.xx.1, not .5, which is what is configured in the SMTP service, and I think this is why its causing a SoftFail.
 
Does anyone know why mail is being received from the wrong IP, and how to get it on the correct IP? I've tried re-adding the IP & stopping/starting the SMTP service, but it didn't help!
 
Any help, much appreciated!
 
Ben
Post #: 1
RE: SMTP using wrong IP - Causing SPF Softfail? - 18.May2007 2:34:01 PM   
spouseele

 

Posts: 12782
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Ben,

when there is a NAT relationship between the Internal and External network, or ISA itself is the source of the traffic, than the outbound traffic will be sourced from the primary IP address assigned to the ISA external interface. This is by design and can't be changed in all current ISA server versions.

Thus, the solution (workaround if you like) is to make sure your MX records points to the primary IP address assigned to the ISA external interface (.1) or make sure the current IP address the MX record is pointing to (.5) becomes the primary IP address.

HTH,
Stefaan


(in reply to bjblackmore)
Post #: 2

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 General ] >> Server Publishing >> SMTP using wrong IP - Causing SPF Softfail? Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts