Hi there,
I'm running Exchange 2010 and my domain has both SPF and DMARC records setup.
https://dmarcian.com/spf-survey/clubaviva.ca
https://dmarcian.com/dmarc-inspector/clubaviva.ca
I'm monitoring the DMARC reports and external mail servers are rejecting messages claiming to be from us so I know the DMARC and SPF are working as they should.
Just today though I received an email purporting to be from admin@clubaviva.ca Unfortunately that email address doesn't exist and in fact the message was a phishing message. What really concerns me though is when I look in the message headers.
Received: from abts-tn-dynamic-074.16.164.122.airtelbroadband.in
(122.164.16.74) by remote.clubaviva.ca (192.168.1.10) with Microsoft SMTP
Server id 14.3.181.6; Wed, 23 Jul 2014 12:11:16 -0700
Received: from mail.clubaviva.ca (10.0.0.111) by clubaviva.ca (10.0.0.102)
with Microsoft SMTP Server (TLS) id M8EDJU6L; Thu, 24 Jul 2014 00:41:16 +0530
Received: from fax.clubaviva.ca (10.93.28.74) by smtp.clubaviva.ca (10.0.0.18)
with Microsoft SMTP Server id KT18XYH2; Thu, 24 Jul 2014 00:41:16 +0530
MIME-Version: 1.0
Date: Thu, 24 Jul 2014 00:41:16 +0530
To: <kevin@clubaviva.ca>
From: Administrator <admin@clubaviva.ca>
Reply-To: Administrator <admin@clubaviva.ca>
X-Mailer: Fax Mail
Subject: You received a voice mail
Message-ID: <MAEKZ1YFGRSPFW9PGEHOQI1E6QUQ.6862545821.0@clubaviva.ca>
x-xerox-mail-id: 7C6ZM5C50N0S966JHVPQSRU0R46Q
Content-Type: multipart/mixed;
boundary="------------04070300504030903090309"
Return-Path: NO-REPLY@clubaviva.ca
X-MS-Exchange-Organization-AuthSource: CASBS.clubaviva.local
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-PRD: clubaviva.ca
X-MS-Exchange-Organization-SenderIdResult: None
Received-SPF: None (CASBS.clubaviva.local: admin@clubaviva.ca does not
designate permitted sender hosts)
X-MS-Exchange-Organization-SCL: 0
X-MS-Exchange-Organization-PCL: 2
X-MS-Exchange-Organization-Antispam-Report: DV:3.3.13517.474;SID:SenderIDStatus None;OrigIP:122.164.16.74
For whatever reason, my own Exchange server cannot see the SPF records for my domain? I'm quite confused about this and I'm just wondering if anyone else has encountered this?
Thanks,
Kevin Morse