Bug 11902 - set Message-ID domain to ipfire.org
Summary: set Message-ID domain to ipfire.org
Status: CLOSED ERRATA
Alias: None
Product: Infrastructure
Classification: Unclassified
Component: Mail & Mailing Lists (show other bugs)
Version: unspecified
Hardware: all All
: - Unknown - Minor Usability
Assignee: Peter Müller
QA Contact: Peter Müller
URL:
Keywords:
Depends on:
Blocks: DMARCREJECT
  Show dependency treegraph
 
Reported: 2018-10-14 06:05 UTC by Peter Müller
Modified: 2018-10-17 17:00 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Peter Müller 2018-10-14 06:05:27 UTC
The Message-ID domain is used for SPF lookups. In case an internal systems sends messages with MID = <[...]@hostname.i.ipfire.org> , hostname.i.ipfire.org is used for SPF lookups, causing some DMARC trouble.

We should rewrite these IDs as soon as possible (Postfix configuration on each host) to make sure we stay DMARC-compliant.
Comment 1 Michael Tremer 2018-10-15 20:31:50 UTC
I am not really a fan of rewriting IDs, because rewriting an ID just feels
wrong.

I also do not see the Message-Id needing to be conforming to any guidelines.
That's not in the original RFC.

However, because I do not have a better solution, just go ahead and have this
rewritten on the individual VMs. Be aware that those servers might need to send
email from another domain than just ipfire.org.
Comment 2 Peter Müller 2018-10-16 18:59:39 UTC
Changed for *.i.ipfire.org (header_checks on mail01.ipfire.org). Other domains are not affected.

However, stumbling across FORGED_SENDER and R_SPF_NA symbols in rspamd output for monitoring mails, I am not sure if this solves the entire problem.
Comment 3 Peter Müller 2018-10-17 16:55:27 UTC
Rewriting Message-IDs is not requried for staying SPF compliant.

After some debugging, it turned out that mails from monitoring01.i.ipfire.org were sent with the envelope sender <icinga@monitoring01.i.ipfire.org>, causing both MX and SPF failures and thus adding some points to the spam score.

We _must_ make sure MIME and envelope sender are equal to each other and point to @ipfire.org (or any other domain with at least a valid MX record).

I reverted all changes made because of this ticket.