McAfee SMEFCE-AI-DA Administration Guide - Page 83

Enforced SPF, Important SPF information:

Page 83 highlights

Email Protection Administrator Guide Email Authentication NOTE: More Options • Upload Enforced TLS List (appends to existing list): To Upload a file with a predefined list, click the Browse button. After you select the file and it's path appears in the text field, click the Upload button. The contents are added to the Add Domain box above. • Download Enforced TLS List (be sure to save changes first): To Download a domain list in a csv file, click the Download button, select the list you wish to download and click Save. 8 Subscribe to Default TLS List By checking the subscription to the TLS default list you will be adding the appropriate Inbound/Outbound Default domain policy to your customized Enforced TLS domain list. The default list can be viewed by clicking the corresponding Inbound/Outbound Default selection under the Policies tab. This option is only available in custom (non-default) policy sets. If the default list changes, your subscription to the default is updated to reflect those changes. Save 9 Click the Save button to save your information. Download To Download a domain list in a csv file, click the Download button, select the list you wish to download and click Save. Enforced SPF Sender Policy Framework (SPF) can be used by email recipients to determine if the messages they receive were sent from someone authorized by the domain owner, which can help detect spoofing. SPF only works when domain owners implement and maintain it voluntarily. To implement SPF, domain owners must create special DNS entries which list the IP addresses that are authorized to send email from their domain. Email recipients must compare an email's source IP address to the IP address in the domain owner's DNS SPF records. If they match, it is reasonable to assume that the message was sent by the domain owner or an authorized third party. Important SPF information: • SPF implementation is voluntary and many domain owners have not implemented DNS SPF records, including many well-known commercially used domains. • Even those that have implemented SPF might have outdated or inaccurate records, resulting in false positives. The only way to resolve this is to contact the domain owner and ask them to correct the issue. November 2012 Proprietary: Not for use or disclosure outside McAfee without written permission 75

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168

Email Protection Administrator Guide
Email Authentication
November 2012
Proprietary:
Not for use or disclosure outside McAfee without written permission
75
More Options
Upload Enforced TLS List (appends to existing list): To Upload a file with a
predefined list, click the Browse button. After you select the file and it's path appears
in the text field, click the Upload button. The contents are added to the Add Domain
box above.
Download Enforced TLS List (be sure to save changes first): To Download a domain
list in a csv file, click the Download button, select the list you wish to download and
click Save.
8
Subscribe to Default TLS List By checking the subscription to the TLS default list you
will be adding the appropriate Inbound/Outbound Default domain policy to your
customized Enforced TLS domain list. The default list can be viewed by clicking the
corresponding Inbound/Outbound Default selection under the Policies tab. This option
is only available in custom (non-default) policy sets.
NOTE:
If the default list changes, your subscription to the default is updated to reflect
those changes.
Save
9
Click the Save button to save your information.
Download
To Download a domain list in a csv file, click the
Download
button, select the list you
wish to download and click Save.
Enforced SPF
Sender Policy Framework (SPF) can be used by email recipients to determine if the
messages they receive were sent from someone authorized by the domain owner, which
can help detect spoofing. SPF only works when domain owners implement and maintain it
voluntarily.
To implement SPF, domain owners must create special DNS entries which list the IP
addresses that are authorized to send email from their domain. Email recipients must
compare an email's source IP address to the IP address in the domain owner's DNS SPF
records. If they match, it is reasonable to assume that the message was sent by the domain
owner or an authorized third party.
Important SPF information:
SPF implementation is voluntary and many domain owners have not implemented
DNS SPF records, including many well-known commercially used domains.
Even those that have implemented SPF might have outdated or inaccurate records,
resulting in false positives. The only way to resolve this is to contact the domain
owner and ask them to correct the issue.