[opendmarc-users] troubleshooting an opendmarc 1.3.1 auth failure?

Juri Haberland juri at sapienti-sat.org
Wed May 11 04:41:32 PDT 2016


jasonsu at mail-central.com wrote:
> Ok, well I'm completely mystefied.  Checking with a DMARC-ed inbound mail from
> gmail, which DOES have a DMARC policy

> 	job 5j587m7ejWls8fh
> 	reporter mail.example.com
> 	received 1462892441
> 	ipaddr 127.0.0.1
> 	from gmail.com
> 	mfrom gmail.com
> 	dkim gmail.com 0
> 	spf -1
> 	pdomain gmail.com
> 	policy 15
> 	rua mailto:mailauth-reports at google.com
> 	pct 100
> 	adkim 114
> 	aspf 114
> 	p 110
> 	sp 0
> 	align_dkim 4
> 	align_spf 5
> 	action 2
>
> It looks like it's working, or doing something at least.
>
> Not sure what that "spf -1" means.

"spf -1" means "result undefined" - I'm not sure under what condition this one
is used, but as DKIM has a "0" (pass), DMARC passed for this mail.
The align_* values support that: 4 = aligned, 5 = unaligned (default value).

So, something with your SPF milter is problematic... maybe it was just the
TrustedAuthservIDs setting.

Juri





More information about the opendmarc-users mailing list