I should be on my way to Neerpelt, but I clearly am not (yet). I'll be leaving soon though, once I finish writing this entry.

A couple of minutes ago, I got my SPF records published for the domain, after some mailing back and forth with my webhost. They were professional and excellent as always, pointing out benefits and disadvantages but leaving the final decision up to me. After getting their informed opinion, I decided to go through with it, as there is little to lose for me.

SPF is not an anti spam tool, but rather an anti forgery tool. It should prevent unauthorized people from sending mail in your name, though much of that depends the checks done by the receiving party. If no one checks the validity of the SPF record, they don't benefit from the added layer. Even if checking, one can still accept, question (accepts but moves to a specific mailbox for instance), or refuse the mail, based on the outcome of the check.

It's a vicious circle, I'm well aware of that. If no one publishes SPF records, people will not rely on them to decide what's potentially legit or fake. If no one checks the records, why would you publish them? I went ahead and had them published for one domain so far. I'll now be monitoring if any problems arise - if not, more of my domains will have their SPF records published.

For the time being, I suggest you don't refuse mail that fails the SPF check on, especially since this is just a first test case. But please, do check if you can. Gmail, the mail service of google, for instance does check SPF records, but appears not to reject based on the outcome.

Note : right now most SPF checking will be done - if any is going on - by the mailservers of the company/ISP/organization you use. End users have little options to verify SPF records themselves as far as I know. If you know of any tools, feel free to leave a comment with explenation or an URL for me to check.

