We keep getting DMARC notices with SPF failures from various postmasters for individual Infusionsoft IP addresses that fall within the ranges set in our spf record.
For instance the source_ip 35.227.130.43 will fail even though it falls within 35.227.130.0/24 noted in the spf record. I’ve verified our spf record multiple times. Any gotchas when providing ip ranges in an SPF record?
Hey, @Ian_F_Hood. I talked to Support they said not to list the IPs in the spf record and to just use: v=spf1 mx include:infusionmail.com ~all
Here is the technical explanation from one of Sys Admins:
they don’t need to add our IPs to SPF anyway
we use our own domain as the envelope sender
“mailer@infusionmail.com”
so SPF gets checked against infusionmail.com
which, as it happens, lists all of the IP ranges we send from
also they already had our ranges added with these two
ip4:208.76.24.0/22 ip4:35.227.130.0/24
which I see are in the record you pasted
@martinc we originally were using ’ mx include:infusionmail.com ~all’ and were getting failures for individual ips in your range. This is why I tried listing all the IP ranges.
@martinc we originally were using ’ mx include:infusionmail.com ~all ’ and were getting failures for individual ips in your range. This is why I tried listing all the IP ranges. If I switch back to the record recommended by the sys admins, how can we go about reporting ips that fail SPF?
Hi, @Ian_F_Hood. You can post them here or private message me or @David_Carriger, the Sys Admin. We would need the spf record you were using at the time and a mail header that shows a failure for a particular IP.