Mailbox forgery and SPF Protection
SPF is a type of DNS record proposed to prevent spam. It is a type of TXT record that is used to register all IP addresses owned by a domain name for outgoing mail. There is a mailbox forgery vulnerability due to lack.
The SPF record can prevent others from falsifying to send emails. when the SPF record of the domain name is defined, the recipient of the email will determine whether the connected IP address is included in the SPF record according to the SPF record. If so, it is considered to be a correct email, otherwise it is considered to be a fake email. The impact on the interconnection and interworking is mainly manifested in that the mail receiver needs spf record detection, if not, it is possible not to receive mail.
Test method:
Nslookup-type=txt *. Com
The content of a mailbox forgery vulnerability:
C:\ Users\ Administrator > nslookup-type=txt bjca.com.cn
Server: public1.114dns.com
Address: 114.114.114.114
Bjca.com.cn
Primary name server = dns1.hichina.com
Responsible mail addr = hostmaster.hichina.com
Serial = 1
Refresh = 3600 (1 hour)
Retry = 1200 (20 mins)
Expire = 3600 (1 hour)
Default TTL = 600 (10 mins)
A situation in which there are no vulnerabilities:
C:\ Users\ Administrator > nslookup-type=txt * * .com
Server: public1.114dns.com
Address: 114.114.114.114
Non-authoritative response:
Bjca.org.cn text =
"v=spf1 include:spf.capmail.cn-all"