Saturday, April 7, 2018

Once SPF is correctly setup is it normal for spoofed email to go to spam folder or should Gmail deleted them?



In the spam folder of Gmail can be found illegitimate spam emails apparently sent from my own domain email address but from an origin not allowed by SPF. The domain is on G Suite emails. SPF is allegedly correctly setup as "v=spf1 include:_spf.google.com ~all". What is the expected behavior of Gmail in that case. Should it delete those emails so they do not even reach the spam folder or should they appear in spam.


Answer



Given the ease of messing up an SPF record, Gmail appears to consider a failing SPF check as a major factor for the spam score of an email, but it's possible for it to still wind up in the inbox.




To my knowledge, Gmail will not just silently delete an email by default.



If you're in a Google Apps install, there may be rules the administrator put in place. This doc indicates a DMARC record may be used to have SPF-fail email deleted.


No comments:

Post a Comment

linux - How to SSH to ec2 instance in VPC private subnet via NAT server

I have created a VPC in aws with a public subnet and a private subnet. The private subnet does not have direct access to external network. S...