<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPF Errors when Outbound Mails or DLP Security enabled in Email and Collaboration</title>
    <link>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-Errors-when-Outbound-Mails-or-DLP-Security-enabled/m-p/164718#M441</link>
    <description>&lt;P&gt;In general, we do not recommend adding an outgoing IP address to the sender's SPF record because we prefer not to be visible to the public like traditional gateways. Sometimes, we suggest on a case-by-case basis that tenants use DLP or Inline for outgoing emails and face frequent SPF issues.&lt;BR /&gt;&lt;BR /&gt;Here are some findings. In my experience, the results were different when I sent the same email to three different domain recipients and then sent it to outlook.com.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Gmail accepted the email, validated SPF as a pass, and detected no problem.&lt;/LI&gt;
&lt;LI data-private="redact" data-wt-guid="7a772e17-38c1-43fc-bda2-b6ec0c302fb9"&gt;Yahoo accepted the email, validated SPF as a pass, and detected no problem.&lt;/LI&gt;
&lt;LI data-private="redact" data-wt-guid="c69309e7-93c0-46d1-8b46-03871a49d6b4"&gt;Outlook accepted the email, validated SPF as a pass, and detected no problem.&lt;/LI&gt;
&lt;LI&gt;Checkpoint accepted the email but not validated and instead considered the existing failed SPF for IP "3.214.204.181".&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gmail email status and SPF validated with the last sender MTA IP “40.107.237.106”&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gmail email status.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18726iC5E4A96D0D93964C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gmail email status.png" alt="Gmail email status.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Gmail SPF status PASS with the last sender MTA IP “40.107.237.106”&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gmail SPF status PASS.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18727iEA0BDBF6B5C7256A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gmail SPF status PASS.png" alt="Gmail SPF status PASS.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Yahoo SPF status PASS with the last sender MTA IP “40.107.237.101”&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Yahoo SPF status PASS.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18728i66F7D2CF2A7429A4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Yahoo SPF status PASS.png" alt="Yahoo SPF status PASS.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Outlook SPF status PASS with the last sender MTA IP “52.100.173.235”&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Outlook SPF status PASS.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18729i6E247F5E983E54C4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Outlook SPF status PASS.png" alt="Outlook SPF status PASS.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Checkpoint SPF status FAIL and the last MTA IP was “40.107.237.105” but SPF failed for “3.214.204.181”&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Checkpoint SPF status FAIL.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18730i3BBE43A4A28C5C94/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Checkpoint SPF status FAIL.png" alt="Checkpoint SPF status FAIL.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Gmail recorded 2 “Received-SPF”, first from “3.214.204.181” (DLP/inline outbound IP) to protection.outlook.com and it failed but second from “40.107.237.106” (the last MTA) and google.com has validated as Pass.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gmail recorded.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18731i3867F39D814C7857/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gmail recorded.png" alt="Gmail recorded.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Yahoo recorded only one “Received-SPF”, from “40.107.237.101” (the last MTA) and yahoo.com has validated as Pass.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Yahoo recorded.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18732iD748EB8ADE22EACC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Yahoo recorded.png" alt="Yahoo recorded.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Outlook recorded 2 “Received-SPF”, first from “3.214.204.181” (DLP/inline outbound IP) to protection.outlook.com and it failed but second from “52.100.173.235” (the last MTA) and outlook.com has validated as Pass.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Outlook recorded.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18733iE8DE75BD95C9A052/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Outlook recorded.png" alt="Outlook recorded.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Checkpoint has recorded only one "Received-SPF", which is “3.214.204.181” (DLP/inline outbound IP) to protection.outlook.com, and it failed. Despite detecting Effective-Source-IP (the last MTA) as "40.107.237.105", it considered the existing SPF header Received-SPF. It is possible that here the SPF validation is being done using a different method.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Checkpoint has recorded.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18735i2933613DB76247B1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Checkpoint has recorded.png" alt="Checkpoint has recorded.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;There is one thing common between all of these scenarios, and it is “X-MS-Exchange-Authentication-Results” where “spf=fail (sender IP is 3.214.204.181) smtp.mailfrom=xxxxxpportlab.onmicrosoft.com, DKIM and DMARC" which is &lt;STRONG&gt;expected since email is being returned to MSFT (O365)&lt;/STRONG&gt; from xxxxxpportlab.onmicrosoft.com by IP 3.214.204.181. The results of email authentication checks for SPF, DKIM, and DMARC are recorded (stamped) in the Authentication-results message header in inbound messages.&lt;BR /&gt;&lt;BR /&gt;Additionally, Gmail, Yahoo, and Outlook (public domains) have checked SPF records for sender domains with the last MTA IP address. At the same time, Checkpoint considered existing SPF records and ignored validating SPF records for the previous IP address of the MTA. The recipient's MX gateway checks SPF records to ensure they are valid using various methods.&lt;BR /&gt;&lt;BR /&gt;As a result, it does not affect all DLP/Inline outbound emails, and we can consider advising tenants individually if it affects them.&amp;nbsp;The outbound IP addresses are available in HEC&amp;nbsp;Admin Guide, and can be added to the SPF records of affected tenants according to their tenants' data residency.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;If you have any tenants having issues with SPF, please log a ticket so we can investigate the matter and respond appropriately.&lt;/P&gt;</description>
    <pubDate>Sat, 10 Dec 2022 09:33:05 GMT</pubDate>
    <dc:creator>Hasnainkhan</dc:creator>
    <dc:date>2022-12-10T09:33:05Z</dc:date>
    <item>
      <title>SPF Errors when Outbound Mails or DLP Security enabled</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-Errors-when-Outbound-Mails-or-DLP-Security-enabled/m-p/163978#M434</link>
      <description>&lt;DIV class=""&gt;&lt;P&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt; Check Point Harmony E-Mail &amp;amp; Collaboration with O365&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Goal:&lt;/STRONG&gt; Adding more security to outbound mails&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&amp;nbsp;After enabling DLP or activating the checkbox "Inline (outgoing) mail under Advanced Options" all mails fail SPF checks on the mail receiver side.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 726px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18629iA3E633C369D731E6/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 698px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18630i7E25DD12E1739602/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 473px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18631i6BE83C848BC4953F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Therefore we opened a SR with TAC and received the following information about the Check Point mail servers that are used by Check Point for DLP:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;52.17.62.50&amp;nbsp;eu-dlp.cloud-sec-av.com&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;As the issue also occurs without DLP as described above, there are obviously more sender domains to check the validity for SPF records. We'd like to avoid trial and error tests.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is there an official documentation for this configuration or does someone have any experience to share on this topic?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thanks for any tips or ideas!&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5260"&gt;@Igor_Moskowitz&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5888"&gt;@Jonas_Reiter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Dec 2022 16:44:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-Errors-when-Outbound-Mails-or-DLP-Security-enabled/m-p/163978#M434</guid>
      <dc:creator>Christoph_Hornu</dc:creator>
      <dc:date>2022-12-02T16:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: SPF Errors when Outbound Mails or DLP Security enabled</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-Errors-when-Outbound-Mails-or-DLP-Security-enabled/m-p/164718#M441</link>
      <description>&lt;P&gt;In general, we do not recommend adding an outgoing IP address to the sender's SPF record because we prefer not to be visible to the public like traditional gateways. Sometimes, we suggest on a case-by-case basis that tenants use DLP or Inline for outgoing emails and face frequent SPF issues.&lt;BR /&gt;&lt;BR /&gt;Here are some findings. In my experience, the results were different when I sent the same email to three different domain recipients and then sent it to outlook.com.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Gmail accepted the email, validated SPF as a pass, and detected no problem.&lt;/LI&gt;
&lt;LI data-private="redact" data-wt-guid="7a772e17-38c1-43fc-bda2-b6ec0c302fb9"&gt;Yahoo accepted the email, validated SPF as a pass, and detected no problem.&lt;/LI&gt;
&lt;LI data-private="redact" data-wt-guid="c69309e7-93c0-46d1-8b46-03871a49d6b4"&gt;Outlook accepted the email, validated SPF as a pass, and detected no problem.&lt;/LI&gt;
&lt;LI&gt;Checkpoint accepted the email but not validated and instead considered the existing failed SPF for IP "3.214.204.181".&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gmail email status and SPF validated with the last sender MTA IP “40.107.237.106”&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gmail email status.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18726iC5E4A96D0D93964C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gmail email status.png" alt="Gmail email status.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Gmail SPF status PASS with the last sender MTA IP “40.107.237.106”&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gmail SPF status PASS.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18727iEA0BDBF6B5C7256A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gmail SPF status PASS.png" alt="Gmail SPF status PASS.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Yahoo SPF status PASS with the last sender MTA IP “40.107.237.101”&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Yahoo SPF status PASS.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18728i66F7D2CF2A7429A4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Yahoo SPF status PASS.png" alt="Yahoo SPF status PASS.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Outlook SPF status PASS with the last sender MTA IP “52.100.173.235”&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Outlook SPF status PASS.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18729i6E247F5E983E54C4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Outlook SPF status PASS.png" alt="Outlook SPF status PASS.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Checkpoint SPF status FAIL and the last MTA IP was “40.107.237.105” but SPF failed for “3.214.204.181”&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Checkpoint SPF status FAIL.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18730i3BBE43A4A28C5C94/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Checkpoint SPF status FAIL.png" alt="Checkpoint SPF status FAIL.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Gmail recorded 2 “Received-SPF”, first from “3.214.204.181” (DLP/inline outbound IP) to protection.outlook.com and it failed but second from “40.107.237.106” (the last MTA) and google.com has validated as Pass.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gmail recorded.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18731i3867F39D814C7857/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gmail recorded.png" alt="Gmail recorded.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Yahoo recorded only one “Received-SPF”, from “40.107.237.101” (the last MTA) and yahoo.com has validated as Pass.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Yahoo recorded.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18732iD748EB8ADE22EACC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Yahoo recorded.png" alt="Yahoo recorded.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Outlook recorded 2 “Received-SPF”, first from “3.214.204.181” (DLP/inline outbound IP) to protection.outlook.com and it failed but second from “52.100.173.235” (the last MTA) and outlook.com has validated as Pass.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Outlook recorded.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18733iE8DE75BD95C9A052/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Outlook recorded.png" alt="Outlook recorded.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Checkpoint has recorded only one "Received-SPF", which is “3.214.204.181” (DLP/inline outbound IP) to protection.outlook.com, and it failed. Despite detecting Effective-Source-IP (the last MTA) as "40.107.237.105", it considered the existing SPF header Received-SPF. It is possible that here the SPF validation is being done using a different method.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Checkpoint has recorded.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18735i2933613DB76247B1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Checkpoint has recorded.png" alt="Checkpoint has recorded.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;There is one thing common between all of these scenarios, and it is “X-MS-Exchange-Authentication-Results” where “spf=fail (sender IP is 3.214.204.181) smtp.mailfrom=xxxxxpportlab.onmicrosoft.com, DKIM and DMARC" which is &lt;STRONG&gt;expected since email is being returned to MSFT (O365)&lt;/STRONG&gt; from xxxxxpportlab.onmicrosoft.com by IP 3.214.204.181. The results of email authentication checks for SPF, DKIM, and DMARC are recorded (stamped) in the Authentication-results message header in inbound messages.&lt;BR /&gt;&lt;BR /&gt;Additionally, Gmail, Yahoo, and Outlook (public domains) have checked SPF records for sender domains with the last MTA IP address. At the same time, Checkpoint considered existing SPF records and ignored validating SPF records for the previous IP address of the MTA. The recipient's MX gateway checks SPF records to ensure they are valid using various methods.&lt;BR /&gt;&lt;BR /&gt;As a result, it does not affect all DLP/Inline outbound emails, and we can consider advising tenants individually if it affects them.&amp;nbsp;The outbound IP addresses are available in HEC&amp;nbsp;Admin Guide, and can be added to the SPF records of affected tenants according to their tenants' data residency.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;If you have any tenants having issues with SPF, please log a ticket so we can investigate the matter and respond appropriately.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2022 09:33:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-Errors-when-Outbound-Mails-or-DLP-Security-enabled/m-p/164718#M441</guid>
      <dc:creator>Hasnainkhan</dc:creator>
      <dc:date>2022-12-10T09:33:05Z</dc:date>
    </item>
  </channel>
</rss>

