SPF pointer usage for domains

Relaying pointers. SPF pointers are kept for being backwards compatible.

Primary Configuration

For most of the domains, those rows should be used:

@ IN SPF "v=spf1 include:_spf.tornevall.net -all"
@ IN TXT "v=spf1 include:_spf.tornevall.net -all"

This SPF limits relaying to our local servers. The former "~all" has been changed to "-all" to prevent softfails. If the sender is not the specified hosts defined by tornevall.net, you can safely reject the mail completely.

For tornevall.se and hosts that needs external relays like telia, etc (country zone is se)

@ IN SPF "v=spf1 include:_spf.tornevall.se -all"
@ IN TXT "v=spf1 include:_spf.tornevall.se -all"

This list of relays includes ISP-servers that may be required for sending mail outside our SMTP address range.
If you really need other relays, contact support@tornevall.net and tell. In that case, relays will be included at tornevall.se or similar. 

Ranges described

Divided into inclusions

_spf.tornevall.net IN TXT "v=spf1 include:_spfblockv4.tornevall.net include:_spfblockv6.tornevall.net include:_spfblockrelay.tornevall.net -all";


_spf.tornevall.se IN TXT "v=spf1 include:_spfblockv4.tornevall.net include:_spfblockv4.tornevall.net include:_spfblockrelay.tornevall.net include:_spfblocktelia.tornevall.net -all";

Categorized as

// Safe
_spfv4tblock IN TXT "v=spf1 ip4: ip4: ip4: ip4: ip4: ip4: ip4: -all"
_spfv6tblock IN TXT "v=spf1 ip6:2a01:299:a0::/48 ip6:2001:470:7ece::/48 -all"

// Safe
_spfblockrelay.tornevall.net IN TXT "v=spf1 ip4: ip6:2a01:298:f001::/48 a:webmail.tornevall.net a:smtp.tornevall.net a:tornevall.net a:i-s-vg-k-se-mailrelay1.tornevall.net -all"

// Unsafe
_spfblocktelia.tornevall.net IN TXT "v=spf1 ip4: ip4: include:_spf-a.telia.net include:_spf-b.telia.net include:_spf-c.telia.net include:_spf-2.telia.com -all"

// Deprecated unsafe
_spfblockteliaold IN TXT "v=spf1 ip4: ip4: ip4: a:v-smtpout2.han.skanova.net -all"