SPF failure due to large DNS TXT response size in Messaging Gateway
search cancel

SPF failure due to large DNS TXT response size in Messaging Gateway

book

Article ID: 446452

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

Sender Policy Framework (SPF) validation fails for specific domains, resulting in emails being quarantined or rejected. This occurs when the number of DNS TXT records for the domain is too large for standard UDP resolution.

Environment

Version: 10.9.0 - 10.9.2

Cause

The SERVFAIL return is caused by a built-in security safeguard. The DNS name resolution service enforces a default limit of 100 records per type per domain name (RRset limit).

Resolution

The issue will be addressed in Messaging Gateway version 10.9.3