Email Authentication (SPF)
By Daniel Miessler on February 11th, 2008: Tagged as Email | Information Security
Got a wicked PayPal spam message today. Looked totally legit.

Here are the headers:

So SPF caught it but it failed “soft”. At what point do we as mail server admins (Google in this case) start dropping these emails instead of letting them through?
Or, to put it another way, what part of an official email from PayPal coming from mail.royalimaging.net (64.2.112.131.ptr.us.xo.net [64.2.112.131]) doesn’t make you want to drop it?
grrr.