683
Field descriptions
Assets field descriptions
DNS TXT Record Properties—General tab
DNS TXT resource records prevent spam or email forgery by informing an email server of verifiable
sender IP addresses. A domain publishes the criteria for legitimate mail sent by it in sender policy
framework (SPF) records served by DNS. SPF records hold information about the servers that are
allowed to send mail from that domain. SMTP receivers can query the sender domain to find out the
list of allowed servers. If the mail is received from a server that is not listed, it is regarded as spam. Use
only one SPF record for each domain.
to help you with the correct syntax for your TXT record.
When specifying the legitimate mail senders for the domain, you should consider what a receiver sees
as the sender for the domain protected by security gateway, such as in the following instances:
■
If you have only a rule allowing traffic from a mail server in an inside network to outside, the
traffic will have security gateway's outside interface address as the source address. In this case, the
SPF record should point to the security gateway’s outside IP address.
This may be not the case if there is an:
■
Address transform, allowing client to see the server’s actual IP address (Use original source
address, if selected). The SPF record should resolve to the actual mail server address.
■
Address transform with a NAT pool. In this case, the SPF record should resolve to the address
from the NAT pool that is assigned.
■
If you have a cluster, to get failover, use the VIP address for sending and receiving SMTP server
addresses, and have service redirects point to the actual servers.
Note:
The security gateway does not use SPF in its antispam protection methods.
Associated tasks
The task that you can perform with this tab is:
■
“Help to block spam or email forgery by configuring a DNS TXT record”
Table D-136
DNS TXT Record Properties—General tab
Field
Description
Enable
Indicates whether this option is enabled.
This option is checked by default.
Domain name
A unique name for the DNS TXT record.
The maximum length is 256 characters.
Allowed characters are a-z, A-Z, numerals, periods (.), and dashes (-).
Do not include spaces in the name. The characters @,!,#,$,%,^,&,*,<,>, _ and other reserved
characters are also invalid.
For example, symantecs.com.
Accessibility
The drop-down list displays the following:
■
Private
Enables the TXT record for the inside interface.
■
Public
Enables the TXT record for the outside interface.
IP address
Corresponding IP address for the domain address that you typed in the Host name text box.
This field is optional.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...