SPF infusionmail.com IPs?

I’ve added infusionmail.com to my spf txt record, but keep getting dmarc warnings for IPs that resolve to subdomains for infusionmail.com. So far they’ve been in the 208.76.24.* range, but in documentation https://classic-infusionsoft.knowledgeowl.com/help/configure-your-spf-records the actual IP range isn’t listed.

Is this documented somewhere?

Here is the article: https://classic-infusionsoft.knowledgeowl.com/help/infusionsoft-email-ip-range

Here is the direct link to the lookup: https://mxtoolbox.com/SuperTool.aspx?action=spf%3Ainfusionmail.com&run=networktools

1 Like

Thanks, exactly what we needed!

Cheers!

We keep getting DMARC notices with SPF failures from various postmasters for individual Infusionsoft IP addresses that fall within the ranges set in our spf record.

For instance the source_ip 35.227.130.43 will fail even though it falls within 35.227.130.0/24 noted in the spf record. I’ve verified our spf record multiple times. Any gotchas when providing ip ranges in an SPF record?

Here is our SPF record:
v=spf1 ip4:35.227.130.0/24 ip4:64.98.36.17 ip4:64.98.42.0/24 ip4:70.166.189.64/29 ip4:70.166.203.176/28 ip4:104.16.42.4 ip4:104.16.43.4 ip4:176.58.123.242 ip4:208.76.24.0/22 ip4:216.40.42.4 ip4:216.40.42.17 ip4:216.40.44.0/24 ~all

Any ideas on why specific IPs would fail SPF that are within your IP range?

Hey, @Ian_F_Hood. I talked to Support they said not to list the IPs in the spf record and to just use: v=spf1 mx include:infusionmail.com ~all

Here is the technical explanation from one of Sys Admins:

they don’t need to add our IPs to SPF anyway
we use our own domain as the envelope sender
"mailer@infusionmail.com"
so SPF gets checked against infusionmail.com
which, as it happens, lists all of the IP ranges we send from

also they already had our ranges added with these two
ip4:208.76.24.0/22 ip4:35.227.130.0/24
which I see are in the record you pasted

@martinc we originally were using ’ mx include:infusionmail.com ~all’ and were getting failures for individual ips in your range. This is why I tried listing all the IP ranges.

@martinc we originally were using ’ mx include:infusionmail.com ~all ’ and were getting failures for individual ips in your range. This is why I tried listing all the IP ranges. If I switch back to the record recommended by the sys admins, how can we go about reporting ips that fail SPF?

Hi, @Ian_F_Hood. You can post them here or private message me or @David_Carriger, the Sys Admin. We would need the spf record you were using at the time and a mail header that shows a failure for a particular IP.

Thanks, I will make the changes. Appreciate the help!

1 Like