Conversation
The Mimecast MxMatch only recognised the two-letter *.mimecast.com
hostnames, so three documented regions were never identified by the
domain analyser:
- South Africa uses za-smtp-inbound-N.mimecast.co.za (different TLD).
- The US (B) region uses a three-letter prefix (usb-), which the
[a-z]{2} class mis-captured as 'sb'.
- Offshore (Jersey) uses *.mimecast-offshore.com.
Broaden the prefix to 2-3 chars, anchor the match, and accept the
.co.za TLD; the za prefix still resolves the SPF include to
za._netblocks.mimecast.com, which is the include those domains
publish. Add a separate Mimecast Offshore provider for
*.mimecast-offshore.com with an empty SpfInclude, because that
region's netblock host is not publicly documented and every
candidate resolves NXDOMAIN - leaving it empty skips SPF-include
validation rather than asserting a wrong expected include.
JohnDuprey
approved these changes
Aug 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Mimecast MxMatch only recognised the two-letter *.mimecast.com hostnames, so three documented regions were never identified by the domain analyser:
Broaden the prefix to 2-3 chars, anchor the match, and accept the .co.za TLD; the za prefix still resolves the SPF include to za._netblocks.mimecast.com, which is the include those domains publish. Add a separate Mimecast Offshore provider for *.mimecast-offshore.com with an empty SpfInclude, because that region's netblock host is not publicly documented and every candidate resolves NXDOMAIN - leaving it empty skips SPF-include validation rather than asserting a wrong expected include.