3 ms·
What about only explicitly allowing domains that have DKIM enabled? Having that form of validation should help since DKIM was made to specifically stop email s
by intimatica 10y ago
What about only explicitly allowing domains that have DKIM enabled?
Having that form of validation should help since DKIM was made to specifically stop email spoofing; and anyone serious about implementing Portier would understand that need.
Outlook/Gmail etc aren't likely to be flagged by ESP's for the most part as those have reputation and rudimentary spoofing protection, at least more than a@a.com anyway.
Persons using custom domains are usually the admins of those domains, and Office 365/GApps/Registrars etc. provide simple ways to enable DKIM.
- intimatica 10y agoEDIT: Forgot to mention SPF records (actually easier to add to DNS than DKIM, sorry), and saw someone mentioned TXT records too; basically anything that can prove ownership of the domain for non-free addresses.
- jlgaddis 10y agoIn response to your other (dead) comment, "SPF" records actually are TXT records. In the past, there was an SPF RR type but that's been deprecated.