3 ms·
It depends. I've seen some servers with a DMARC policy which fails when SPF fails. DKIM completely supersedes SPF, hence my recommendation to just skip SPF.
by emersion 5y ago
It depends. I've seen some servers with a DMARC policy which fails when SPF fails.
DKIM completely supersedes SPF, hence my recommendation to just skip SPF.
- brightball 5y agoIt does, but it’s more involved to setup so depending on how many different sources your domain is using you may not be able to use DKIM everywhere. Additionally, DKIM keys need to be rotated periodically just like SSL. Many services like Sendgrid or ProtonMail will handle this for you now by setting up multiple CNAME records so they can rotate the keys for you, but it only works with that sender. SPF helps to address the gaps. I totally agree that strict DMARC policy plus DKIM should be enough though.
- remram 5y agoYou're far from your original claim that "SPF always breaks mailing-list". You are now at "there is a way to configure DMARC that breaks mailing-lists".