3 ms·
If you have any domains that does not use email, it may be a good idea to set up some DNS records to prevent it being used. DNS SPF record: mydomain.io. TXT "v
by TheChaplain 2mo ago
If you have any domains that does not use email, it may be a good idea to set up some DNS records to prevent it being used.
DNS SPF record: mydomain.io. TXT "v=spf1 -all"
DNS DMARC: _dmarc.mydomain.io. TXT "v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s"
That ought to stop anyone trying to use your domains as source.
- newsoftheday 2mo agoI use postfix and the recipient_access file to control email to my domains which use little email, so the domains are able to process standard email: admin@example.com OK postmaster@example.com OK abuse@example.com OK webmaster@example.com OK hostmaster@example.com OK info@example.com OK example.com REJECT example.com
- teddyh 2mo agoAlso consider (using your example domain): *.mydomain.io. TXT "v=spf1 -all" to restrict SPF on all subdomains.
- auscompgeek 2mo agoSpecifying sp=reject in a DMARC policy would have a similar effect right?
- teddyh 2mo agoThe wildcard DNS SPF record is useful for mail receivers who won’t check DMARC, but will check SPF records. Also, the DMARC sp= setting defaults to the same as the p= setting (unless the DMARC record is itselt on a subdomain, in which case the sp= setting is ignored). So if you already have a strict p=reject setting, the sp= setting is useless.
- brightball 2mo agoYes! IMHO every registrar should be turning this on by default. Every DNS should do this by default until the owner explicitly turns on email sending. It would solve a lot of issues globally.
- mike-cardwell 2mo agoAlso, if your domain doesn't receive mail, set up a null mx record: @ IN MX 0 . https://datatracker.ietf.org/doc/rfc7505/ https://datatracker.ietf.org/doc/rfc7505/
- inigyou 2mo agoIsn't it default for domains without MX records, usually?