Account for email settings for domains that are not used to send emails
Hi, Some domains are not used to send emails, but still require the TXT and MX settings to be done in order to signal that [this] domain is not used for email at all. Kindly adjust your filters so that it accounts for this kind of domain settings. For example: An unused domain without email service requires specific DNS records to inform global mail servers that **no mail is sent or received** from it. This prevents attackers from spoofing your domain and stops unsolicited incoming email attempts. The exact records to add to your DNS provider's control panel are listed below. Replace `example.com` with your actual domain name. | Record Type | Host / Name | Value / Data | Description | | --- | --- | --- | --- | | **MX** | `@` | `0 .` | **Null MX:** Indicates the domain accepts no incoming mail. | | **TXT** | `@` | `v=spf1 -all` | **Null SPF:** Disallows all IP addresses from sending mail. | | **TXT** | `_dmarc` | `v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s;` | **Reject DMARC:** Tells receiving servers to reject spoofed emails. | | **TXT** | `*._domainkey` | `v=DKIM1; p=` | **Revoked DKIM:** Revokes all selectors to prevent signing. | --- ### Step-by-Step Instructions 1. **Add the Null MX Record:** Blocks incoming mail. Create an `MX` record with the Host set to `@` (or leave blank depending on your DNS host), set the Priority to `0`, and set the Value/Target to a single dot `.`. *Note: If your DNS editor requires a domain name for the MX host, enter `.` or leave it blank as permitted.* 2. **Add the Null SPF TXT Record:** Blocks outgoing mail authorization. Create a `TXT` record at the domain root `@`. Set the text value to `v=spf1 -all`. This declares that zero IP addresses are authorized to send mail on behalf of this domain. 3. **Add the Enforced DMARC TXT Record:** Instructs receiving servers to drop unauthorized mail. Create a `TXT` record with the Host set to `_dmarc`. Enter `v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s;` in the value field. This instructs recipient servers to reject any email that fails SPF or DKIM alignment. 4. **Add the Wildcard Revoked DKIM TXT Record:** Disables all DKIM selectors. Create a `TXT` record with the Host set to `*._domainkey`. Enter `v=DKIM1; p=` as the value. The empty public key parameter (`p=`) explicitly tells mail verifiers that any DKIM key for the domain is permanently revoked.
1 comment
Eduard PANTAZIOwner4 weeks ago
Hey Marius! Thank you for pointing this out. I'll work on this. Have a nice day!
Add a comment
No account needed. Your email stays private.
