All feedback

Account for email settings for domains that are not used to send emails

ImprovementDoneMarius C ·

Hi, Some domains are not used to send emails, but still require the TXT and MX settings to be done in order to signal that [this] domain is not used for email at all. Kindly adjust your filters so that it accounts for this kind of domain settings. For example: An unused domain without email service requires specific DNS records to inform global mail servers that **no mail is sent or received** from it. This prevents attackers from spoofing your domain and stops unsolicited incoming email attempts. The exact records to add to your DNS provider's control panel are listed below. Replace `example.com` with your actual domain name. | Record Type | Host / Name | Value / Data | Description | | --- | --- | --- | --- | | **MX** | `@` | `0 .` | **Null MX:** Indicates the domain accepts no incoming mail. | | **TXT** | `@` | `v=spf1 -all` | **Null SPF:** Disallows all IP addresses from sending mail. | | **TXT** | `_dmarc` | `v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s;` | **Reject DMARC:** Tells receiving servers to reject spoofed emails. | | **TXT** | `*._domainkey` | `v=DKIM1; p=` | **Revoked DKIM:** Revokes all selectors to prevent signing. | --- ### Step-by-Step Instructions 1. **Add the Null MX Record:** Blocks incoming mail. Create an `MX` record with the Host set to `@` (or leave blank depending on your DNS host), set the Priority to `0`, and set the Value/Target to a single dot `.`. *Note: If your DNS editor requires a domain name for the MX host, enter `.` or leave it blank as permitted.* 2. **Add the Null SPF TXT Record:** Blocks outgoing mail authorization. Create a `TXT` record at the domain root `@`. Set the text value to `v=spf1 -all`. This declares that zero IP addresses are authorized to send mail on behalf of this domain. 3. **Add the Enforced DMARC TXT Record:** Instructs receiving servers to drop unauthorized mail. Create a `TXT` record with the Host set to `_dmarc`. Enter `v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s;` in the value field. This instructs recipient servers to reject any email that fails SPF or DKIM alignment. 4. **Add the Wildcard Revoked DKIM TXT Record:** Disables all DKIM selectors. Create a `TXT` record with the Host set to `*._domainkey`. Enter `v=DKIM1; p=` as the value. The empty public key parameter (`p=`) explicitly tells mail verifiers that any DKIM key for the domain is permanently revoked.

1 comment

  • Eduard PANTAZIOwner4 weeks ago

    Hey Marius! Thank you for pointing this out. I'll work on this. Have a nice day!

Add a comment

No account needed. Your email stays private.