@Jerry@hear-me.social also good idea while you’re in there to make sure you don’t have any old records pointing to servers you don’t own anymore.
Cybersecurity
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Rules
Community Rules
- Be kind
- Limit promotional activities
- Non-cybersecurity posts should be redirected to other communities within infosec.pub.
@Jerry@hear-me.social thank you for this post!
I've set up email servers using iRedMail and mailcow successfully with dmarc, etc., but this post really tied it all together for me.
now i have some dns to ... improve
@Jerry@hear-me.social
#email
If it helps anyone as an example of a domain w/o email, I have a domain 'hack-char.dev' that has those records configured. Never knew about the null mx, and will put one in today.
As a side note, I've seen someone try to spoof a different domain of mine and for some reason gmail sends a bounce to my domain, without rua set. I was wondering if it was an attempt to get a phish through in a bounce, but I don't see how that would be successful.
@Jerry@hear-me.social great advice. One question: does this config protect also subdomains?
@esplovago@mastodon.uno
Yep.
If you want to have different rules for subdomains, then the records get much more complicated. but "v=spf1 -all" pertains to the domain and subdomains.
@Jerry@hear-me.social Interesting. I own two domains (one I plan to use, one I use to connect to things remotely) and maybe I should set this up.