Tagged “dns”
26 articles
How to add DMARC, SPF and DKIM records on Azure DNS
An Azure DNS-specific walkthrough of publishing TXT and CNAME records for DMARC, SPF and DKIM, covering record sets, the @ apex, TXT chunking, the CLI add-record trap, Alias records and why delegation must be set at the registrar.
Read more
How to add DMARC, SPF and DKIM records on Cloudflare
A precise, Cloudflare-specific walkthrough of publishing TXT and CNAME records for DMARC, SPF and DKIM in the Cloudflare DNS editor, with the real gotchas: root versus host name, the orange-cloud proxy, automatic TXT chunking, CNAME flattening at the apex, TTL on Auto, and Email Routing conflicts.
Read more
How to add DMARC, SPF and DKIM records on DigitalOcean
A DigitalOcean-specific walkthrough for publishing DMARC, SPF and DKIM as TXT and CNAME records in the DigitalOcean DNS editor, covering the root-vs-host hostname convention, the no-auto-chunking DKIM trap, apex CNAME rules and TTL.
Read more
Automatic SPF flattening: staying under ten lookups without thinking about it
SPF has a hard limit baked into the specification: a receiving server is allowed to perform at most ten DNS lookups while evaluating your record.
Read more
How to add DMARC, SPF and DKIM records on Gandi
A precise, Gandi-specific walkthrough for publishing DMARC, SPF and DKIM in the Gandi LiveDNS editor, covering the root vs host name convention, TXT quoting and chunking, CNAME trailing dots and TTL.
Read more
1024-bit vs 2048-bit DKIM keys
2048-bit DKIM is now the baseline every major mailbox provider expects, but a 2048-bit public key will not fit in a single DNS TXT string. This guide covers the real security trade-offs, the 255-byte per-string DNS limit and how chunking works, the exact way each major DNS provider wants the value entered, and how to verify the published key actually parses before you rely on it.
Read more
How to add DMARC, SPF and DKIM records on GoDaddy
A precise, GoDaddy-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the GoDaddy DNS editor, covering root versus host names, TXT chunking, CNAME rules and TTL.
Read more
How to add DMARC, SPF and DKIM records on Google Cloud DNS
A precise, Google Cloud DNS-specific walkthrough for publishing TXT and CNAME records for DMARC, SPF and DKIM, including the gotchas that silently break authentication: public versus private managed zones, console versus gcloud TXT quoting, trailing dots on CNAME targets, 255-byte chunking and a TTL strategy for a safe staged rollout to p=reject.
Read more
SPF PermError: when your SPF silently stops working
SPF breaks quietly. Cross the 10 DNS-lookup limit and your record returns PermError, fails open, and stops protecting your domain. Here is how to count, fix and flatten it safely.
Read more
DKIM selectors explained
A DKIM selector is the label that points a receiver at the right public key. Here is what selectors are, how to read them out of a message and DNS, and how multiple selectors let you rotate keys without an outage and let many senders sign one domain.
Read more
How to add DMARC, SPF and DKIM records on IONOS
A precise, IONOS-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the IONOS DNS editor, covering the root-versus-host gotcha, TXT chunking, CNAME flattening, TTL and a safe sequence to p=reject.
Read more
How to add DMARC, SPF and DKIM records on Namecheap
A precise, Namecheap-specific walkthrough for adding DMARC, SPF and DKIM records in the Advanced DNS editor, covering the host-field gotchas, TXT chunking, CNAME targets, TTL and the safe path from p=none to p=reject.
Read more
How to add DMARC, SPF and DKIM records on OVH
A precise, OVH-specific walkthrough for adding SPF, DKIM and DMARC records in the OVH DNS zone editor, covering the apex naming rule, TXT chunking for long DKIM keys, CNAME trailing dots and TTL behaviour.
Read more
How to add DMARC, SPF and DKIM records on AWS Route 53
A precise, Route 53-specific walkthrough for publishing SPF, DKIM and DMARC: empty Record name versus host names, TXT quoting and 255-character chunking, why DKIM CNAMEs must never become Alias records, and TTL strategy for a safe staged path to p=reject.
Read more
How to add DMARC, SPF and DKIM records on Squarespace
A precise, Squarespace-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the Squarespace DNS editor, including the gotchas that actually break setups: the doubled-domain Host field, TXT chunking, CNAME-at-apex, SPF flattening and TTL.
Read more
How to add DMARC, SPF and DKIM records on Wix
A precise, Wix-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the Wix DNS editor, covering the real gotchas: relative host names, long-TXT chunking, CNAME targets without a trailing dot, the one-SPF-record rule and TTL during testing.
Read more
DNSSEC and email security: what it does and does not do
DNSSEC turns up in almost every conversation about hardening email, usually as a vague recommendation: "you should enable DNSSEC". The advice is rarely wrong, but it is almost never explained.
Read more
Automating DMARC, SPF and DKIM with the DMARC Engine API
Most teams start with email authentication as a one-off project: someone fixes the SPF record, publishes a DKIM key, sets a DMARC policy, and moves on.
Read more
How to enable DKIM in Google Workspace
A step-by-step guide to enabling DKIM for a Google Workspace domain: generating a 2048-bit key in the Admin console, publishing the public key as a DNS TXT record (including the 255-byte chunking that trips people up), verifying it is live, and turning on signing safely in the right order.
Read more
Publishing DMARC, SPF and DKIM on common DNS hosts
Exact steps to publish SPF, DMARC and DKIM on Cloudflare, GoDaddy, Namecheap and AWS Route 53, plus the two gotchas that break most setups: TXT chunking on long DKIM keys and CNAME coexistence at the apex.
Read more
The SPF 10-lookup limit, explained
SPF caps how much DNS work a receiver may do when evaluating your record. Go over the 10-lookup limit, or the separate void-lookup limit, and SPF returns a permerror that quietly stops helping your DMARC result. Here is how includes consume the budget, why exceeding it breaks SPF, and how to get safely back under the line.
Read more
DANE and TLSA records explained
DANE pins your mail server's certificate in DNSSEC-signed TLSA records so senders refuse to deliver over a downgraded or substituted TLS connection. Here is how TLSA records work, how DNSSEC anchors the trust, how DANE compares with MTA-STS, and which one fits your domain.
Read more
What is DKIM and how does it work?
DKIM attaches a cryptographic signature to every message you send, letting receivers verify with a public key in DNS that the mail really came from your domain and was not altered. Learn how signing and verification work step by step, how to read the headers and DNS record, and why a DKIM signature survives forwarding that breaks SPF outright.
Read more
What is MTA-STS and how does it work?
MTA-STS forces encrypted, authenticated delivery of your inbound mail. Learn how the _mta-sts DNS record and the HTTPS-hosted policy file work together, the difference between testing and enforce mode, and exactly how it stops TLS downgrade and interception attacks.
Read more
What is SPF and how does it work?
SPF lets you publish, in DNS, the list of servers allowed to send mail for your domain. Here is how the syntax works, what the all qualifier and each mechanism mean, what SPF actually authorises, the ten-lookup limit that catches everyone, and the spoofing gap that DMARC alignment closes.
Read more
What is TLS-RPT?
TLS-RPT (SMTP TLS Reporting) is a single safe-to-publish DNS record that gives you a daily, machine-readable summary of how other mail servers negotiated encryption with your inbound MX hosts. Learn what the record and its JSON reports contain, how to decode each failure type, and the exact publish-then-enforce workflow that pairs it with MTA-STS without risking an email outage.
Read more