| ▲ | TheChaplain 5 hours ago | |
If you have any domains that does not use email, it may be a good idea to set up some DNS records to prevent it being used. DNS SPF record: mydomain.io. TXT "v=spf1 -all" DNS DMARC: _dmarc.mydomain.io. TXT "v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s" That ought to stop anyone trying to use your domains as source. | ||
| ▲ | brightball 3 hours ago | parent | next [-] | |
Yes! IMHO every registrar should be turning this on by default. Every DNS should do this by default until the owner explicitly turns on email sending. It would solve a lot of issues globally. | ||
| ▲ | teddyh 4 hours ago | parent | prev | next [-] | |
Also consider (using your example domain):
to restrict SPF on all subdomains. | ||
| ▲ | newsoftheday 4 hours ago | parent | prev [-] | |
I use postfix and the recipient_access file to control email to my domains which use little email, so the domains are able to process standard email: admin@example.com OK postmaster@example.com OK abuse@example.com OK webmaster@example.com OK hostmaster@example.com OK info@example.com OK example.com REJECT example.com | ||