How to set up SPF, DKIM, and DMARC for your sending domain
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
How to set up SPF, DKIM, and DMARC for your sending domain
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
comrade1234 · · focus · HN ↗
adiabatichottub · · focus · HN ↗
marcus9999 · · focus · HN ↗
[dead]
thayne · · focus · HN ↗
adiabatichottub · · focus · HN ↗
edelbitter · · focus · HN ↗
adiabatichottub · · focus · HN ↗
edelbitter · · focus · HN ↗
2000UltraDeluxe · · focus · HN ↗
zh3 · · focus · HN ↗
Fire up Claude, give it an account with sudo, let it loose. Not long after, emails from $PERSONALDOMAIN are making it through to my gmail and outlook accounts.
buredoranna · · focus · HN ↗
I'd like to add the following, which I continually reference and has led to repeatable success:
<a href="https://www.linuxbabe.com/mail-server/setting-up-dkim-and-spf" rel="nofollow">https://www.linuxbabe.com/mail-server/setting-up-dkim-and-sp...
And as far as confirming it works, I continually rely on sending to a gmail address. Under the three dots is "view original" which gives you
SPF, DKIM, and DMARC results;
jcul · · focus · HN ↗
<a href="https://www.learndmarc.com/" rel="nofollow">https://www.learndmarc.com/
dbbr · · focus · HN ↗
duhhhhh1212 · · focus · HN ↗
Don’t waste your time.
dolebirchwood · · focus · HN ↗
duhhhhh1212 · · focus · HN ↗
The reason for my post was that you the reader is most likely gonna spend more time reading this post than the author(s) did writing it.
glitchcrab · · focus · HN ↗
gerdesj · · focus · HN ↗
However, it is woefully incomplete.
jonathanlydall · · focus · HN ↗
We have the CNAME set up for a like em1234 sub-domain as per SendGrid’s docs which their docs say should cover SPF even if the emails we send have a from address of our main domain (eg noreply@example.com), this is apparently because receiving servers are supposed to do SPF checks against the replyTo address which sendgrid does populate with an address on the subdomain.
This has worked fine for years, Gmail for example is happy and looking at mails from us says everything passes.
However, we recently onboarded a large corporate whose server was blocking the SendGrid emails because it was checking the SPF against the from header rather than the replyTo.
Only way to let the email through was to either add SendGrid SPF records to our main domain, or change the from address of the SendGrid emails, neither of which was 100% ideal.
Not going to try tell the client they’ve configured their server wrong, but have they?
mcmcmc · · focus · HN ↗
adiabatichottub · · focus · HN ↗
See: <a href="http://www.open-spf.org/FAQ/What_it_does/" rel="nofollow">http://www.open-spf.org/FAQ/What_it_does/
Edit: for those unfamiliar with the intricacies of SMTP, the first three lines sent are HELO, MAIL FROM:, and RCPT TO:. The From: address that you see in your mail client is actually another header that gets sent once the server provisionally accepts the message based on the first three headers. It's the difference between the return address on the envelope of a paper letter, and an address printed on the letterhead of the actual letter.
mnaza · · focus · HN ↗
[dead]
gerdesj · · focus · HN ↗
Your MTA should announce itself and DNS should agree. So your MTA says: HELO smtp.example.co.uk
smtp.example.co.uk will resolve to an A record (say a.b.c.d) and a reverse lookup will also work:
d.c.b.a.in-addr.arpa PTR smtp.example.co.uk.
Remember this is all about reputation, so if you also DNSSEC sign example.co.uk, then you will look like you care about your domain reputation.
Then do SPF, DKIM and DMARC. Note how the example for SPF stops at ~all and not -all. The rest is also superficial.
Anyway, I run email systems that do the job properly and it is not trivial and certainly not formulaic. There is no shortcut to getting an IP address/range trusted.
The advice on that page is ... good as far as it goes but woefully inadequate for running an email system. It's a good start.
albertgoeswoof · · focus · HN ↗
gerdesj · · focus · HN ↗
dddw · · focus · HN ↗
taylortrusty · · focus · HN ↗
wahern · · focus · HN ↗
Like email, I run my own HTTP server, serving directly to clients. I know about Cloudflare just from HN threads, but have never used it or know much about that whole reverse proxy universe beyond the very low-level details from having written several reverse proxies myself.
adrian_b · · focus · HN ↗
Anthony-G · · focus · HN ↗
gerdesj · · focus · HN ↗
I just run Exim and Postfix instances that shuffle email around the world. I also have several Dovecots that store the stuff and a large number of MS Exchange online tenants.
adiabatichottub · · focus · HN ↗
snowwrestler · · focus · HN ↗
Reputation, in my experience, is not really based on tech stuff. You can ruin it with bad technical configuration, sure. But the only way to grow it above average is to send a steady stream of emails that readers open and click, sustained over a period of time, with no complaints.
albertgoeswoof · · focus · HN ↗