‹ BackHN Continuity

Thread

How to set up SPF, DKIM, and DMARC for your sending domain

92 points · 31 comments · spy888

  1. gerdesj · · focus · HN ↗
    This was not written by an email admin. Start with the real basics:

    Your MTA should announce itself and DNS should agree. So your MTA says: HELO smtp.example.co.uk

    smtp.example.co.uk will resolve to an A record (say a.b.c.d) and a reverse lookup will also work:

    d.c.b.a.in-addr.arpa PTR smtp.example.co.uk.

    Remember this is all about reputation, so if you also DNSSEC sign example.co.uk, then you will look like you care about your domain reputation.

    Then do SPF, DKIM and DMARC. Note how the example for SPF stops at ~all and not -all. The rest is also superficial.

    Anyway, I run email systems that do the job properly and it is not trivial and certainly not formulaic. There is no shortcut to getting an IP address/range trusted.

    The advice on that page is ... good as far as it goes but woefully inadequate for running an email system. It's a good start.

    1. albertgoeswoof · · focus · HN ↗
      They don’t do ips they just use SES, same as resend and a bunch of other email startups lately
      1. gerdesj · · focus · HN ↗
        Sorry, what is SES?
        1. taylortrusty · · focus · HN ↗
          Wait, you claim to run email systems and don't know what SES is?
          1. wahern · · focus · HN ↗
            If you hosted your own email server, why would you need to be familiar with SES, especially if you've been hosting longer than SES providers have been around?

            Like email, I run my own HTTP server, serving directly to clients. I know about Cloudflare just from HN threads, but have never used it or know much about that whole reverse proxy universe beyond the very low-level details from having written several reverse proxies myself.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.