Set up SPF, DKIM, and DMARC for your sending domain, check a real message, and fix common DNS and alignment mistakes.
20 comments
Your MTA should announce itself and DNS should agree. So your MTA says: HELO smtp.example.co.uk
smtp.example.co.uk will resolve to an A record (say a.b.c.d) and a reverse lookup will also work:
d.c.b.a.in-addr.arpa PTR smtp.example.co.uk.
Remember this is all about reputation, so if you also DNSSEC sign example.co.uk, then you will look like you care about your domain reputation.
Then do SPF, DKIM and DMARC. Note how the example for SPF stops at ~all and not -all. The rest is also superficial.
Anyway, I run email systems that do the job properly and it is not trivial and certainly not formulaic. There is no shortcut to getting an IP address/range trusted.
The advice on that page is ... good as far as it goes but woefully inadequate for running an email system. It's a good start.
Don’t waste your time.
The reason for my comment is that we, the readers, are most likely gonna spend more time reading this post than the author(s) did writing it.
I'd like to add the following, which I continually reference and has led to repeatable success:
https://www.linuxbabe.com/mail-server/setting-up-dkim-and-sp...
And as far as confirming it works, I continually rely on sending to a gmail address.
Under the three dots is "view original" which gives you
SPF, DKIM, and DMARC results.
(edit:formatting)
Read the full thread on Hacker News →
Related stories
- Show HN: I Measured SPF/DKIM/DMARC on 400 French SMB Domainshilarious-starburst-dabca0.netlify.appHacker News · 1 points · 2 days ago
- Hacker News · 37 points · 14 days ago
- Hacker News · 2 points · 1 day ago
- DEV Community · 9 points · 6 days ago
- Hacker News · 3 points · 9 days ago
- Hacker News · 1 points · 6 days ago