SPF/DKIM/DMARC notes, October 2023

Discussion about BCA's Internet Hosting Service
User avatar
David Gibson
Posts: 602
Joined: Thu 16 Mar 2006 23:45

SPF/DKIM/DMARC notes, October 2023

Post by David Gibson » Thu 05 Oct 2023 16:56

This is a note, mostly "to self", documenting some changes to the SPF/DKIM/DMARC settings for some of the domains I manage on britiac4.

SPF SETTINGS

At my DNS host, 123reg, I confirmed/created the DNS entries called @ with TYPE = "TXT/SPF" and DESTINATION/TARGET as follows...

Code: Select all

[for bcra]  v=spf1 +a +mx +ip4:31.25.186.126 -all
[for caves] v=spf1 +a +mx +ip4:31.25.186.126 +ip4:213.120.69.0/24 +a:btinternet.com  ~all
[for wellhouse] I added I record like the BCRA record
[for caving-library]  I updated the record to be like the BCRA record
Note: changed caves record from... v=spf1 +a +mx +ip4:31.25.186.126 +ip4:78.31.106.228 +a:owa.exeter.ac.uk/16 +ip4:65.20.0.12 ?include:btinternet.com -all

Note: changed caving-library record from... v=spf1 +mx +a +ip4:126.186.25.31 -all , as someone appears to have entered it incorrectly.

DKIM SETTINGS

At cpanel, went to Email:Email Deliverability:manage [domain]. If prompted, clicked on generate local DKIM key.
Copied the proferred DKIM settings and pasted to my DNS host, 123reg, where I created a DNS entry called default._domainkey... with TYPE = "TXT" and DESTINATION/TARGET as follows

Code: Select all

[for bcra] default._domainkey

v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3Lvwj0IlzxlK1Tt15RDZBiUCyUj9UfHB5WFaMgjyKPoswSz0bmjlXEmp4Qfg177KKJ3qi/iPwMqAWxFJOXH7IOJAaAtxaLLf+2j5Dui573nRcZynXgvW9LHU/M8SQALwrqDyvS8ayLTUGyvoAwJlG7f9z3GohvPNuPDanI4k+pfUuX9vbsMmhace3YMIbMdmIk4uVKE2SplucnAPSp/fYTUWEK3QRb7B4IB6HZNGNGbKS+EuSH3SNtmLoNw7pO5lwV/4jtkyzotlqPVHeyggo8YxHJ0Gau+NGQVD0VhZIiAeh4V8OqDAHl10zjvDfpVJfub6Q5e4ILO4LZoLUtGSCwIDAQAB;

[for caves] default._domainkey

v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwQsM3eKT7YdoLGmRfZ6ukd3T5wdRh6Wu1mPpYXziCuuFamSfW9eHh0R64um2CtjXG74d3XWRoUt49csyM3PQl3gSiJ0LoSUr4Hkp5aklRDbwCm32egA2s/+HmvNf4PwMVsVph9VRMifD6N0Hon3J5t+2pkJzCCqKyX2pOLxTQeRJi8cIlqTrVoZ9veNhr6pWxUkS2XuD2rFSmT2eaBo/0V2gipOIYTsjdl7/+4+wB7IENg7nwM4vTgvqOkcnYbwUFAT7yF7HtIlf3jt5XFHVWflfe3CqsEvJn9igPy5HqisEXv3xdBkrVxi+o7aeOLQLWC17r+vg1qvNcNfBg8zW5QIDAQAB;

[for wellhouse] default._domainkey

v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxrwCcavS+3hC+L/4aS6/LEAgaCEl1nTc2/bSEUg4HDPfXDuPwjSZKSEgWeTkbuEU4vQS6Y2sz4nn9hQZNHpWq0tYo0FetY5pqgyVrqVTw4a+qU4ZYAvLqsdyVFTvpWXOUnEUnvOhN7IlK2A878Ve9SLZKOmYsfxI13zK2vfdj7PewUWp802eUgoysXPoZQlnHkVIKZ2/bExsGq5piQQZiDLdA3IX59jp08ykHoumHtLoXJTV4Gc6haueDrf5r5ISnbTkJVLhTPp8ANt+02clJnymdD263SfgkBwvNZA6gYJ+62Tk3Ys8hP4JVpCismdqu3GquuPMXJl2fcnmKNXdYwIDAQAB;
DMARC SETTINGS

At my DNS host, 123reg, I created a DNS entry called _dmarc with TYPE = "TXT" and DESTINATION/TARGET =

Code: Select all

v=DMARC1; p=none; sp=none; adkim=r; aspf=r; fo=1; rf=afrf; pct=100; ruf=mailto:dmarcreports@caves.org.uk; ri=86400;
Copied that to bcra.org.uk and wellhouse.me.
Note: initially I tried "reject" instead of "none" but there are then rejections when Katie Eavis (via british-caving) or Ally Graff (via btinternet) tries to send email to gmail.

OTHER SETTINGS

I set up email forwarding from dmarcreports@caves.org.uk --> david@caves.org.uk
I set up mail forwarding at bcra.org.uk [sic] for crimson.amber@wellhouse.me to david@caves.org.uk
Noted an additional DKIM setting at caves.org.uk, which is test._domainkey containing the following. See https://sandbox.caves.org.uk/_my_index.html

Code: Select all

v=DKIM1\; k=rsa\; g=*\; s=email\; h=sha1\; t=s\; p=MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA4KW60d4HK+5CEmgDeTb5j5cxzWyGvTdTSBJuEJGse+WwgKBdLrHCep4t+lI5MTdXcJCGfClYNC7ojy/fbgLxTlHjXp4OUmUYag2r/OpQ4GB6CHzrugX8W7QQ24WmeZAHAM31ySZROJptoQTTikjiNNz/l+pRtNUZ9/0AjH4vr6RX1PQ+6+9m8KU7RydzUfIWWtVZokhEBuGEenmDGu+wj48/zDjsjACwNGxgtHN2LjA6KUUhKzSp6x5YfIo2DTjdIVW80JOUYEUmEFjeBbnaKPajY4Ke72Ju8FTUn4hfqERGVqS/xKNR7Mm30nB4IVpC1qOTZlzpp1olh0/OuMUqWqtPDrlUTx6n11cfuWEp8NDrb51hVqH8MZeRrbSbbt5CLk5SmQMdS+y7bAuo9bEkymVV0WI2qbCcuDt7Gd0jys4VK/beMIUaYs6dxn6AR9QUnjaTQt0qizCEkw5oQ/HBhhhsiLbPC0YL4mwyVQ/ZGSjFxVUg7u6xP7VgTdFYid09UYt1DxM8kpZO+CnqJdbOmMAkSAnbh6ZcHIJFnGsO1Vl0Wv1qfa0WSSmTQSvq8P98bfv5CSI5NbFIwqNj50N2MSi+hm0IqDa0DJSdvx3hnBL/YjnMzpV1turv82NSPqGw5Gso2dojeGoKdySUs8qced13WmG+AVFvr2xvC/WlrzsCAwEAAQ==\;

User avatar
David Gibson
Posts: 602
Joined: Thu 16 Mar 2006 23:45

Re: SPF/DKIM/DMARC notes, October 2023

Post by David Gibson » Mon 09 Oct 2023 15:25

added RUA to DMARC, viz

Code: Select all

v=DMARC1; p=none; sp=none; adkim=r; aspf=r; fo=1; rf=afrf; pct=100; ruf=mailto:dmarcreports@caves.org.uk; rua=mailto:dmarcreports@caves.org.uk; ri=86400;

User avatar
David Gibson
Posts: 602
Joined: Thu 16 Mar 2006 23:45

Re: SPF/DKIM/DMARC notes, October 2023

Post by David Gibson » Tue 10 Oct 2023 17:36

Added fo=1:d to DMARC for BCRA, CAVES and WELLHOUSE

User avatar
David Gibson
Posts: 602
Joined: Thu 16 Mar 2006 23:45

Re: SPF/DKIM/DMARC notes, October 2023

Post by David Gibson » Wed 11 Oct 2023 14:52

for subdomain sandbox.caves.org.uk added SPF and DKIM entries, and set DMARC subdomain policy to reject;

That didnt seem to do what I was expecting, so...

Set DMARC record for subdomain sandbox to p=reject;

Post Reply