A Defensive Computing Checklist    by Michael Horowitz
HOME | About | Domain Names | VPNs | Rules of the Road | DC Presentation | ChangeLog | Stats |

EMAIL

Many times, perhaps most of the time, the first step in a company getting hacked is an email message.

EMAIL FOR YOUR DOMAIN

From: Jerry Lerman on Mastodon December 15, 2024.

If you own a domain name that you do not use for email, you can/should protect it from bad guys from flagging all email from the domain as junk. You do this by adding two TXT records to the DNS for your domain:
TXT v=spf1 -all
TXT v=DMARC1; p=reject;

"The first says there is not a single SMTP server on earth authorized to send email on behalf of your domain. The second says that any email that says otherwise should be trashed."

If you do use your own domain for sending email, Lerman suggests adding this:
SPF record to indicate which SMTP server(s) are allowed to send your email.
DKIM records to add a digital signature to emails, allowing the receiving server to verify the sender and ensure message integrity.
DMARC record that tells the receiving email server how to handle email that fails either check.


NOTE: This topic was moved to its own page Jan. 3, 2024.

 This page: 7 views per day (over 408 days)   Total views: 2,677   Created: January 3, 2024
This Page
Last Updated

January 5, 2025
Site Page
Views TOTAL

 1,097,383
Site Page
Views TODAY

  14
Website by
Michael Horowitz
@defensivecomput
top
Copyright 2019 - 2025