Need DNS records help for single server (and IP), and multi-domain mail server.

Grant Taylor gtaylor at tnetconsulting.net
Wed Aug 23 22:18:51 UTC 2017


On 08/23/2017 01:58 PM, John Miller wrote:
> Finally, be _very_ careful about using the SPF qualifier "-all" to
> start out with.  What you're saying there is that the only server
> authorized to _send_ mail for X.TLD is the one listed in the MX.
> Unless people are always logging directly into the mail server to
> send, you're better off with "~all" or "?all" to begin with.

I agree that ~all or ?all is good advice for existing domains.

I would personally try to use -all for new domains from the word go.

Band new domains give you the unique opportunity of doing things 
correctly without any legacy ... cruft ... to support / be compatible with.

So if you want to end up with a -all, I'd suggest starting with it.



-- 
Grant. . . .
unix || die

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3717 bytes
Desc: S/MIME Cryptographic Signature
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20170823/d939dc15/attachment.bin>


More information about the bind-users mailing list