1000 FAQs, 500 tutorials and explanatory videos. Here, there are only solutions!
Secure email traffic with SPF / DMARC
This guide details the operations automatically performed by Infomaniak to secure the messaging of Service Mail for domain names with extensions .ch
and .li
.
Addition or modification of certain DNS records
To ensure the security of email exchanges around the globe, it has been decided to automatically apply certain DNS configurations to domain names with the .ch/.li extension (and whose DNS zone is on Infomaniak) that have no other impact than to avoid unsolicited emails on both sides. You do not have to do anything specific about this.
Here is a detailed explanation of the necessary modifications and their reasons:
Update of the SPF (Sender Policy Framework)
SPF is an essential security mechanism to verify the authenticity of emails sent on behalf of a specific domain.
When you own a domain name with the extension .ch
/.li
and you want to secure your email services, it is recommended to configure SPF using the directive "-all
".
If this is not already the case (SPF set to "?all
" for example), this policy will be applied automatically.
100% DMARC Reject policy
The DMARC policy is a mechanism that allows you to control how emails from your domain should be handled if they do not pass SPF and DKIM (DomainKeys Identified Mail) checks.
When you set a DMARC policy to "Reject" at 100%, it means that any email that fails SPF or DKIM checks must be rejected, i.e., blocked, by the receiving server.
You can also consider a configuration with a "Quarantine" DMARC policy at 100% which will treat any email that fails SPF or DKIM checks as unwanted mail and may be placed in quarantine, meaning it will be moved to the SPAM folder.
Consequences of SPF and DKIM failures
If an email fails SPF or DKIM verification, it is considered unauthenticated. This means that the receiving server may mark it as potentially unreliable, quarantine it, or reject it (the latter will be the case in effect), depending on the defined DMARC policy. This ensures that only legitimate emails, sent in accordance with the established security policies, are accepted.