Conversation

Replying to
Email doesn't actually require MX records - in absence of one delivery is to be attempted wherever the A record points. You need to add records to explicitly assert no legitimate mail will be sent. SPF/DMARC records say you won't send, null MX says you don't receive.
3
43
Replying to
Unfortunately you need to set NULL MX and SPF records alongside every A / AAAA record. DMARC with a reject policy will reject mail without valid and aligned DKIM or SPF though. That means the SPF records aren't very important. NULL MX is also primarily about providing fast fail.
1
1
Replying to and
NULL MX is primarily about being friendly to other mail servers so that they can stop trying to send mail over and over again. They can immediately report that they were unable to send mail. DMARC for domain.tld with p=reject is what's most important, and DNSSEC to authenticate.
1