Conversation

You need to add the NULL MX and SPF records alongside every A and AAAA record. DMARC applies to subdomains unless they provide their own policy. Just make sure not to have a permissive policy for subdomains via the sp parameter. SPF hardly does anything. It's DMARC that matters.
1
3
DMARC requires valid, aligned SPF / DKIM. The policy specifies what to do when it fails to pass. A p=reject policy will prevent spoofed emails from the domain to providers enforcing DMARC. SPF itself doesn't stop spoofing since it does not need to be aligned with the FROM header.
2
3
Yes, I largely agree. Iโ€™ve had SPF, DKIM, and DMARC configured on my domains for years. The key word is โ€œeitherโ€ mei ONT that one (SPF) is sufficient for DMARC. Should you have DKIM too? Yes. Is DKIM technically required? I donโ€™t think so.
1
Show replies
This whole thread (as annoying as Twitter makes reading an entire threaded conversation) has been a wonderful education in the nuances of SPF, DKIM, and DMARC. I don't want to spam your replies on each of them, but did want to profusely thank you both for the learnin'!
1