Skip to content

Backup & Email

DNS & Mail Authentication

Authoritative DNS design with SPF, DKIM and DMARC rolled out in stages so mail stays deliverable and the domain becomes hard to spoof.

DNS resolver appliances in a secure cage with a hierarchical name resolution map
SYSTEM ACTIVE
NAME RESOLUTION · DNS & Mail Authentication

Capabilities

What we implement

  • Zone audit and record cleanup
  • Sending-source inventory
  • Staged DMARC enforcement
  • Failover and TTL strategy

Security

How it is hardened

  • DNSSEC where the registrar supports it
  • Registrar lock and access control
  • MTA-STS and TLS-RPT
  • DMARC aggregate report monitoring

Architecture

DNS and mail authentication chain

Every legitimate sending source is enumerated before policy changes, then authentication moves to enforcement in stages so mail never silently breaks.

  1. 01 · Registrar & zone

    Registrar lockAuthoritative nameserversTTL strategy

    Ownership, contacts and transfer lock verified before any record work begins.

  2. 02 · Record hygiene

    A / AAAA / CNAME auditStale record removalFailover records

    Conflicting and orphaned records removed; TTLs lowered ahead of planned cutovers.

  3. 03 · Sending sources

    Mail tenantMarketing platformApplication / CRM senders

    Each source inventoried and explicitly authorised — nothing sends unlisted.

  4. 04 · Authentication

    SPFDKIM signingDMARC p=none → quarantine → reject

    Alignment verified with real message headers at each stage before tightening.

  5. 05 · Transport & reporting

    MTA-STSTLS-RPTDMARC aggregate reports

    Encrypted transport enforced and reports reviewed so new senders are caught early.

FAQ

DNS & Mail Authentication questions we are asked

Will enforcing DMARC break our mail?
Not when it is staged. Policy starts at p=none, aggregate reports are reviewed for a full billing and campaign cycle, unauthorised senders are fixed, and only then does enforcement move to quarantine and reject.
Is SPF on its own enough?
No. SPF breaks on forwarding and only checks the envelope sender. DKIM signing with aligned DMARC is what actually makes a domain hard to spoof.
How many DNS lookups can SPF have?
Ten. Exceeding it makes the record permerror and effectively unauthenticated, so includes are flattened or consolidated when a domain gets close.
Can you get our domain off a blacklist?
Delisting is requested once the cause — a compromised account, an open relay, misconfiguration or an unauthorised sender — has been identified and closed. Delisting before the fix simply repeats.

Related

Other backup & email platforms

DNS & Mail Authentication is referenced to describe engineering capability. All trademarks and product names are the property of their respective owners; no partnership or endorsement is implied.

Ready to scope the work?

Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.