I have recently updated much of my email server setup, including DKIM >signing and validation, and publishing DMARC records. Since I changedThis is not really correct... A restrictive DMARC policy should be used
the DMARC policy away from p=none (as that it is supposed to be only
for testing purposes),
A restrictive DMARC policy should be used if a domain is subject to
spoofing (e.g. because it is a phishing target). But p=none is
a totally valid configuration.
Isn't any domain potentially subject to spoofing and phishing? One Potentially, obviously yes.But experience shows that it is an actual problem only for a tiny number
Do we need to all change/downgrade our email setups, or is there a
plan to address this at some point?
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 491 |
Nodes: | 16 (3 / 13) |
Uptime: | 129:55:31 |
Calls: | 9,689 |
Calls today: | 5 |
Files: | 13,728 |
Messages: | 6,177,503 |