Duggy Tuxy · @duggytuxy
10 followers · 21 posts · Server mastouille.fr

Une toolbox intéressante et très utile par les temps qui courent autour des BIMI, DMARC, DKIM, TXT, etc.

Lien de la source ==> lnkd.in/emCnGryq

#cybersecurity #toolbox #infosec #blueteam #BIMI #DKIM #DMARC

Last updated 2 years ago

Steve Atkins · @steve
68 followers · 57 posts · Server deliverabilit.ie

I host my own on a cheap (<$10/mo) VPS.

Technically, I deployed postfix with the default configuration, published records and sign with .

I am an email expert, but the only experty things I did were to not host on a provider like OVH that seems to specialize in hosting spammers, not to allow my users to send spam, nor to forward spam.

That's all. And my is just fine, with no particular effort involved.

#email #SPF #DKIM #deliverability

Last updated 2 years ago

Mr Jau @work · @mrjau
15 followers · 76 posts · Server inosoft.social

Um ja nicht zu viel und Kram zu machen, habe ich erst mal auf dem Linux Mail Server konfiguriert.

#MSTeams #Azure #DKIM #DerGeneralist

Last updated 2 years ago

· @mtjm
6 followers · 40 posts · Server m.mtjm.eu

When I set up years ago, I was happy that it blocked so much . Then I moved to requiring matching reverse DNS records (which I still have mixed feelings about) and that blocked all that spam and more.

After several days of having and verifiers, I observed only one piece of spam being blocked by these (with SPF also failing), while all professional spammers have valid DKIM signatures.

Maybe I should write more so I experience my messages being blocked or not.

#SPF #spam #DKIM #DMARC #email

Last updated 2 years ago

· @mtjm
6 followers · 40 posts · Server m.mtjm.eu

I like the approach of UI design, but now I remember useful examples only in Emacs and Python.

I feel it's a confusing complexity in how handles its config and the entire logic of signing or verifying.

A milter needs to verify mail that an MTA receives from elsewhere and sign mail that the MTA sends from its own system, and these are obviously different for Postfix. So OpenDKIM duplicates some MTA settings and has a nontrivial logic which mails to sign.

#DWIM #OpenDKIM #DKIM

Last updated 2 years ago

· @mtjm
6 followers · 40 posts · Server m.mtjm.eu

Reading about , I think the main complexity in configuring it is key rotation and the automation it needs with various mail servers and DNS servers. (There is also dkim-rotate, maintaining a zone file and providing Exim configuration.)

I think as all my emails are GPG-signed, except for automated ones like Nextcloud share notifications, I have completely no need for plausible deniability which would be the only reason for key rotation.

So I might use a manual procedure for key rotation.

#DKIM

Last updated 2 years ago

Teknikal_Domain · @tek_dmn
45 followers · 842 posts · Server mastodon.tekdmn.me

Today: ripping out my old and processors, OpenDKIM / OpenDMARC, in favor of . I can even drop Postgrey and parts of Postscreen.

Oh it's a pain to set up (you kinda have to wrap your head around hey they do configuration includes to separate site config from package config), but the all-in-one approach *with a web interface* for easy viewing is... Yeah I'm migrating.

Plus it also supports ARC, and seems to be faster at scanning than SpamAssassin.

is happy.

#DKIM #DMARC #rspamd #postfix #email

Last updated 3 years ago