Cheers Alan,
A pretty good breakdown of the approach. I’d recommend having a look at Dmarcly as they a comprehensive guide on this from a Microsoft perspective (but it translates easy enough across to Google as well) How to Set Up DMARC, DKIM, and SPF in Office 365 (O365) Exchange Server: the Complete Implementation Guide - DMARCLY.
They also have some Tools to check your SPF (so you can see when a DNS record includes additional lookups that push you over the limit of 10), DKIM and DMARC records. Free SPF/DKIM/DMARC analyzer tools for DMARC setup - DMARCLY.
I regularly use their free tools to check records while setting this up as it becomes very important once DMARC is in the equation (and they very recently pointed out a stubborn DKIM Selector2 record that just wasn’t being added to DNS despite the portal swearing it was there).
Cheers,
Jono
Sent from Mail for Windows
--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/F88BAFF9-DC91-408F-A48C-80678C0D80FD%40timarugirls.school.nz.
“v=DMARC1; p=quarantine; rua=mailto:dmarc@timarugirls.school.nz; ruf=mailto:dmarc_failed@timarugirls.school.nz; pct=100; adkim=s; aspf=s; ri=21600;”
At the moment I have it set to 100% quarantine (p=quarantine; pct=100;) When I am confident that I have identified all the genuine sources (email servers) for my domain, I will change this to "p=reject"
The DMARC record only allows two "mailto:” entries for each of the “rua" (aggregate reports) and “ruf" (message-specific reports) tags, so I set up two group emails in Gsuite to receive the DMARC reports. Each groups forward any emails received to a MS Teams channel, so that I have visibility into the reports that I am getting. They also forward to one of many DMARC analysis services that are available. These sites aggregate reports over time and present the information in a user friendly way. In this way I can test different analysis sites in parallel, although I have found that some sites refuse to work unless they actually see their address in your DMARC record!
My favourite DMARC analysis site so far is https://app.glockapps.com/
So far I haven’t received any forensic (“ruf") reports for some reason.
Being a holiday, email is quiet at the moment, but here is an example of compliance failures over the last week.
This is how I spotted that “notification.fortinet.net” needed to be in my SPF record. It is used to send the login token for the Fortinet VPN.
Alan Jenks
IT Administrator
Timaru Girls High School
--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/F88BAFF9-DC91-408F-A48C-80678C0D80FD%40timarugirls.school.nz.
--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsub...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/C91CB6D2-FCEA-4C74-9434-E7360C69F0F1%40hxcore.ol.
Kind regards,
Alistair Baird
IT Manager
P
06 354 4198 1 Holdsworth Avenue, Milson |
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsubscribe...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/F88BAFF9-DC91-408F-A48C-80678C0D80FD%40timarugirls.school.nz.
--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-schools+unsubscribe...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/C91CB6D2-FCEA-4C74-9434-E7360C69F0F1%40hxcore.ol.
--
Kind regards,
Alistair Baird
IT Manager
P 06 354 4198
stpeterspn.school.nz1 Holdsworth Avenue, Milson
Palmerston North, 4414
Thanks for sharing! I was testing my knowledge of TLD Country domains instead 😊
--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/402c075b-302a-40a8-a686-e0035011ab5an%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/18c2ae91-223e-4159-bcd5-6cc5b30f89cbn%40googlegroups.com.
You received this message because you are subscribed to a topic in the Google Groups "Techies for schools" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/techies-for-schools/rqGUlXWrCdk/unsubscribe.
To unsubscribe from this group and all its topics, send an email to techies-for-sch...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/CAJtT%3DCDkLTXxrZ8x5umkZ99MnaynhXeBhGTNN2PH3bkdQ2Wejw%40mail.gmail.com.
v=DMARC1; p=quarantine; rua=mailto:bl...@gbh.school.nzmailto:yve...@gbh.school.nz; pct=100; adkim=r; aspf=s
To view this discussion on the web visit https://groups.google.com/d/msgid/techies-for-schools/CABLu1fGZFfPUqk%3DDbOw3pRguyOXY9LQ9mx72NWBECM384b6%3DxQ%40mail.gmail.com.