Feature request: The ability to check for a DMARC record in the custom MAIL FROM domain

0

When defining a custom MAIL FROM domain please have SES check for a DMARC record on the custom MAIL FROM as well rather than just the root domain. Right now I have lots of high impact findings in Virtual Delivery Manager advisor because its not looking for a DMARC record in the custom MAIL FROM domain and its cluttering my security audit results.

preguntada hace un mes90 visualizaciones
3 Respuestas
0

Hi There

If you are using a custom MAIL FROM domain then SES will use the DMARC record for the custom domain. Please check for a misconfiguration of your SPF, DKIM, and DMARC records. Ensure that those DNS records are in your MAIL FROM subdomain.

For example, if your custom MAIL FROM subdomain is mail.example.com, the DMARC record should be published as a TXT record for _dmarc.mail.example.com.

profile pictureAWS
EXPERTO
Matt-B
respondido hace un mes
0

Hi Matt, thanks for your reply, it looks like SES Deliverability Manager is not recognizing a number of DNS subdomain records, I will be raising a ticket with support whats happening (or not happening in this case). Kind regards Meint

respondido hace un mes
0

Hi Matt, I raised a ticket with support and this is the response I got back:

"SES VDM advisor recommendations are general recommendations for any domain registered with SES. For your domain “example.com” SPF records have been configured only for the subdomain “secure.example.com” as part of Custom Mail setup. The SPF record for parent domain doesn’t include amazonses.com. Hence VDM will only consider SPF record published for sub domain and not the parent domain. Since SPF checks consider the Mail From Domain and not the From domain and in this case Mail From domain’s “secure.example.com” SPF records are successfully passed, you can ignore the VDM recommendation."

There are no misconfigurations in SPF, DKIM and DMARC as checked by SES support. So it looks like VDM does not carry out the check on the MAIL FROM subdomain? Happy to carry on the conversation via a more private channel where I can share concrete examples.

respondido hace 20 días

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas