Feature request: The ability to check for a DMARC record in the custom MAIL FROM domain

0

When defining a custom MAIL FROM domain please have SES check for a DMARC record on the custom MAIL FROM as well rather than just the root domain. Right now I have lots of high impact findings in Virtual Delivery Manager advisor because its not looking for a DMARC record in the custom MAIL FROM domain and its cluttering my security audit results.

posta un mese fa90 visualizzazioni
3 Risposte
0

Hi There

If you are using a custom MAIL FROM domain then SES will use the DMARC record for the custom domain. Please check for a misconfiguration of your SPF, DKIM, and DMARC records. Ensure that those DNS records are in your MAIL FROM subdomain.

For example, if your custom MAIL FROM subdomain is mail.example.com, the DMARC record should be published as a TXT record for _dmarc.mail.example.com.

profile pictureAWS
ESPERTO
Matt-B
con risposta un mese fa
0

Hi Matt, thanks for your reply, it looks like SES Deliverability Manager is not recognizing a number of DNS subdomain records, I will be raising a ticket with support whats happening (or not happening in this case). Kind regards Meint

con risposta un mese fa
0

Hi Matt, I raised a ticket with support and this is the response I got back:

"SES VDM advisor recommendations are general recommendations for any domain registered with SES. For your domain “example.com” SPF records have been configured only for the subdomain “secure.example.com” as part of Custom Mail setup. The SPF record for parent domain doesn’t include amazonses.com. Hence VDM will only consider SPF record published for sub domain and not the parent domain. Since SPF checks consider the Mail From Domain and not the From domain and in this case Mail From domain’s “secure.example.com” SPF records are successfully passed, you can ignore the VDM recommendation."

There are no misconfigurations in SPF, DKIM and DMARC as checked by SES support. So it looks like VDM does not carry out the check on the MAIL FROM subdomain? Happy to carry on the conversation via a more private channel where I can share concrete examples.

con risposta 20 giorni fa

Accesso non effettuato. Accedi per postare una risposta.

Una buona risposta soddisfa chiaramente la domanda, fornisce un feedback costruttivo e incoraggia la crescita professionale del richiedente.

Linee guida per rispondere alle domande