Email Security Guides
No entries match.
Start here:Choose your provider: email-security setup guides by host →
SPF
- How do ip4 and ip6 mechanisms work in SPF?The SPF ip4 and ip6 mechanisms authorize sending hosts by IP or CIDR block. Why they are fast and consume zero DNS lookups.
- Setting up SPF at All-InklSPF at All-Inkl: the correct TXT entry in the KAS — step by step with verification.
- Setting up SPF at Amazon Route 53SPF at Amazon Route 53: writing the TXT record for your own mail server — step by step with verification.
- Setting up SPF at checkdomainSPF at checkdomain: the correct TXT entry in the pro settings — step by step with verification.
- Setting up SPF at CloudflareSPF at Cloudflare: publishing the TXT record in the dashboard for your mail provider — step by step with verification.
- Setting up SPF at dogadoSPF at dogado: the exact TXT record for your domain in CloudPit or oneHome — including an explanation of the divergence between ~all and -all.
- Setting up SPF at domainfactorySPF at domainfactory: the wizard in the nameserver settings — step by step with verification.
- Setting up SPF at GandiSPF at Gandi: step by step to the correct TXT record in LiveDNS — including verification.
- Setting up SPF at GoDaddySPF at GoDaddy: the TXT record in the Domain Portfolio — the ready value for GoDaddy mail, step by step with verification.
- Setting up SPF at Hetzner DNSSPF at Hetzner DNS: writing the record for your own mail server — step by step with verification.
- Setting up SPF at HostingerSPF at Hostinger: step by step to the correct TXT record in the hPanel DNS Zone — including verification.
- Setting up SPF at IONOSSPF at IONOS: step by step to the correct DNS record — including verification.
- Setting up SPF at NetcupSPF at Netcup: the correct TXT record in the CCP — step by step with verification.
- Setting up SPF at one.comSPF at one.com: step by step to the correct DNS record inside your Control Panel — including verification.
- Setting up SPF at OVHcloudSPF at OVHcloud: the built-in SPF assistant or your own record — step by step with verification.
- Setting up SPF at StratoSPF at Strato: predefined rule or your own record — step by step with verification.
- Setting up SPF at united-domainsSPF at united-domains: one click under Email security — plus the manual path for your own mail servers.
- Setting up SPF at webgoSPF at webgo: step by step to the correct TXT record in your DNS settings — including verification.
- Setting up SPF for Google WorkspaceSPF for Google Workspace: the right TXT entry at your domain host — with Google's own combined examples.
- Setting up SPF for Mailcow (self-hosted)SPF for Mailcow: the right TXT entry for your own mail server — including PTR and IPv6.
- Setting up SPF for Microsoft 365SPF for Microsoft 365: the right TXT entry at your DNS provider — with Microsoft's own recommendations.
- What do -all, ~all, ?all, and +all mean in SPF?SPF qualifiers dictate what happens when mail fails authentication. The differences between -all, ~all, ?all, and +all.
- What do the a and mx mechanisms check in SPF?The SPF a and mx mechanisms authorize sending from your web and mail servers. How they check A, AAAA, and MX records.
- What does the exists mechanism do in SPF?The SPF exists mechanism checks authorization via dynamic A lookups and macros. How it works and how it impacts DNS limits.
- What does the include mechanism do in SPF?The SPF include mechanism authorizes third-party senders. How recursive evaluation works and why every include adds a DNS lookup.
- What does the redirect modifier do in SPF?The SPF redirect modifier transfers policy evaluation to a shared domain record. How consolidation works and why it differs from include.
- Why should you avoid the ptr mechanism in SPF?The SPF ptr mechanism authorizes senders via reverse DNS. Why RFC 7208 discourages it and recommends IP or include alternatives.
DKIM
- Setting up DKIM at All-InklDKIM at All-Inkl: the TXT (DKIM) record in the KAS with your own selector — step by step with verification.
- Setting up DKIM at Amazon Route 53DKIM at Amazon Route 53: CNAME records for SES-style delegation or a TXT public key for your own server — with the Route 53 apex caveat.
- Setting up DKIM at checkdomainDKIM at checkdomain: one switch under Emails → Security — enables SPF and DKIM together.
- Setting up DKIM at CloudflareDKIM at Cloudflare: publish the public key as a selector._domainkey TXT record — for Cloudflare Email Service or your own mail server.
- Setting up DKIM at dogadoDKIM at dogado: automatic setup on dogado name servers — plus all prerequisites and platform limitations explained.
- Setting up DKIM at domainfactoryDKIM at domainfactory: no wizard, but a TXT record with your sending service's key.
- Setting up DKIM at GandiDKIM at Gandi: one toggle with LiveDNS — plus the 3 CNAME entries for external DNS.
- Setting up DKIM at GoDaddyDKIM at GoDaddy: no bare-domain wizard — your mail product generates the key, you publish it as a CNAME or TXT record.
- Setting up DKIM at HetznerDKIM at Hetzner: konsoleH generates the key pair automatically — plus the TXT route for external DNS and your own servers.
- Setting up DKIM at HostingerDKIM at Hostinger: configure CNAME records in the hPanel DNS Zone and secure your cryptographic email signatures — step by step.
- Setting up DKIM at IONOSDKIM at IONOS: active by default — plus the 3 CNAME entries for external DNS.
- Setting up DKIM at NetcupDKIM at Netcup: two CNAME entries in the CCP — key1 and key2 are both mandatory.
- Setting up DKIM at one.comDKIM at one.com: automatically enabled when using our name servers — plus required CNAME guidance for external DNS.
- Setting up DKIM at OVHcloudDKIM at OVHcloud: one-click activation for MX Plan/Email Pro, or two CNAMEs for external DNS — step by step.
- Setting up DKIM at StratoDKIM at Strato: automatically active via smtp.strato.de — plus the CNAME selectors for your own nameservers.
- Setting up DKIM at united-domainsDKIM at united-domains: automatically enabled for mailbox domains — except with external nameservers.
- Setting up DKIM at webgoDKIM at webgo: add the TXT record for your selector in your DNS settings and secure your cryptographic email signature — step by step.
- Setting up DKIM for Google WorkspaceDKIM for Google Workspace: generate the key in the Admin console, enter the google._domainkey TXT at your domain host.
- Setting up DKIM for Mailcow (self-hosted)DKIM for Mailcow: generate the key in the UI, put the dkim._domainkey TXT in DNS — step by step with verification.
- Setting up DKIM for Microsoft 365DKIM for Microsoft 365: two CNAME selectors, activation in the Defender portal — incl. the new format since May 2025.
- What is a DKIM selector and what is it used for?DKIM selectors subdivide a domain's key namespace. How they work and why they enable concurrent keys and key rotation.
- What is Ed25519 in DKIM and why is it superior to RSA?Ed25519 (RFC 8463) brings elliptic curve signatures to DKIM. Why shorter keys offer stronger security and how to migrate from RSA.
- What is the structure of a DKIM DNS record?A DKIM DNS record publishes your public key along with control tags. The v, k, p, s, and t tags explained in detail.
- Which key length is best for DKIM: 1024 or 2048 bits?RFC 8301 requires at least 1024-bit RSA keys and recommends 2048 bits for DKIM. Why verifiers reject shorter keys.
DMARC
- Setting up DMARC at All-InklDMARC at All-Inkl: adjusting the pre-set _dmarc record — incl. authorizing external report addresses.
- Setting up DMARC at Amazon Route 53DMARC at Amazon Route 53: create the _dmarc TXT yourself in the hosted zone — safely from p=none to p=reject.
- Setting up DMARC at checkdomainDMARC at checkdomain: the _dmarc TXT record and the safe path from p=none to p=reject.
- Setting up DMARC at CloudflareDMARC at Cloudflare: create the _dmarc TXT yourself in the dashboard — safely from p=none to p=reject.
- Setting up DMARC at dogadoDMARC at dogado: create the _dmarc TXT record, choose the right policy, and stop email spoofing — including an explanation of RUA and RUF reports.
- Setting up DMARC at domainfactoryDMARC at domainfactory: create the _dmarc TXT yourself in the nameserver settings.
- Setting up DMARC at GandiDMARC at Gandi: create the _dmarc TXT in LiveDNS — safely from p=none to p=reject.
- Setting up DMARC at GoDaddyDMARC at GoDaddy: the _dmarc TXT record in the Domain Portfolio — GoDaddy's ready value, safely staged to enforcement.
- Setting up DMARC at HetznerDMARC at Hetzner: create the _dmarc TXT yourself in the DNS zone — safely from p=none to p=reject.
- Setting up DMARC at HostingerDMARC at Hostinger: create the TXT record for _dmarc in hPanel and control email protection — step by step.
- Setting up DMARC at IONOSDMARC at IONOS: the _dmarc TXT record and the safe path from p=none to p=reject.
- Setting up DMARC at NetcupDMARC at Netcup: create the _dmarc TXT yourself in the CCP — safely from p=none to p=reject.
- Setting up DMARC at one.comDMARC at one.com: create the _dmarc TXT record inside DNS settings and build your enforcement ramp from p=none to p=reject.
- Setting up DMARC at OVHcloudDMARC at OVHcloud: the _dmarc record via the DNS-zone assistant — start at p=none, then tighten.
- Setting up DMARC at StratoDMARC at Strato: default rule or your own _dmarc record — and why Strato itself sends no reports.
- Setting up DMARC at united-domainsDMARC at united-domains: from p=none to p=reject via radio buttons — and securing unused domains right away.
- Setting up DMARC at webgoDMARC at webgo: create the TXT record for _dmarc in your DNS settings and control email protection — step by step.
- Setting up DMARC for Google WorkspaceDMARC for Google Workspace: the _dmarc TXT at the domain host — the safe path from p=none to p=reject.
- Setting up DMARC for Mailcow (self-hosted)DMARC for Mailcow: the _dmarc TXT record and the safe path from p=none to p=reject.
- Setting up DMARC for Microsoft 365DMARC for Microsoft 365: the _dmarc TXT at the domain host — incl. the peculiarity of the high-risk outbound pool.
- What do adkim= and aspf= mean in DMARC? (Relaxed vs Strict)The adkim= and aspf= tags control DMARC alignment between the visible From header and underlying SPF/DKIM domains. Relaxed vs strict explained.
- What do p=none, p=quarantine, and p=reject mean in DMARC?The DMARC p= tag dictates receiver policy when authentication fails. The differences between none, quarantine, and reject explained.
- What does the pct= tag do in DMARC and how does it aid rollout?The DMARC pct= tag applies enforcement to a percentage of mail. How it works and how to stage a risk-free rollout.
- What does the sp= tag do in DMARC and when do you need it?The DMARC sp= tag sets policy enforcement exclusively for subdomains. How it works and how to use it safely.
- What is the difference between rua= and ruf= in DMARC?The rua= tag delivers aggregate XML traffic reports while ruf= requests detailed failure reports. The differences explained.
- What is the fo= tag in DMARC and what options are available?The fo= tag controls precisely when DMARC failure reports are generated. Options 0, 1, d, and s explained in detail.
DANE & DNSSEC
- DANE for email: who can use it, who can't — and what to use insteadDANE needs DNSSEC and TLSA at the MX — only the mail server operator can do that. Who supports it, who doesn't, and what to use otherwise.
- Setting up DANE and DNSSEC for MailcowDANE for Mailcow: sign with DNSSEC, generate TLSA from the MX certificate (3 1 1), publish under _25._tcp — and keep it in sync on every certificate renewal.
- Setting up DANE and DNSSEC for Microsoft 365DANE + DNSSEC for Microsoft 365: enabled via PowerShell since GA — DNSSEC on, switch the MX, SMTP DANE on.
MTA-STS
- MTA-STS at shared hosts: what works, what doesn'tWhy MTA-STS isn't a toggle at the German shared hosts — and which paths remain open to you anyway.
- Setting up MTA-STS for Google WorkspaceMTA-STS for Google Workspace: DNS TXT plus a policy file on the mta-sts subdomain — testing first, then enforce.
- Setting up MTA-STS for Mailcow (self-hosted)MTA-STS for Mailcow: configurable in the UI since 2025-09 — mailcow hosts the policy centrally, you only set TXT and CNAME.
- Setting up MTA-STS for Microsoft 365MTA-STS for Microsoft 365: DNS TXT plus a self-hosted policy file with *.mail.protection.outlook.com.
TLS-RPT
- TLS-RPT setup: the single DNS record and when it's worth itTLS-RPT is a single, provider-agnostic TXT record that emails you reports about TLS failures. When it's worth it, what it reports, and how to publish it.
BIMI
- BIMI setup: requirements, VMC/CMC costs, and whether it's worth itBIMI shows your logo next to authenticated email — but only with DMARC at enforcement, and at the major inboxes only with a paid certificate. Requirements, costs, and setup.
Blocklists (DNSBL)
- SORBS Blocklist Shutdown: Why dnsbl.sorbs.net Was Discontinued in 2024Is your email server still querying the SORBS blocklist? Discover why SORBS shut down in 2024 and how to remove it immediately.
- SpamCop Blocking List (SCBL): Check, 24-Hour Delisting, and VerdictIs your mail server listed on the SpamCop SCBL? Discover how reports trigger listings and how to achieve automatic 24-hour delisting.
- Spamhaus Blocklists (SBL & PBL): Check, Delisting, and VerdictIs your mail server IP listed on the Spamhaus SBL or PBL? Discover how to check your reputation and request free delisting.
- UCEPROTECT Level 1, 2 & 3 Blocklist: Check, Fees, and VerdictIs your server listed on UCEPROTECT Level 1, 2, or 3? Discover why Level 2 and Level 3 listings should be ignored and how Level 1 works.
Port 25 Blocks
- AWS (Amazon EC2) Port 25 Block: Unblocking Policy and AlternativesAWS blocks outbound port 25 on EC2 to public IPs by default. How to submit per-Region unblock requests or use SES.
- Contabo Port 25 and Email Sending Policy: Rate Limits and ReputationContabo documents a 25 emails/minute sending limit without documenting a general port 25 block. Policy rules and relay alternatives.
- DigitalOcean Port 25, 465, and 587 Block: Why SMTP is Restricted on DropletsDigitalOcean blocks outbound SMTP ports 25, 465, and 587 across all Droplets and Reserved IPs by default. Why and alternatives.
- Google Cloud (Compute Engine) Port 25 Block: Policy and AlternativesGoogle Cloud blocks outbound port 25 external to your VPC by default. Policy exceptions, Workspace relay rules, and port 587 setups.
- Hetzner Cloud Port 25 Block: Unblocking, Policy, and AlternativesHetzner blocks outbound ports 25 and 465 by default. How the limit request unblock process works and what alternatives exist.
- IONOS Port 25 Block: Unblocking Requirements, Policy, and AlternativesIONOS blocks port 25 centrally across cloud and dedicated servers. How to unblock via phone support or use smarthost relays.
- Microsoft Azure Port 25 Block: Subscription Rules and AlternativesAzure blocks outbound TCP port 25 by default across most subscription tiers. Policy differences by subscription type and port 587 relays.
- netcup Port 25 Block (Mail block policy): Removal, Rules, and Alternativesnetcup blocks SMTP by default via a firewall policy (Mail block). How to remove the block directly in SCP self-service.
- Oracle Cloud (OCI) Port 25 Block: June 2021 Cutoff and Exemption RequestsOracle Cloud blocks outbound TCP port 25 across tenancies created after June 2021. How to open a service limits request or use port 587.
- OVHcloud Port 25 Block: Support Unblocking Policy and AlternativesOVHcloud blocks outbound port 25 by default across dedicated, VPS, and public cloud instances. How to request support unblocking.
- Scaleway Port 25, 465, and 587 Block: KYC Unblocking and Security GroupsScaleway blocks remote SMTP ports 25, 465, and 587 across Instances by default. How to unblock via KYC and Security Group settings.
- STRATO Server Port 25 Block: Unblocking and AlternativesSTRATO blocks outbound SMTP port 25 by default on server offerings for security reasons. How to request an unblock or use alternatives.
- Vultr Port 25 Block: Support Ticket Unblocking and AlternativesVultr blocks outbound TCP port 25 by default across cloud instances. How to open a support ticket for removal or use port 587.
SMTP Error Codes
- Gmail SMTP Errors 550 5.7.26, 421 4.7.28 & 4.7.25: Meaning and FixesIs Gmail rejecting your emails with 550 5.7.26 or 421 4.7.28? Discover what these bounce codes mean and how to fix them.
- GMX & WEB.DE SMTP Error 554 IP Address is Block Listed & 421 RetriesAre your emails bouncing from GMX.net or WEB.DE with status 554 or 421? Discover how Nemesis ESMTP errors work and exact steps to unblock.
- IONOS SMTP Error 550 Reject due to policy restrictions & HELO ThrottlingAre your emails bouncing from IONOS mail servers with error 550 or HELO/EHLO delays? Discover exact postmaster definitions and fix steps.
- Outlook SMTP Error 5.7.606: Banned Sending IP and Custom Block ListsAre your emails to Outlook.com or Microsoft 365 bouncing with error 5.7.606 (banned sending IP)? Discover the exact causes and fixes.
- T-Online SMTP Error 554 IP Blocked: Causes and Delisting via tosa@rx.t-online.deAre your emails bouncing from @t-online.de with error 554? Discover the exact causes and how to contact T-Online postmaster support.
- Yahoo SMTP Errors 421, 451, 553 & 554: Meaning and SolutionsReceiving bounce messages from Yahoo like 421, 451, 553, or 554? Find the exact causes and step-by-step solutions to fix email delivery.
Other
- Configure SPF and DMARC in PleskSet up SPF and DMARC for your Plesk domains. Learn how to modify the DNS template, manage incoming SPF checks, and deploy DMARC policies.
- Disable Outdated TLS Versions and Weak Ciphers in EximSecure your Exim mail server by disabling weak ciphers and outdated TLS versions using the tls_require_ciphers parameter.
- DNSBL Blocklist Directory: Check, Delisting, and VerdictsIs your mail server IP listed on a blocklist? Compare reputational verdicts, expiration rules, and free delisting steps for major DNSBLs.
- Enable and Configure DKIM in PleskEnable automatic DKIM signing for your emails in Plesk. Learn how to configure DKIM server-wide, enable it for domains, and manage external DNS setups.
- Enable and Configure STARTTLS in EximLearn how to enable STARTTLS in Exim, manage SSL certificates, and enforce TLS encryption for specific hosts.
- Enable and Configure STARTTLS in SendmailEnable STARTTLS in Sendmail and secure email delivery. Learn how to configure certificates, enforce TLS, and set cipher policies.
- Enable and Enforce STARTTLS in PostfixLearn how to configure STARTTLS in Postfix, when you should enforce TLS encryption, and when it will break your public mail flow.
- How to Disable Legacy TLS Versions and Weak Ciphers in PostfixSecure your Postfix server by disabling obsolete TLS 1.0/1.1 versions and weak cryptographic ciphers.
- Manage Email Deliverability in cPanelOptimize your email deliverability under cPanel. Learn how to automatically repair or manually configure SPF, DKIM, and DMARC records.
- Outbound Port 25 Block by Cloud Provider: Overview and UnblockingOutbound port 25 restrictions across 13 cloud and bare metal providers compared — with links to provider-specific unblocking rules.
- rspamd 4.1.2 fixes remote DoS in the MIME parserDeeply nested message/rfc822 messages could take down the scanner — 4.1.2 bounds the recursion depth. The release also corrects DMARC and SPF address evaluation and changes glob map matching.
- rspamd 4.1.3 fixes out-of-bounds read in DKIM signature verificationAn unbounded bh= length in DKIM signatures allowed an out-of-bounds read during ed25519 verification — 4.1.3 bounds it. Three more memory-safety bugs are also flagged critical.
- rspamd 4.1.4 fixes critical authentication bypass in the controllerA malformed password hash in the rspamd controller accepted any password — 4.1.4 closes the gap. Also fixed: regexp memory leaks, a CSS tokeniser stack overflow, and a startup segfault.
- Set Up DKIM Signing in RspamdEnable automatic DKIM signing for outgoing emails in Rspamd. Learn how to generate secure keys and configure the dkim_signing module.
- Set Up DKIM Signing with OpenDKIMConfigure DKIM on your mail server using OpenDKIM. Learn how to generate key pairs, configure lookup tables, and integrate OpenDKIM with Postfix.
- SMTP Error Dictionary: Common Bounce Codes by ProviderAre your outbound emails bouncing? Discover what SMTP error strings from Gmail, Outlook, Yahoo, T-Online, GMX, and IONOS mean and how to resolve them.
- SPF vs DKIM vs DMARC: how they fit togetherSPF, DKIM and DMARC aren't alternatives — they're a stack. What each one does, why DMARC ties them together, and how to reach enforcement safely.
- SPF, DKIM & DMARC provider comparison: Overview of all 27 hostsWhich provider automates what? Complete comparison of all 27 hosts for SPF setup, DKIM key generation, and DMARC configuration.
- TLS 1.2 is frozen: IETF deprecates RSA and FFDHE key exchangeThree new RFCs seal the TLS 1.2 era: feature freeze, deprecated key exchanges, TLS 1.3 required for new protocols. Nothing breaks for mail servers — but the direction is now official.
- What is email authentication? SPF, DKIM, DMARC and the transport layerSPF, DKIM and DMARC prove who sent your mail; TLS, MTA-STS and DANE protect it in transit. The full stack, explained — with links to every setup guide.
- Which provider supports DANE and MTA-STS? Overview of all 27 hostsWhich email provider supports DANE and MTA-STS? Complete overview of all 27 hosts with detailed reasoning and direct guides.