Setting Up DNS Records Correctly for Associations: MX, SPF, DKIM, and DMARC as the Foundation for Reliable Email Delivery and Protection Against Spoofing on Your Own Virtualmin Server
Learn how, as an association, to set up MX, SPF, DKIM, and DMARC DNS records correctly to ensure reliable email delivery and prevent spoofing. Step-by-step guide for Virtualmin.
Why DNS Records Are So Important for Associations
As an association, you rely on reliable email communication: invitations to meetings, newsletters to members, or exchanges with authorities – all of this happens via email. But without the right DNS records, your messages often end up in the spam folder or get forged. In this article, we'll show you how, as an association with your own Virtualmin server, to set up the DNS records MX, SPF, DKIM, and DMARC correctly.
Basics: What Are MX, SPF, DKIM, and DMARC?
Before we dive into practice, let's clarify the terms:
- MX (Mail Exchange): Determines which server should receive emails for your domain.
- SPF (Sender Policy Framework): Specifies which servers are allowed to send emails on behalf of your domain.
- DKIM (DomainKeys Identified Mail): Adds a digital signature to emails to verify their authenticity.
- DMARC (Domain-based Message Authentication, Reporting and Conformance): Provides instructions on how to handle emails that fail SPF or DKIM checks.
These four records form the foundation for trustworthy email communication.
Preparation: Domain and Virtualmin Server
You need a domain, which you can register via Dezhost Domains, and a Virtualmin server. If you don't have one yet, you can rent a virtual server from Dezhost. Alternatively, you can use web hosting if you don't want to manage your own server.
Make sure you have access to your domain's DNS management. At Dezhost, you can find this in the customer area.
Step 1: Set MX Records Correctly
The MX record is the most important record for receiving email. It indicates which server emails for your domain should be delivered to.
How to set the MX record:
- Log in to your DNS provider.
- Create an MX record with the hostname of your mail server (e.g.,
mail.your-association.org). - Set the priority to 10 (or another value if you have multiple mail servers).
- Save the change.
Tip: If you use Virtualmin, you can also have the MX record set automatically by adding the domain in Virtualmin and enabling DNS management.
Step 2: Configure SPF Record
The SPF record is a TXT record that defines which servers are allowed to send emails for your domain. Without SPF, spammers can forge your domain.
Example of an SPF record:
v=spf1 mx a:mail.your-association.org ~all
Explanation:
v=spf1: Identifies the record as SPF.mx: Allows all servers listed in the MX record to send emails.a:mail.your-association.org: Additionally allows the A record of the mail server.~all: All other servers are marked as "softfail" (emails will likely be rejected).
Add this TXT record in your DNS management.
Step 3: Set Up DKIM
DKIM signs your emails with a private key. The public key is stored as a TXT record in your DNS.
Enable DKIM in Virtualmin:
- Open Virtualmin and select your domain.
- Go to Email Settings > DKIM.
- Click Enable DKIM. Virtualmin automatically generates a key pair.
- Copy the displayed public key.
- Create a TXT record with the name
default._domainkey.your-association.organd the valuev=DKIM1; k=rsa; p=YOUR_PUBLIC_KEY.
After publishing in DNS, you can test the signature by sending an email to an address like check-auth@verifier.port25.com.
Step 4: Define DMARC Policy
DMARC builds on SPF and DKIM and tells recipients how to handle unauthenticated emails. You also receive reports about misuse of your domain.
Create DMARC record:
Add a TXT record with the name _dmarc.your-association.org and the following content:
v=DMARC1; p=quarantine; rua=mailto:dmarc@your-association.org; ruf=mailto:dmarc@your-association.org; fo=1
Explanation:
v=DMARC1: Version of the DMARC record.p=quarantine: Emails that fail SPF/DKIM are moved to quarantine (recommended for the beginning).rua: Address for aggregate reports.ruf: Address for forensic reports.fo=1: Reports on errors in SPF or DKIM.
Start with p=none to collect reports first, and later increase to quarantine or reject.
Testing and Monitoring
After setting all records, you should test them. Use tools like MXToolbox or dmarcian. Monitor the DMARC reports to ensure that legitimate emails are not blocked.
If you encounter problems, you can contact our support or search the knowledge base for further instructions.
Conclusion
The correct setup of MX, SPF, DKIM, and DMARC is essential for associations to deliver emails reliably and prevent spoofing. With a Virtualmin server and the steps shown here, you are well equipped. Remember to check regularly and adjust as needed.
If you don't have a server yet, take a look at our virtual servers or web hosting packages. If you have any questions, our team is happy to help.
