All tips
Fundamentals 2 min read

DNS hygiene for email administrators

TTLs, string limits, propagation and stale records cause more email incidents than the protocols themselves. A short checklist for keeping the zone honest.

Every part of email authentication is a DNS record, so email reliability is DNS reliability. These are the habits that prevent the avoidable incidents.

Manage TTLs deliberately

  • Lower the TTL on a record to five minutes at least one full old-TTL period before a planned change.
  • Raise it back to an hour or more once the change is verified. Low TTLs everywhere means more queries and a harder dependency on your DNS provider being reachable.
  • Remember that a TTL governs how long a wrong answer stays wrong.

Respect the string limits

A TXT record is made of strings of at most 255 characters. Long SPF records and 2048-bit DKIM keys must be split into multiple quoted strings within the single record; resolvers join them with no separator. Truncating instead of splitting produces a record that looks right in a control panel and fails everywhere else.

Verify from outside

Your DNS provider's UI shows what you intended. A public resolver shows what the world sees. Always confirm from at least one external resolver, and after a change from several, since propagation is uneven.

Prune dead records

  • DKIM selectors for services you no longer use.
  • SPF includes for vendors decommissioned years ago. Each one still uses a lookup.
  • Deprecated type 99 SPF records.
  • Verification TXT records from expired trials. Harmless individually, but they hide the records that matter.

Keep a written inventory of every mail-related record and which service owns it. Re-reading the zone once a quarter with that list in hand catches drift long before it becomes an outage.

Run a full health check on your domain
dnsoperationsttl