DNS hygiene for email administrators
TTLs, string limits, propagation and stale records cause more email incidents than the protocols themselves. A short checklist for keeping the zone honest.
Every part of email authentication is a DNS record, so email reliability is DNS reliability. These are the habits that prevent the avoidable incidents.
Manage TTLs deliberately
- Lower the TTL on a record to five minutes at least one full old-TTL period before a planned change.
- Raise it back to an hour or more once the change is verified. Low TTLs everywhere means more queries and a harder dependency on your DNS provider being reachable.
- Remember that a TTL governs how long a wrong answer stays wrong.
Respect the string limits
A TXT record is made of strings of at most 255 characters. Long SPF records and 2048-bit DKIM keys must be split into multiple quoted strings within the single record; resolvers join them with no separator. Truncating instead of splitting produces a record that looks right in a control panel and fails everywhere else.
Verify from outside
Your DNS provider's UI shows what you intended. A public resolver shows what the world sees. Always confirm from at least one external resolver, and after a change from several, since propagation is uneven.
Prune dead records
- DKIM selectors for services you no longer use.
- SPF includes for vendors decommissioned years ago. Each one still uses a lookup.
- Deprecated type 99 SPF records.
- Verification TXT records from expired trials. Harmless individually, but they hide the records that matter.
Keep a written inventory of every mail-related record and which service owns it. Re-reading the zone once a quarter with that list in hand catches drift long before it becomes an outage.
More on Fundamentals
Email authentication in plain English
SPF, DKIM and DMARC are three DNS records answering one question for a receiving server: should this message, claiming to be from your domain, be trusted?
Locking down domains that never send mail
Parked domains, redirect domains and internal subdomains are spoofed precisely because nobody protects them. Three records fix it permanently.
A monthly email authentication checklist
Authentication is not a project you finish. Thirty minutes a month keeps SPF, DKIM and DMARC from drifting out from under you.