All tips
Fundamentals 2 min read

Locking down domains that never send mail

Parked domains, redirect domains and internal subdomains are spoofed precisely because nobody protects them. Three records fix it permanently.

Most organisations own more domains than they use: defensive registrations, old brands, regional variants, the misspelling bought after a phishing scare. Each one, unprotected, is a credible-looking From address for an attacker who has done their homework.

The three records

Publish these on every non-sending domain

example-parked.com        TXT  "v=spf1 -all"
_dmarc.example-parked.com TXT  "v=DMARC1; p=reject; rua=mailto:dmarc@example.com"
example-parked.com        MX   0 .
  • The SPF record authorises no sender at all.
  • The DMARC record instructs receivers to reject anything claiming to be from it, and still sends you reports so you can see attempts.
  • The null MX record (RFC 7505) states the domain accepts no mail, so senders fail fast rather than queueing for days.

Reporting to an address at a different domain needs authorisation from that domain: a TXT record at example-parked.com._report._dmarc.example.com containing v=DMARC1. Skip it and the reports never arrive.

SPF has no subdomain fallback like DMARC's

DMARC has no wildcard, but the organisational-domain fallback covers subdomains, so one record on the parent protects every subdomain that lacks its own. SPF has no such fallback, so an unprotected subdomain has no SPF unless you publish it, which is an argument for a wildcard TXT record of v=spf1 -all on domains where nothing sends from subdomains.

Make it part of registration

The durable fix is process: whoever registers a domain publishes these three records the same day. Retrofitting across fifty domains is a project; doing it at registration is a checkbox.

Run a full health check on your domain
dnsspoofingparked-domains