SasView / sasmeta

BSD 3-Clause "New" or "Revised" License
0 stars 0 forks source link

Add DMARC policy and verifications to mailing lists #20

Open butlerpd opened 3 years ago

butlerpd commented 3 years ago

The SasView domain currently does not have any DMARC policy set and thus no SPF policy or DKIM signatures. This can cause some receiving servers to mark it as spam (and also could allow spoofing our domain in emails). We should set up up mailman to properly digitally sign all outgoing email and add appropriate entries into the SasView DNS records as explained in the help links below. As recommended we should start by setting policy to none but receive updates on when SPF and DKIM fail. Once those seem to be working we should up the required compliance level.

Useful resources: DMARC

DKIM signing for Mailman

Verifications

Domain Reputation

butlerpd commented 3 years ago

Note that as per some of the resources above, the UTK OIT folk strongly suggest implementing DMARC and point out that we can start with DMARC p=none to minimize disruption.

krzywon commented 6 months ago

Should this be transferred to sasview/sasmeta?

butlerpd commented 6 months ago

yes -- I'll move it.