Showing posts with the label typo domains
A few months ago, I posted about " SPF Lockdown ," a simple way to use an SPF (sender policy framework) DNS record to tell the world that a given domain sends no mail. Email/anti-abuse industry group M3AAWG has some useful guidance that goes even further. Back in Dec…
I've been asked this question pretty regularly: How do I tell the world that a certain domain of mine isn't valid for sending email? What about typo domains, bad domains? How can they configure things to tell the world that no legitimate mail should have this domain in …
RRVS (the Require-Recipient-Valid-Since Header Field) as documented in RFC 7293 seems like a neat idea. It was designed by Yahoo and Facebook folks with the best of intentions. But as an identify theft prevention measure, I am worried that it really falls short. Here's th…