Spam Filtering & Blacklists

Mastering Email Security: A Comprehensive Guide

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (6 sections)

Email security for a domain rests on a handful of DNS standards. Three of them, SPF, DKIM and DMARC, stop other people sending mail in your name and help your genuine mail reach the inbox. Three more, MTA-STS, TLS-RPT and BIMI, add encryption rules, reporting and a logo. This page explains what each one does and the order to set them up in.

For step-by-step setup, see the Email Deliverability Deep-Dive

Our main guide, Email Deliverability Deep-Dive: SPF, DKIM, DMARC, BIMI, gives the exact records for all six standards, a complete example and the common mistakes. For mailbox protection, phishing and payment fraud, read Email Security Best Practices.

Key takeaways

Set up SPF, DKIM and DMARC first: every sending domain needs them, and Gmail, Yahoo and Microsoft require them from bulk senders. Start DMARC at p=none, read the reports, then move to quarantine or reject. MTA-STS and TLS-RPT protect mail coming to you, and BIMI can show your logo in some inboxes once DMARC is enforced. None of them replaces strong passwords and two-factor login on your mailboxes.

1. The six standards at a glance

StandardWhat it doesRecordPriority
SPFLists the servers allowed to send mail for your domainOne TXT record on the domainEssential
DKIMSigns each message so receivers can check it wasn't forged or changedTXT record at a selectorEssential
DMARCTells receivers what to do when SPF and DKIM fail, and sends you reportsTXT record at _dmarcEssential
MTA-STSAsks other servers to deliver to you only over verified TLSTXT record plus a policy file over HTTPSOptional
TLS-RPTSends you reports of TLS failures on mail sent to youTXT record at _smtp._tlsOptional, pairs with MTA-STS
BIMIShows your logo next to your mail in supporting inboxesTXT record at default._bimi plus an SVG logoOptional, needs enforced DMARC

2. SPF, DKIM and DMARC: the essentials

  • SPF. Publish one SPF record that includes every service that sends mail as you: your hosting server, Business Email, a newsletter tool. Two SPF records on one domain break both. See Understanding SPF.
  • DKIM. Your mail host creates the key; you publish the public half in DNS. On Domain India cPanel hosting, DKIM is on by default for new accounts. On DirectAdmin the selector is x and most domains already have a key; see checking DKIM in DirectAdmin.
  • DMARC. Start with a monitoring policy, then tighten it once the reports show all your genuine mail passing:
text
_dmarc.yourdomain.com  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"

Setting up DMARC walks through reading the reports and moving to p=quarantine and p=reject.

3. MTA-STS and TLS-RPT: encryption for incoming mail

MTA-STS needs a TXT record and a policy file served over HTTPS from https://mta-sts.yourdomain.com/.well-known/mta-sts.txt. TLS-RPT is one TXT record that tells senders where to report failures:

text
_mta-sts.yourdomain.com   TXT  "v=STSv1; id=20260924000000"
_smtp._tls.yourdomain.com TXT  "v=TLSRPTv1; rua=mailto:[email protected]"
text
version: STSv1
mode: testing
mx: mail.yourdomain.com
max_age: 604800
Start in testing mode

In enforce mode, senders refuse to deliver if your mail server's certificate doesn't match the mx names in the policy. A wrong policy can stop your incoming mail. Use mode: testing, read the TLS reports for a few weeks, and switch to enforce only when they are clean. Change the id whenever you change the policy. If your mail is hosted with us and you're unsure which MX names and certificate apply, ask support before enforcing.

4. BIMI: your logo in the inbox

BIMI needs DMARC at p=quarantine or p=reject, a logo in the SVG Tiny PS format, and a TXT record at default._bimi. Gmail shows the logo only with a Verified Mark Certificate (VMC) or a Common Mark Certificate (CMC). BIMI doesn't improve deliverability by itself; it is a branding layer on top of good authentication. The full process is in Complete Guide to BIMI and VMC.

5. The order to set things up

  1. SPF.
    One record covering every service that sends as you.
  2. DKIM.
    Turn it on for each sending service and publish the keys.
  3. DMARC at p=none.
    Collect reports for two to four weeks.
  4. Tighten DMARC.
    Move to quarantine, then reject, once genuine mail passes.
  5. TLS-RPT and MTA-STS in testing mode.
    Switch to enforce when reports are clean.
  6. BIMI.
    Only after DMARC is enforced, and only if a logo in the inbox is worth the certificate cost to you.

6. Email security with Domain India

Hosting email on cPanel, DirectAdmin and Webuzo gives you SSL/TLS connections and SPF and DKIM through your control panel. Business Email runs on a separate platform, signs every message with DKIM and provides SPF and DMARC records for your domain:

Business Email
₹60/mo + GST
  • Priced per mailbox - start with one
  • Email at your own domain ([email protected])
  • Add and remove mailboxes yourself
  • Webmail with calendar, contacts and tasks
See plan details

The price on the card is a live list price and excludes 18% GST. Support is by 24/7 live chat and support tickets, with a first response to tickets within 15 minutes; there is no phone support.

Which email security records does every domain need?

SPF, DKIM and DMARC. They let receivers check that mail really comes from you, and Gmail, Yahoo and Microsoft require them from bulk senders. MTA-STS, TLS-RPT and BIMI are optional extras.

Should I start DMARC with p=reject?

No. Start with p=none and a reporting address, check the reports until all your genuine mail passes, then move to quarantine and finally reject.

What does MTA-STS protect?

MTA-STS protects mail sent to your domain. It tells other mail servers to deliver only over verified TLS, which blocks downgrade attacks. Start it in testing mode, because an enforced policy with the wrong MX names can stop incoming mail.

Does BIMI improve email deliverability?

Not by itself. BIMI shows your logo in supporting inboxes once DMARC is at quarantine or reject. Gmail needs a Verified Mark Certificate or a Common Mark Certificate to show it.

Is DKIM enabled on Domain India hosting?

DKIM is on by default for new cPanel accounts. On DirectAdmin most domains already have a key with the selector x. Business Email signs every message with DKIM.

Ready to secure your domain's email? Follow the Email Deliverability Deep-Dive, look at Business Email, or open a support ticket if a record isn't working.

Professional email on your own domain

Business Email with DKIM signing, SPF and DMARC records, and webmail over HTTPS.

See Business Email

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app