Feature request: The ability to check for a DMARC record in the custom MAIL FROM domain

0

When defining a custom MAIL FROM domain please have SES check for a DMARC record on the custom MAIL FROM as well rather than just the root domain. Right now I have lots of high impact findings in Virtual Delivery Manager advisor because its not looking for a DMARC record in the custom MAIL FROM domain and its cluttering my security audit results.

asked 20 days ago78 views
3 Answers
0

Hi There

If you are using a custom MAIL FROM domain then SES will use the DMARC record for the custom domain. Please check for a misconfiguration of your SPF, DKIM, and DMARC records. Ensure that those DNS records are in your MAIL FROM subdomain.

For example, if your custom MAIL FROM subdomain is mail.example.com, the DMARC record should be published as a TXT record for _dmarc.mail.example.com.

profile pictureAWS
EXPERT
Matt-B
answered 20 days ago
0

Hi Matt, thanks for your reply, it looks like SES Deliverability Manager is not recognizing a number of DNS subdomain records, I will be raising a ticket with support whats happening (or not happening in this case). Kind regards Meint

answered 19 days ago
0

Hi Matt, I raised a ticket with support and this is the response I got back:

"SES VDM advisor recommendations are general recommendations for any domain registered with SES. For your domain “example.com” SPF records have been configured only for the subdomain “secure.example.com” as part of Custom Mail setup. The SPF record for parent domain doesn’t include amazonses.com. Hence VDM will only consider SPF record published for sub domain and not the parent domain. Since SPF checks consider the Mail From Domain and not the From domain and in this case Mail From domain’s “secure.example.com” SPF records are successfully passed, you can ignore the VDM recommendation."

There are no misconfigurations in SPF, DKIM and DMARC as checked by SES support. So it looks like VDM does not carry out the check on the MAIL FROM subdomain? Happy to carry on the conversation via a more private channel where I can share concrete examples.

answered 7 days ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions