email-toolbox-wiki/parked-domain-how-to.md

33 lines
1.5 KiB
Markdown
Raw Normal View History

2019-09-23 14:50:06 +02:00
# Introduction
This how-to is created by the Dutch Internet Standards Platform (the organization behind [internet.nl](https://internet.nl)) and is meant to provide practical information and guidance on explicitly configuring a parked domain not to use e-mail.
2020-05-27 11:12:03 +02:00
# What is a parked domain?
[Domain parking](https://en.wikipedia.org/wiki/Domain_parking) is the registration of an Internet domain name without that domain being associated with any services such as e-mail or a website.
## Domain without e-mail
If a domain is not using e-mail it is recommended to use the following settings.
### Null MX
2019-09-23 14:50:06 +02:00
Explicitly configure an 'empty' MX record according to [RFC7505 ](https://tools.ietf.org/html/rfc7505).
`example.nl IN MX 0 .`
2020-05-27 11:12:03 +02:00
### DMARC
Set DMARC policy to reject mails, but allow reporting to take place. This helps detecting activity related to your domain.
2019-09-23 14:50:06 +02:00
2019-09-23 15:13:09 +02:00
`_dmarc IN TXT "v=DMARC1; p=reject; rua=mailto:rua@example.nl; ruf=mailto:ruf@example.nl`
2019-09-23 14:50:06 +02:00
2020-05-27 11:12:03 +02:00
### DKIM
2019-09-23 14:50:06 +02:00
2020-05-27 11:12:03 +02:00
`*._domainkey IN TXT "v=DKIM1; p="`
2019-09-23 14:50:06 +02:00
2020-05-27 11:12:03 +02:00
### SPF
2019-09-23 14:50:06 +02:00
`example.nl IN TXT "v=spf1 all"`
2020-05-27 11:12:03 +02:00
## Domain without a website
2019-09-23 14:50:06 +02:00
* Don't use an A or AAAA record for parked domains.
2020-05-27 11:12:03 +02:00
* Don't redirect from a parked domain to the used domain, since this encourages users to keep using the parked domain name. If a redirect is desirable, make sure to use the proper redirect order in order for HSTS headers to remain effective:
2019-09-23 14:50:06 +02:00
1. redirect from HTTP to HTTPS on the same (sub)domain.
2. when using HTTPS, redirect to another (sub)domain.