← Back to Learning Hub

Security & SSL • Intermediate • 10 min read

Hardening a New Domain: SPF, DKIM, DMARC, DNSSEC and SSL

A launch-day security checklist for a fresh domain, lock down email spoofing, sign your DNS, and get TLS right before anyone abuses the gaps.

A brand-new domain is a blank slate, including to attackers, who will happily spoof mail "from" it or exploit a missing control before you've noticed. Spend an hour at launch on these five layers and you close the gaps that cause the most pain later.

1. Stop spoofing: SPF

Publish an SPF record listing exactly which servers may send mail as your domain, ending in -all (hard fail) once you're confident, or ~all (soft fail) while testing. Keep it under the 10 DNS-lookup limit or it "permerrors" and stops protecting you. Verify with the SPF / DKIM / DMARC checker.

2. Sign your mail: DKIM

Turn on DKIM at your mail provider and publish the selector's public key in DNS. DKIM cryptographically signs each message so receivers can prove it wasn't altered and genuinely came from you. Confirm the selector resolves and validates.

3. Tie it together and get feedback: DMARC

DMARC is the policy that says "if SPF/DKIM don't align, here's what to do", and, crucially, sends you reports. Start at p=none with a rua= reporting address to watch who sends as you, then tighten to quarantine and finally reject once legitimate mail passes. Even before enforcing, the reports are the single best map of your real sending sources.

4. Make DNS tamper-evident: DNSSEC

DNSSEC signs your DNS answers so resolvers can detect tampering and cache-poisoning. Enable signing at your DNS provider, then publish the DS record at your registrar to complete the chain of trust. Verify the full chain, DS at the parent, DNSKEY and RRSIG in the zone, with the DNSSEC checker. An incomplete chain (signed zone, no DS at the registrar) provides no protection, so this last hand-off matters.

5. Serve HTTPS correctly: SSL/TLS

Install a TLS certificate that covers every hostname you serve (apex and www at minimum), and confirm the full chain is present, a missing intermediate works in some clients and fails in others. Add HSTS so browsers always use HTTPS. Validate expiry, hostname coverage, chain and protocols with the SSL / TLS certificate checker.

A sensible launch order

Do SPF, DKIM and DMARC (p=none) together first, they're the highest-value, lowest-risk wins and start collecting reports immediately. Add DNSSEC once your DNS is stable (it's a two-step provider-then-registrar dance). Confirm SSL and HSTS as the site goes live. Then, over the following weeks, tighten DMARC to enforcement using the reports as your guide.

FAQ

Should I start DMARC at reject?

No. Start at p=none with reporting so you can see every legitimate sender first. Jumping straight to reject can silently drop your own mail (newsletters, invoices, helpdesk). Tighten once the reports are clean.

I enabled DNSSEC but nothing seems protected. Why?

You almost certainly signed the zone but didn't publish the DS record at the registrar. Without DS at the parent, the chain of trust is broken. Verify with the DNSSEC checker.

Do I need certificates for both apex and www?

Cover every hostname visitors actually use. If both example.com and www.example.com load, the certificate must be valid for both, and one should redirect to the other in a single hop.

Related guides

Troubleshooting box

If results look inconsistent, compare authoritative nameservers first, then recursive resolvers by region. Capture snapshots every 10 minutes for deterministic incident timelines.

Try VallaDNS free →