Learn
Reference material on the protocols behind domain trust — how they behave, what breaks them, and how to tell one failure from another. Written for people who run this, not as an introduction to the idea of email.
Email authentication
How SPF, DKIM and DMARC decide whether a message claiming to be from your domain gets delivered.
- The SPF 10-lookup limit, and the void lookup limit nobody mentions
- DMARC alignment: why mail passes SPF and DKIM and still fails
- Getting from p=none to p=reject without blocking your own mail
- Why your DMARC reports never arrive: external destination authorisation
- SPF flattening: what it fixes, what it breaks, and when to use it
- Why legitimate mail fails DMARC
More sections coming
DNS and DNSSEC, dynamic DNS, and brand protection are in progress. In the meantime the free tools cover the same ground diagnostically.
Looking for the product documentation?
These pages are about the protocols, and most of what is here applies whatever you run your DNS on. For step-by-step instructions inside the CertaDNS dashboard, the knowledge base is the other half.