Context
Telling clients to authenticate their mail while not doing it on your own domain is a hard position to hold. We needed three live domains, the company one and two projects, with mail that arrives, senders nobody else can forge, and a way to find out when somebody tries.
What we did
- A single mail server for all three domains, with the MX records pointing home.
- SPF and DMARC published on each domain, with the aggregate reports all arriving at one address.
- The policy tightened gradually: two domains reject, the third stays on quarantine until the reports say it is safe.