Inter-Actief / Inter-Actief/Beheer_Issues

Configure DKIM/DMARC for our GSuite domains

Open
#21 0 comments 0 reactions 0 assignees View on GitHub
GSuite Priority
Dominant language
No language data
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Currently all mail sent via our GSuite is signed by DKIM but with the google domain, not with our own domain. This makes DMARC fail if we enable it so we need to configure it.

This involves enabling DKIM in GMail in the GSuite admin https://admin.google.com/inter-actief.nl/AdminHome?hl=en#AppDetails:service=email&flyout=authenticate_email for each domain and doing one of two things based on the domain:
- If the domain is managed by the UT: Send them a mail to modify the TXT record for that domain. (preferably all in one go)
- If the domain is managed by us: Add the TXT record.

After that we can enable DMARC, preferably using the slow deployment strategy as found in this guide: https://support.google.com/a/answer/2466580?hl=en&ref_topic=2759254

This helps us be more resilient against (mostly Google's) spam filters.

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the GSuite Admin Console link and the referenced Google DMARC deployment guide first. Identify each domain and whether its DNS is managed by the UT or by the project, then arrange or add the required DKIM TXT records. Done means DKIM uses each domain and DMARC is enabled with the guide's gradual deployment strategy.

Written by the indexing model from the issue text.

Assessment

Domain
cloud, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
28/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.