ramasaig
New Pleskian
- Server operating system version
- Ubuntu 20.04.4 LTS
- Plesk version and microupdate number
- Plesk Obsidian 18.0.44 Update #3
My entire server is getting blacklisted, allegedly because someone is using one of the domains to send spam. I very much doubt if any of my clients is doing this, so it's probably some other organisation.
To counteract whatever is going on I have edited the SPF records for every domain to 'v=spf1 ip4:77.68.113.147 -all' except the offending domain, where it's set to 'v=spf1 -all' in the hope of not authorising any e-mails at all (which may be overkill?).
I have also set up DKIM on all domains. Plesk seems to have made this easier than I expected (or I didn't understand!)
And I've started with DMARC as 'v=DMARC1; p=none'. I'm aware that sets no policy, but I've read that it's prudent to start there and go to 'p=quarantine' or 'p=Reject' later. However, 'p=none' generates a 'not enabled' response from Mxtoolbox.
I have lso limited the number of e-mails that can be sent to ten per hour, which I hope is low enough to make spamming not worthwhile.
Then there's the matter of 'Reverse DNS'. I've seen apparently adverse comment that the reverse DNS is not consistent, or doesn't properly reflect the sending domain. Isn't that inevitable with several domains on one server? The reverse DNS goes back to the server, not the individual domain.
I'm unclear whether one should explicitly set Reverse DNS in Plesk, or whether it will be generated automatically.
There may be specific issues surrounding contact forms, but I think that's best kept for another post.
What more could I be doing in regard to DNS?
To counteract whatever is going on I have edited the SPF records for every domain to 'v=spf1 ip4:77.68.113.147 -all' except the offending domain, where it's set to 'v=spf1 -all' in the hope of not authorising any e-mails at all (which may be overkill?).
I have also set up DKIM on all domains. Plesk seems to have made this easier than I expected (or I didn't understand!)
And I've started with DMARC as 'v=DMARC1; p=none'. I'm aware that sets no policy, but I've read that it's prudent to start there and go to 'p=quarantine' or 'p=Reject' later. However, 'p=none' generates a 'not enabled' response from Mxtoolbox.
I have lso limited the number of e-mails that can be sent to ten per hour, which I hope is low enough to make spamming not worthwhile.
Then there's the matter of 'Reverse DNS'. I've seen apparently adverse comment that the reverse DNS is not consistent, or doesn't properly reflect the sending domain. Isn't that inevitable with several domains on one server? The reverse DNS goes back to the server, not the individual domain.
I'm unclear whether one should explicitly set Reverse DNS in Plesk, or whether it will be generated automatically.
There may be specific issues surrounding contact forms, but I think that's best kept for another post.
What more could I be doing in regard to DNS?