Mail Authentication & Contextual Setup Cards
Prototyping information hierarchy, novice guidance vs. expert efficiency, and standardized 4-tier Contextual Help Cards.
Contextual Help Card: SPF, DKIM & DMARC Architecture
SPF specifies which mail servers may send for your domain. DKIM cryptographically signs outgoing emails. DMARC tells receiving servers what to do if SPF or DKIM checks fail, protecting your reputation from spoofing.
- Administrative access to your public DNS provider (e.g. Cloudflare, BIND, Route53).
- Port 25 outbound connectivity.
- Static public IPv4/IPv6 address for mail routing.
- Generates 2048-bit RSA keypairs.
- Signs outgoing mail via Postfix / Gromox milter.
- Formats standard DNS TXT records.
- Runs live DNS resolution health checks.
You must publish the DNS TXT records at your DNS host. Grommunio does not modify external DNS zones directly in the baseline. Wait 5-15 mins for DNS TTL propagation before cutover.
Step 1: DomainKeys Identified Mail (DKIM)
Generate a cryptographic keypair. The private key remains secure on the server to sign outgoing mail; you publish the public key in your DNS zone.
Keypair Active on Server
Publish this DNS TXT record at your DNS host:
Type: TXT
Value: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3f7j9......