{"id":4953,"date":"2024-02-21T21:16:51","date_gmt":"2024-02-21T21:16:51","guid":{"rendered":"https:\/\/www.piglet-net.net\/pigblog\/?p=4953"},"modified":"2024-02-21T21:17:14","modified_gmt":"2024-02-21T21:17:14","slug":"flat-out","status":"publish","type":"post","link":"https:\/\/www.piglet-net.net\/pigblog\/?p=4953","title":{"rendered":"Flat Out"},"content":{"rendered":"<p>Warning: DNS\/Email nerdery below.<\/p>\n<p>For my sins, one of the things I had to do recently was complete DNS domain authentication, DKIM, and DMARC for some email domains at work in Mailchimp. Mailchimp is the <strike>spamming engine<\/strike> mass email system of choice, and to be fair, they&#8217;re responsible and force compliance with good practice. They also try to increase the chances of your <strike>spam<\/strike> legitimate mass email being deliverable, which is where this comes in.<\/p>\n<p>The big email providers such as Yahoo, Hotmail\/Outlook, and Gmail <a href=\"https:\/\/blog.google\/products\/gmail\/gmail-security-authentication-spam-protection\/\">now insist<\/a> that if you send over a certain threshold, you:<\/p>\n<p>* Send from a domain you own<br \/>\n* Configure DKIM, SPF, and DMARC<br \/>\n* Don&#8217;t send shitloads of actual spam<br \/>\n* include a one-click unsubscribe<\/p>\n<p>This is all part of the spam arms race: electronic means to detect spam are less effective, so this is an attempt to stop the problem at source by making sure the email is coming from where it claims to: spoofing email is trivial, so this effectively adds a signature.<\/p>\n<p>Well, we already had the domain, and SPF, we don&#8217;t <em>actually<\/em> spam people, and Mailchimp handles the unsubscribe, so that left DKIM and DMARC. This actually isn&#8217;t that hard, just involving publishing a few records in DNS that match up with the email servers. The DMARC is little more than a published policy of what people should do if the mail seems to be unathenticated- and &#8220;take no action&#8221; is acceptable. The actual authentication is done by DKIM, where you publish a public key in DNS, and the email is signed by your outgoing server with a corresponding private key. If the encryption key matches, the mail is deemed as being legitimate.<\/p>\n<p>So, I went ahead and did all this for our own infrastructure, as it seems silly to set it all up only for the mass mailing. Pretty simple, too, in the end.<\/p>\n<p>Now, obviously, if someone (Mailchimp) is sending mail for you, you need to publish <em>their<\/em> key for DKIM. The logical way to do this is for them to publish it, and then for you to alias an entry in your DNS (with what is called a CNAME record). That way, if they change the key, it keeps working without changes to your DNS.<br \/>\n<!--more--><\/p>\n<p>Here&#8217;s where the problem came in: I created the CNAME aliases as instructed, but it failed to verify, repeatedly. Mailchimp support were less than helpful, suggesting the records weren&#8217;t propagating (they were, and I proved it), but what they didn&#8217;t know (and I didn&#8217;t realise for a while) was that our DNS provider had something called <a href=\"https:\/\/developers.cloudflare.com\/dns\/cname-flattening\/\">CNAME flattening<\/a>. This is a feature that speeds up a CNAME lookup- which usually involves a referral to another server by definition- by taking the record, caching it, and returning the data directly in a single step, as if the alias wasn&#8217;t there. <\/p>\n<p>Sadly, Mailchimp doesn&#8217;t like this. The data may be correct, but it wants a CNAME and nothing else. If it sees what looks like a TXT record- even if you didn&#8217;t enter a TXT record, and the CNAME alias points to a TXT record- it bombs.<\/p>\n<p>People wonder why I don&#8217;t like new features that mess with long-established tech! A more normal, less featured DNS would simply not entertain such frivolity, and it would have worked first time. Admittedly, they also woudn&#8217;t have the DDOS protection etc as well, though.<\/p>\n<p>The TLDR: <a href=\"https:\/\/developers.cloudflare.com\/dns\/cname-flattening\/set-up-cname-flattening\/\">turn off CNAME flattening for records below the root<\/a> if you want Mailchimp domain authentication to work. Happy Spamming!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Warning: DNS\/Email nerdery below. For my sins, one of the things I had to do recently was complete DNS domain authentication, DKIM, and DMARC for some email domains at work in Mailchimp. Mailchimp is the spamming engine mass email system of choice, and to be fair, they&#8217;re responsible and force compliance with good practice. They &hellip; <a href=\"https:\/\/www.piglet-net.net\/pigblog\/?p=4953\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Flat Out<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,23],"tags":[61,60,63,62],"class_list":["post-4953","post","type-post","status-publish","format-standard","hentry","category-computers","category-tech","tag-cloudflare","tag-cname","tag-dkim","tag-mailchimp"],"_links":{"self":[{"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/posts\/4953","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4953"}],"version-history":[{"count":2,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/posts\/4953\/revisions"}],"predecessor-version":[{"id":4955,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/posts\/4953\/revisions\/4955"}],"wp:attachment":[{"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4953"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4953"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4953"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}