Top Deliverability’s Blog
WttW: Customer subdomain authentication
- October 20, 2023
- Posted by: Top Deliverability
- Category: Industry News Word to the Wise

Word to the Wise just shared a brilliant post:
On Tuesday I wrote about using DNS wildcards to implement customer-specific subdomains for email authentication. As I said then, that approach isn’t perfect. You’d much prefer to have per-customer domain authentication, where each customer has their own DKIM d= and ideally their own SPF records, rather than having all customers sharing those records and relying on loose DMARC alignment to have them to work with a per-customer subdomain in the 5322 From: header. But doing that with DNS wildcards would have some odd side effects, such as TXT records appearing where they weren’t expected, in ways that could trigger bugs in rarely tested code paths at mailbox providers and potentially even open up security problems. I mentioned using a “stunt” DNS server would be one option to do that, and then quite a few people asked me what I meant by that. A stunt DNS server is one that doesn’t
Read more here: Customer subdomain authentication
Leave a Reply Cancel reply
Email Service Providers Handbook
The most comprehensive “Handbook of Email Service Providers“!
SPAMASSASSIN RULES
All SpamAssassin rules in one place, EXPLAINED!
SMTP COMMANDS
& REPLY CODES
All SMTP/ESMTP commands and reply codes in one place, EXPLAINED!
Free DNS Tool
Check the DNS records of your domain with our free DNS tool.
Deliverability Glossary
The most comprehensive Email Deliverability and Marketing Glossary!
- Term: Mailbox Provider (MBP)
- Term: Authentication
- Term: DMARC Alignment
- Term: Subdomain
- Term: Header
- Term: Domain Name System (DNS)
- Term: DomainKeys Identified Mail (DKIM)
- Term: Sender Policy Framework (SPF)
- Term: Email Service Provider (ESP)
- Term: Deliverability
- Term: SpamAssassin
- Term: Extended Simple Mail Transfer Protocol (ESMTP)
- Term: Simple Mail Transfer Protocol (SMTP)