Summary: Setting up your own custom domain allows you to brand your Ziflow account with your company's unique URL address.
Available for administrators on: Enterprise
Each custom domain mapping in Ziflow can only be assigned to a single account. If you manage multiple Ziflow accounts, you will need a unique custom domain for each one, as domain mappings cannot be shared or reused across different instances.
Inside the Settings tab, click on Domain mapping.
The Domain mapping process consists of several actions that need to be done before a custom domain is enabled.
Subdomain - This is your current Ziflow subdomain. You can rename it at any time. It stays active even after you turn on a custom domain.
Domain - Enter the domain you want to use. It must be a subdomain of a primary domain, such as proofing.mydomain.com or proofing.mysubdomain.mydomain.com.
-
SSL Certificate - SSL Certificate: Click this button to generate an Amazon Web Services (AWS) Secure Sockets Layer (SSL) certificate. This also adds your domain to Amazon Simple Email Service (SES), which requires Domain Name System (DNS) verification, DomainKeys Identified Mail (DKIM) DNS entries, and mail exchange (MX) entries. At this step, verify the domain and add the entries for SES.
If your domain uses Certification Authority Authorization (CAA) records, you need to add a CAA record that allows Amazon to issue certificates. Otherwise, the SSL certificate can't be created. Add these values: amazon.com, amazontrust.com, awstrust.com, and amazonaws.com. For more information, see the AWS guide to troubleshooting CAA problems: https://docs.aws.amazon.com/acm/latest/userguide/troubleshooting-caa.html
-
Validate using either DNS validation or Email validation. Ziflow recommends DNS validation:
- DNS validation: Choose if you have, or can get, permission to change the DNS settings for the domains in your certificate request.
-
Email validation: Choose if you do not have permission or cannot obtain permission to modify the DNS configuration for the domains in your certificate request. An email is sent to your hostmaster's email address.
For more information, see SSL certificate validation for custom domains.
Authorize to send emails from the entire domain or from validation email - Choose whether Ziflow can send emails from your entire domain or only from the root email address. For example: no-reply@subdomain.domain.com (entire domain) or no-reply@domain.com (single email address).
Enable custom domain - Turn this on to validate the certificate and check that all entries have passed. If validation passes, Ziflow refreshes and starts using your custom domain. All emails then come from your custom domain. For system emails, Ziflow uses the "Email from" setting.
After your domain is verified, the Domain mapping screen looks like this:
Configuring DMARC settings for your Ziflow custom domain
DMARC (Domain-based Message Authentication, Reporting & Conformance) is an email authentication protocol designed to give domain owners the ability to protect their domain from unauthorized use, commonly known as email spoofing.
While setting up a custom domain in Ziflow, when you open the "What do I have to do?" window under the certificate information, you will find all the necessary details related to verifying your domain and setting up DMARC settings.
Here's a breakdown of what DMARC is and how to use it:
What is DMARC?
Email Authentication: DMARC ensures that legitimate emails are properly authenticated against established DKIM and SPF standards and that fraudulent activity appearing to come from domains under the organization's control is blocked.
Reporting: It provides a way for email receivers to report back to the domain owner about emails that pass and fail DMARC evaluation.
Policy: It allows domain owners to instruct email receivers on how to handle emails that fail DMARC checks.
How DMARC Works
SPF Check: Verifies that the email comes from an IP address authorized to send mail on behalf of the domain.
DKIM Check: Ensures that the email has not been altered in transit and was actually signed by the domain.
Alignment: DMARC requires that the domain in the From address aligns with the domain in the SPF and DKIM checks.
Policy Application: Based on the policy specified in the DMARC record, the receiver decides how to handle emails that fail the checks (e.g., quarantine or reject).
How to Use DMARC
To implement DMARC for your domain, follow these steps:
-
Ensure SPF and DKIM are Implemented:
SPF: Create a DNS TXT record specifying which mail servers are permitted to send email on behalf of your domain.
DKIM: Configure your mail servers to sign outgoing emails with a private key, and publish the corresponding public key in a DNS TXT record.
-
Create a DMARC Record:
Add a DMARC record to your domain's DNS settings. This is a TXT record that defines your DMARC policy.
-
The DMARC record includes several tags, the most important of which are:
v: DMARC protocol version (must beDMARC1).p: Policy for handling emails that fail DMARC (none,quarantine,reject).rua: Address to which aggregate feedback reports should be sent.ruf: Address to which forensic reports should be sent (optional).pct: Percentage of emails subjected to filtering (optional, defaults to 100).
Example DMARC record:
v=DMARC1; p=reject; pct=100; ri=86400; rua=mailto:; ruf=mailto: -
Monitor and Adjust:
Start with a policy of
noneto monitor your email traffic without impacting email delivery. Review the reports sent to the addresses specified in theruaandruftags to understand who is sending emails on behalf of your domain.Gradually move to stricter policies (
quarantineorreject) once you are confident that legitimate emails are authenticated correctly.
-
Analyze Reports:
Use the reports to identify sources of unauthenticated emails and take corrective actions (e.g., update SPF records, ensure DKIM signing).
Tools and services are available to help parse and analyze DMARC reports for easier understanding and action.
Example DMARC Record Explanation
"v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourdomain.com; ruf=mailto:dmarc-forensics@yourdomain.com; pct=50;"v=DMARC1: Specifies the version of DMARC.p=quarantine: Instructs email receivers to place emails failing DMARC checks into spam/junk folders.rua=mailto:dmarc-reports@yourdomain.com: Email address to receive aggregate reports.ruf=mailto:dmarc-forensics@yourdomain.com: Email address to receive forensic reports (optional).pct=50: Only 50% of emails are subjected to the DMARC policy.
By following these steps and continuously monitoring and adjusting your DMARC settings, you can significantly enhance the security of your domain against email spoofing and phishing attacks.
Supporting material:
Related to
Comments
0 comments
Please sign in to leave a comment.