Suggestion for SPF Record for parked domains or no-email ones

I discovered we have quite a few vanity domains that are not being used for email (or just parked ones to prevent someone from registering a similar domain). If these domains do not have mx records, could we still use the mx tag as in the first example below, or do we need to omit it as in the second example below?

“v=spf1 mx -all”
“v=spf1 -all”

You could, but if MX records do not exist, it’s best not to use the tag in spf. In case of any DNS poisoning type of attacks.

Just use “v=spf1 -all” for domains that are not used for email.

1 Like

If you want to be a super nice guy, you could also add a null MX record to those parked domains.
https://tools.ietf.org/html/rfc7505

1 Like