Z
ZoneSanity Console v1.3.0
IETF Engineering Knowledge Base • Perimeter Security

IETF Standards Center & Technical Documentation

Comprehensive guides for infrastructure architecture, perimeter vulnerability mitigation, SMTP transport compliance, and authoritative DNS resolution.

Authentication & Anti-Spoofing (Email Security)

RFC 7208 §4.6.4 8 min read

SPF PermError Limit & 10 DNS Lookups

Mitigating evaluation errors caused by exceeding 10 DNS lookups. TXT record flattening strategies and SaaS subdomain delegation.

RFC 7489 10 min read

DMARC Deployment & Domain Alignment

Domain-based message authentication protocol, RUA/RUF reporting, and progressive policy migration from none to reject without traffic loss.

Requirements 2024+ 9 min read

Google & Yahoo Bulk Senders Requirements 2024+

Mandatory requirements for senders of more than 5,000 daily emails: FCrDNS resolution (PTR), one-click unsubscribe, and spam rates below 0.3%.

SMTP Transport Security (In-Transit Protection)

RFC 8461 & RFC 8460 7 min read

MTA-STS Implementation & TLS-RPT Telemetry

Preventing Man-in-the-Middle attacks and STARTTLS downgrade on SMTP channels via HTTPS .well-known policies and aggregated TLS-RPT reports.

RFC 5321 & FCrDNS 6 min read

FCrDNS Verification & SMTP Banner Alignment

Configuring reverse PTR records matching HELO/EHLO headers and mail server banners to pass strict anti-spam filters.

DNS Infrastructure & Resilience

RFC 2182 9 min read

DNS Server Redundancy & ASN Diversity (RFC 2182)

Preventing Single Points of Failure (SPOF) through geographic NS server distribution across BGP networks and disjoint Autonomous Systems (ASN).

RFC 6698 & DNSSEC 11 min read

DNSSEC Cryptographic Validation & DANE TLSA Anchors

Authenticating encryption keys within the DNS system to protect SMTP traffic via TLSA records and zone signing using RRSIG and DS.

Perimeter Hygiene & Exposure Surface

DNS Hygiene 8 min read

Orphan CNAME Detection & Subdomain Takeover

Identifying and remediating DNS pointers to removed resources in AWS S3, GitHub Pages, or Azure to prevent subdomain hijacking.