Internet.nl icon indicating copy to clipboard operation
Internet.nl copied to clipboard

Status notice/warning too strict for having Null MX without any A/AAAA

Open WKobes opened this issue 2 years ago • 3 comments

Discussed this morning with @baknu

Per #468 the situation Null MX without A/AAAA record present is given warning/notice score. The reasoning is that a Null MX is not necessary, since there is no A/AAAA record to which an email would otherwise be transmitted.

However, this warning is too strict, since there is no downside to having a Null MX. One could argue that having a Null MX in place at all times could be useful, such that the domain remains protected even if an A/AAAA record is added at a later date.

This is also in line with the M3AAWG policy for parked domains

Proposal: Change scoring for Null MX without A/AAAA from notice to info (Verdict D1 in #468)

WKobes avatar Sep 09 '22 13:09 WKobes

I understand the point of view but IMHO it is about DNS hygiene. NULL MX is not needed when A/AAAA and MX are not there. For internet.nl both notice and info do not penalize the result but notice could make people notice because of the extra icon attention.

Not to sound snarky but for the sake of discussion the last remark could be rewritten as:

One could argue that having a Null MX in place at all times could be ~useful~ risky, such that the domain ~remains protected~ does not receive email even if an ~A/AAAA~ MX record is added at a later date. :)

gthess avatar Sep 09 '22 14:09 gthess

Fully agree with the last statement, I guess it depends on the perspective (security vs usability) which case is worse. I assume M3AAWG bases their policy on the security perspective since it specifically entails parked domain names.

With DNS hygiene, do you mean the minimization of the number of DNS records defined for the maintainability of the zone? Or are there any other technical downsides to having such record that I am not aware of?

WKobes avatar Sep 09 '22 14:09 WKobes

With DNS hygiene, do you mean the minimization of the number of DNS records defined for the maintainability of the zone?

Yes. I don't see a technical downside atm except for the risk of email operation as I stated above.

gthess avatar Sep 09 '22 14:09 gthess