Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a domain should never send email, publish an SPF record that authorizes no senders and a DMARC policy that asks receivers to reject messages that fail authentication. If it should not receive mail either, add a null MX record. First check the domain and its subdomains for legitimate email activity: enforcing the wrong policy can disrupt real messages, and no DNS policy can force every receiving system to reject a spoof.

Before changing DNS, confirm the domain really is mail-free

Check whether the domain or any of its subdomains are used by applications, websites, contact forms, mailing platforms, or other services to send legitimate messages. A parked apex domain may have no mail activity while a subdomain still sends alerts or transactional email.

If you are unsure, start with DMARC monitoring rather than immediate enforcement. The UK National Cyber Security Centre (NCSC) recommends using p=none while identifying senders, then moving to enforcement once legitimate sources are understood. Aggregate reports can reveal unexpected use, but they should be interpreted alongside your service and DNS inventory. See the NCSC guidance on implementing a DMARC policy of none.

Pay particular attention to subdomains. If a subdomain sends legitimate mail, configure its sending service and authentication appropriately. A parent-domain policy can also set sp=none for subdomains while you handle them separately; do not apply blanket subdomain rejection until you know it is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
JCBIZ 1PC 20mm Thread Tubular Cam Lock Keyed Alike Security Lock DIY Furniture Hardware for Drawer Cabinet Desk Table Office Table with 2 Quincunx Key
  • Type: 1pc 20mm Thread Silver Tone Keyed Alike Tubular Cam Lock for Drawer Cabinet Desk Table Office Table, come with 2 quincunx keys.
  • Fine Workmanship: Made of high quality zinc alloy, strengthen and thickened lock head, E-coating processed surface, durable to use.
  • Easy to Install: Drill a hole at the suitable place, insert the lock head, fix the cam with fastening screw.
  • Function: Helps to protect personal privacy, wealth and important materials, supply you a security personal space with a stylish and complete appearance.
  • Application: Used for sliding door, showcase, cabinet, drawer, safety box, letter box, postal box, coffer, AD showcase, coin-op, vehicle, mail box & tools box, furniture, terminal equipment, electronic/metal/wooden cabinet etc.

Which DNS records to publish

These records have different jobs. SPF and DMARC provide outbound anti-spoofing signals; null MX says the domain does not accept inbound email. The optional empty DKIM record is an additional measure, not a substitute for SPF or DMARC.

Record Example Purpose and scope Main risk or qualification
SPF TXT @ "v=spf1 -all" States that no IP address is authorized to send mail for the domain. Check sending subdomains and any legitimate senders before applying equivalent protection to them.
DMARC TXT _dmarc "v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com" Requests receiver handling for messages that fail DMARC; rua provides an address for aggregate reports. Use sp=reject only if relevant subdomains should not send mail. A receiving system may choose a different action.
Null MX MX 0 . Explicitly signals that the domain has no mail service and does not accept mail. Not an outbound authentication control; some DNS providers do not support it.
Optional wildcard DKIM TXT *._domainkey "v=DKIM1; p=" An additional signal suggested by NCSC; an empty key can also help revoke cached keys. Optional, and it does not prove that every selector or old key record has been removed.

The examples show record content and common DNS names; your provider may present the name and value fields differently. Follow its syntax requirements and avoid creating duplicate SPF records for the same hostname.

Publish SPF to authorize no senders

At the domain’s apex, add a TXT record with the value v=spf1 -all. The -all mechanism marks all senders as unauthorized. The NCSC and GOV.UK both recommend this for domains that do not send email. GOV.UK’s guidance is available at Protect domains that do not send email.

Rank #2
Master Lock Keyed Padlock, 1-1/2-inch Shackle, Keyed Alike 3-Pack 3TRILF
  • Indoor and outdoor lock; Padlock with key is best used for residential gates & fences, sheds, workshops & garages, tool boxes and more.Note: Measure your door's backset, cross bore and thickness to ensure you find the right fit.
  • Key lock features a laminated steel body and a hardened steel shackle for strength and security
  • 4-Pin cylinder for added pick resistance and dual ball bearing locking for maximum pry resistance
  • 1-9/16 in. (40 mm) wide lock body; 9/32 in. (7 mm) diameter shackle with 1-1/2 in. (38 mm) length, 5/8 in. (16 mm) width; Extended shackle for application flexibility
  • Includes three padlocks with two keys; Both keys open all locks

SPF applies to the hostname being checked. Do not assume an apex record automatically covers every subdomain. Identify subdomains in use and give each a suitable configuration; a subdomain that sends mail needs an SPF record reflecting its authorized service rather than a blanket no-senders policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Publish DMARC and choose the right policy

Create a TXT record at _dmarc with a value such as v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com. Replace the example report address with a mailbox you control that can receive aggregate reports. NCSC recommends a reject policy for non-sending parked domains; GOV.UK provides a stricter example that also specifies alignment and subdomain behavior.

If you have not confirmed that all legitimate senders are accounted for, use p=none temporarily to collect reports and investigate. After confirming the domain should not send mail, change to p=reject. For subdomains, sp=reject requests rejection for failing mail using subdomain identifiers. If legitimate subdomains send mail, GOV.UK advises using sp=none at the parent and configuring those subdomains separately. Do not add a stricter setting simply because it appears in an example; match the policy to the domain’s actual mail use.

DMARC evaluates whether SPF and/or DKIM authentication passes with an identifier aligned to the domain in the visible RFC 5322 From field. Under relaxed alignment, identifiers can share an organizational domain; strict alignment requires an exact match. The current specification is RFC 9989, published by the RFC Editor in May 2026 as a Proposed Standard, which obsoletes RFC 7489 and RFC 9091.

Add a null MX if the domain should not receive mail

If the domain has no inbound mail service, publish an MX record with priority 0 and target ., commonly displayed as MX 0 .. This explicitly communicates that no mail service is available. NCSC highlights null MX for domains that have an A record but no MX record, since otherwise senders may attempt delivery to the web server. Check whether your DNS provider supports the null MX syntax.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A null MX does not authenticate outbound mail or stop a sender from using the domain in a forged message. It complements SPF and DMARC by addressing inbound routing instead.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Consider the optional wildcard DKIM record and existing keys

NCSC suggests a wildcard TXT record at *._domainkey with the value v=DKIM1; p= as an additional signal. It is optional, and provider interfaces may not support all wildcard records. GOV.UK also advises revoking existing DKIM selectors published as TXT or CNAME records. Review existing selector records rather than assuming a wildcard record removes or overrides every old key.

Verify DNS and monitor for unexpected use

  1. Check that the apex TXT record returns v=spf1 -all.
  2. Check that _dmarc returns the policy you intended, including any deliberate subdomain setting and report address.
  3. If the domain should not receive mail, confirm that its MX answer is priority 0 with target ..
  4. If you chose the optional wildcard DKIM measure, verify that the provider published it as intended and review existing DKIM TXT and CNAME selectors.
  5. Use a DNS or email-authentication checker, and review DMARC aggregate reports for legitimate senders or unexpected use. NCSC’s Mail Check service can help check and monitor domains where an account is available.

DNS record visibility confirms what you published; it does not prove that every receiving system will enforce it in the same way. DMARC’s policy is a request to receivers, and receivers retain discretion over messages that fail.

What these measures can—and cannot—stop

SPF -all and DMARC p=reject tell participating receivers that the domain has no authorized sender and that messages failing DMARC should be rejected. Their effectiveness depends on receiver handling and correct configuration. They do not guarantee universal rejection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DMARC addresses spoofing of the exact domain in the visible From address when authentication fails alignment. It does not stop lookalike domains, misleading display names, or every message whose content is malicious. A DMARC pass indicates authentication and alignment for the domain; it is not a safety check for the message itself.

For further context, the M3AAWG’s June 2022 Protecting Parked Domains document discusses how SPF, DMARC, and MX records signal that a domain does not send or receive email.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.