From 5e7bdc0cf271258bfa247c7905bbcdf54d5046aa Mon Sep 17 00:00:00 2001 From: Alireza Hassani Date: Fri, 18 Sep 2026 11:29:53 +0330 Subject: [PATCH] Use SPF v=spf1 mx -all for Email DNS upserts. Co-authored-by: Cursor --- docs/PROJECT_CONTEXT.md | 2 +- src/mail-dns/mail-dns.ts | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/PROJECT_CONTEXT.md b/docs/PROJECT_CONTEXT.md index 886b8eb..ac9c65a 100644 --- a/docs/PROJECT_CONTEXT.md +++ b/docs/PROJECT_CONTEXT.md @@ -659,7 +659,7 @@ See `.env.example` for the full list. Key groups: - Multi-tenant auth (register, login, passwordless OTP login, reset password via SMS, profile) - Super admin: users, businesses, domains, system business categories - Super admin add/update domain upserts tenant DNS via ArvanCloud or Cloudflare (`@` ANAME/CNAME, `www`/`business`/`customer`/`api` CNAMEs; Cloudflare DNS-only) -- Super admin Websites ⋯ **Email DNS** upserts Stalwart mail records (mail A `185.214.101.41`, MX `mail.meshkee.com`, SPF, two DKIM TXT, autoconfig/autodiscover) on Arvan or Cloudflare; removes extra MX, `dkim._domainkey`, and `_dmarc` +- Super admin Websites ⋯ **Email DNS** upserts Stalwart mail records (mail A `185.214.101.41`, MX `mail.meshkee.com`, SPF `v=spf1 mx -all`, two DKIM TXT, autoconfig/autodiscover) on Arvan or Cloudflare; removes extra MX, `dkim._domainkey`, and `_dmarc` - Super admin: selective migrate-from-old + purge-data (portfolio categories + portfolios; oversized images resized to max 1280×1280; purge removes portfolios + images) - Business team management - Media upload (S3 + Sharp) diff --git a/src/mail-dns/mail-dns.ts b/src/mail-dns/mail-dns.ts index 4dc345d..32a72de 100644 --- a/src/mail-dns/mail-dns.ts +++ b/src/mail-dns/mail-dns.ts @@ -1,7 +1,7 @@ export const MAIL_IPV4 = '185.214.101.41'; export const MAIL_HOSTNAME = 'mail.meshkee.com'; export const MAIL_MX_PRIORITY = 10; -export const MAIL_SPF = `v=spf1 ip4:${MAIL_IPV4} -all`; +export const MAIL_SPF = 'v=spf1 mx -all'; /** Old provider selector (dkim._domainkey.example.com) — removed on mail DNS update. */ export const LEGACY_DKIM_NAME = 'dkim._domainkey'; export const DMARC_NAME = '_dmarc';