Ta strona nie została jeszcze przetłumaczona na Twój język; wyświetlana jest po angielsku.
Słownik
Pojęcia poczty elektronicznej, w dwóch do czterech zdaniach. 80 haseł.
A
- A and AAAA records
- DNS records mapping a name to an IPv4 (A) or IPv6 (AAAA) address. The SPF a mechanism relies on them, and an MX host must have at least one. A name with only A or AAAA records and no MX is sometimes used as a fallback for mail delivery.
- adkim tag (DKIM alignment)
- DMARC tag specifying the alignment mode between the DKIM signature domain (d=) and the From domain: r (relaxed, same organizational domain is enough) or s (strict, identical domain). The default is r and fits most deployments. Czytaj stronę
- Alignment (DMARC)
- DMARC condition under which the domain authenticated by SPF (envelope domain) or by DKIM (d= tag) must match the From header domain. Alignment is relaxed if both share the same organizational domain, strict if they are identical. A message passes DMARC as soon as one of the two mechanisms is aligned. Czytaj stronę
- Allowlist
- List of explicitly authorised senders that bypass all or part of the filtering at a receiver. It may be local to an organisation or managed by a sender certification body. It does not remove the need for SPF, DKIM and DMARC authentication. Czytaj stronę
- Apex (root domain)
- The domain name itself, without any subdomain, for instance example.com. It is where the MX records and the main SPF are most often published, and it is the From domain of the most visible addresses. A CNAME is not allowed at the apex. Czytaj stronę
- APR (Aggregate Performance Reporting, IETF draft)
- Proposal submitted to the IETF as the individual draft draft-brotman-aggregate-performance-reporting, which transposes the DMARC aggregate report model to delivery performance: a sending domain publishes a receiving address and willing routers send it reports on messages accepted, deferred or rejected. It is a draft not adopted by a working group, not a standard. Czytaj stronę
- ARC (Authenticated Received Chain)
- Mechanism described in RFC 8617 that lets each intermediary (mailing list, forwarder) seal the authentication results observed at its hop. The final recipient can then trust a chain of relays even when SPF or DKIM were broken by forwarding. Czytaj stronę
- ARF (Abuse Reporting Format)
- Format standardised by RFC 5965 for complaint reports sent through feedback loops and for DMARC forensic reports. An ARF report wraps the original message or its headers with metadata about the complaint, in a machine-readable structure. Czytaj stronę
- aspf tag (SPF alignment)
- DMARC tag specifying the alignment mode between the envelope domain verified by SPF and the From domain: r (relaxed) or s (strict). In strict mode, a provider that uses a subdomain as Return-Path no longer allows SPF alignment. Czytaj stronę
B
- BIMI
- Brand Indicators for Message Identification: a mechanism that lets a brand's logo be displayed next to its messages in supporting mail clients. It relies on a DNS record pointing to an SVG logo and requires a DMARC policy of quarantine or reject, often complemented by a VMC or CMC certificate. Czytaj stronę
- Blacklist / DNSBL
- List of IP addresses or domains deemed to emit unwanted mail, queried over DNS (DNS-based Blocklist). Receiving servers query one or more lists on reception and refuse or mark messages from listed sources. Each list has its own listing and delisting criteria. Czytaj stronę
- Bounce (non-delivery message)
- Automatic message returned to the envelope address when mail cannot be delivered, with a code and a reason. Bounces must be processed by the sender to remove invalid addresses, otherwise reputation degrades quickly.
C
- CMC (Common Mark Certificate)
- Variant of the BIMI certificate that does not require a registered trademark but documented prior use of the logo. It lets organisations without a registered mark get their logo displayed at providers that accept it, sometimes with a lower displayed trust level than with a VMC. Czytaj stronę
- CNAME record
- DNS record that makes one name an alias of another. Providers use it to delegate the publication of DKIM keys or validation records. A name carrying a CNAME cannot carry other records, which forbids, for example, an MX and a CNAME on the same name.
- Complaint rate
- Share of messages reported as junk by their recipients, relative to the number of messages delivered. Large routers and mailbox providers set thresholds beyond which delivery degrades; the order of magnitude usually cited is a few reported messages per thousand. Czytaj stronę
D
- DANE
- DNS-based Authentication of Named Entities: publication, in TLSA records protected by DNSSEC, of the fingerprint of the certificate expected for a server. Applied to SMTP (RFC 7672), it enforces TLS to the MX hosts without depending on a certification authority. It requires DNSSEC on the zone. Czytaj stronę
- Dedicated IP / shared IP
- A dedicated IP is used by a single sender, who alone carries its reputation; it suits regular, substantial volumes. A shared IP pools the reputation of several customers of the same provider, which protects small volumes but exposes them to their neighbours' practices. Czytaj stronę
- DKIM (DomainKeys Identified Mail)
- Mechanism described in RFC 6376: the sending server cryptographically signs selected headers and the body of the message, and publishes the matching public key in DNS. The receiver verifies the signature and gains assurance that the message was not altered and that the signing domain takes responsibility for it. Unlike SPF, DKIM survives forwarding. Czytaj stronę
- DKIM key rotation
- Practice of periodically replacing the DKIM key pair, publishing the new key under another selector before retiring the old one. It limits the consequences of a private key compromise. A 2048-bit key is the expected size today. Czytaj stronę
- DKIM selector
- Label chosen by the sender that designates one DKIM key among several. The public key is published at <selector>._domainkey.<domain>, and the selector appears in the s= tag of the signature. Several selectors allow providers to coexist and keys to be rotated without interruption. Czytaj stronę
- DKIM signature
- DKIM-Signature header added to the message, containing the signing domain (d=), the selector (s=), the list of signed headers (h=), the body hash (bh=) and the signature itself (b=). Any change to a signed header or to the body in transit invalidates the signature. Czytaj stronę
- DKIM2 (IETF draft)
- Proposal under discussion at the IETF (DKIM working group, draft-ietf-dkim-dkim2 series) aiming to replace DKIM with a mechanism that records every relay, guarantees traceability of forwarding and allows failure reports to be returned. It is work in progress, not an adopted standard. Czytaj stronę
- DMARC
- Policy described in RFC 7489 and published at _dmarc.<domain>, telling receivers what to do with a message where neither SPF nor DKIM is aligned with the From header domain, and where to send reports. DMARC ties both authentication mechanisms to the domain the user actually sees. Czytaj stronę
- DMARC aggregate report
- XML file sent, usually daily, by a receiver to a domain's rua address. It summarises, per sending IP, the number of messages received, the SPF and DKIM results, the alignment and the policy applied. It is the main tool for inventorying sending flows before tightening the policy. Czytaj stronę
- DMARC forensic report
- Report sent to the ruf address for an individual message that failed, in ARF format. It may contain headers and sometimes excerpts of the message, which explains its limited distribution. It serves one-off diagnosis, not volume tracking. Czytaj stronę
- DNS lookup (SPF limit)
- DNS resolution triggered by an SPF mechanism (include, a, mx, ptr, exists) or by the redirect modifier. RFC 7208 caps the number of lookups per evaluation at ten; beyond that, the result is permerror and the record protects nothing. The ip4 and ip6 mechanisms consume no lookups. Czytaj stronę
- DNS wildcard
- Record of the form *.example.com that answers for any name without an entry of its own in the zone. A wildcard may carry MX records, an SPF TXT or any other type, and then brings an infinity of subdomains into existence. It complicates the inventory of real subdomains and widens the spoofing surface. Czytaj stronę
- DNS zone
- Portion of the DNS name space administered by a single manager and served by the same set of name servers. A domain's zone holds its records and those of its non-delegated subdomains. A subdomain can be delegated to a separate zone with other name servers.
- DNSSEC
- DNS extension that cryptographically signs the records of a zone, letting a resolver verify that an answer was not altered. DNSSEC encrypts nothing but guarantees integrity; it is required for DANE and strengthens trust in the published SPF, DKIM and DMARC records.
E
- Envelope sender / Return-Path
- Address given in the MAIL FROM command of the SMTP dialogue, to which bounces are returned; the receiver copies it into the Return-Path header. Its domain is what SPF verifies. It often differs from the visible From, notably when a provider handles bounces.
- ESP (Email Service Provider)
- Provider offering a mail sending platform, generally for marketing campaigns or transactional messages. The ESP supplies its servers, IPs and tracking tools, and asks the customer to publish SPF and DKIM records and sometimes dedicated subdomains. Czytaj stronę
F
- Feedback loop (FBL)
- Arrangement by which a mailbox provider sends the sender a notification each time a recipient reports a message as junk. It allows complainants to be unsubscribed and the complaint rate to be measured. Enrolment is done with each provider that offers one. Czytaj stronę
- fo tag (failure options)
- DMARC tag setting the conditions for sending forensic reports: 0 (both SPF and DKIM fail, the default), 1 (either one fails), d (DKIM signature fails) or s (SPF fails). It only has effect when a ruf address is declared. Czytaj stronę
- From header
- Sender address shown to the recipient, defined in RFC 5322. The domain of this header is what DMARC protects, by requiring it to be aligned with the domain authenticated by SPF or DKIM. It is also the address a spoofer tries to imitate.
G
- Greylisting
- Anti-spam technique that temporarily refuses (4xx code) the first delivery attempt from an unknown source, counting on the fact that legitimate MTAs retry while many spam tools do not. It delays delivery by a few minutes to a few hours. Czytaj stronę
H
- hardfail (-all)
- SPF fail result obtained when the IP is not authorised and the record ends with -all. The domain owner explicitly asks for rejection. It is the recommended value once every legitimate sending flow has been inventoried and declared. Czytaj stronę
I
- include (SPF mechanism)
- SPF mechanism that delegates evaluation to another domain's SPF record, typically a sending provider's. If that domain authorises the IP, the result is pass. Each include consumes one DNS lookup, and a provider's nested includes often consume several, which quickly approaches the limit of ten. Czytaj stronę
L
- List-Unsubscribe header
- Header defined in RFC 2369 giving a mailto: address or a URL to unsubscribe from a list. Mail clients can display an unsubscribe button based on this header, which reduces junk reports.
M
- Mailbox provider
- Service that hosts recipients' mailboxes and receives the mail addressed to them, whether a large consumer provider or a corporate mail system. These providers are the ones applying SPF, DKIM and DMARC on arrival and setting their own requirements for senders.
- MDA (Mail Delivery Agent)
- Component that places a message accepted by the MTA into the recipient's mailbox, applying sorting or filtering rules where relevant. The recipient then accesses it through their MUA, usually over IMAP. Czytaj stronę
- MSA (Mail Submission Agent)
- Component that accepts messages from mail clients, after authentication, usually on port 587, before handing them to the MTA. It completes missing headers and applies the first conformance checks on the submitted message. Czytaj stronę
- MTA (Mail Transfer Agent)
- Server software that receives, queues and relays mail from one server to another over SMTP. Postfix, Exim or commercial MTAs are examples. On the sending side, the MTA applies rate policies and handles bounces; on the receiving side, it evaluates SPF, DKIM and DMARC. Czytaj stronę
- MTA-STS
- Mechanism described in RFC 8461 by which a receiving domain publishes, via DNS and an HTTPS file, the requirement that inbound SMTP connections use TLS with a valid certificate for its MX hosts. It protects against forced downgrade to a cleartext connection. Czytaj stronę
- MUA (Mail User Agent)
- Mail client used by a person to read and write messages, whether installed software, a mobile app or a web interface. The MUA submits messages to an MSA and retrieves them from the MDA. Czytaj stronę
- MX record
- DNS record naming the servers responsible for receiving a domain's mail, each with a priority; the server with the lowest priority value is contacted first. A domain without MX does not receive mail. MX host names often reveal the mail provider in use. Czytaj stronę
N
- NOERROR
- DNS response code indicating the query succeeded. A NOERROR answer may contain no record of the requested type: the name exists, but there is no TXT, for example. This differs from NXDOMAIN, where the name itself is absent.
- NXDOMAIN
- DNS response code meaning the requested name does not exist, whatever the record type. For SPF, an include pointing at an NXDOMAIN name counts as a void lookup. A wildcard, by construction, prevents any NXDOMAIN answer under the domain concerned.
O
- One-click unsubscribe
- Mechanism described in RFC 8058 that adds the List-Unsubscribe-Post header so that a mail client can unsubscribe the user through a POST request, without an intermediate page. Large mailbox providers have required it from bulk senders since 2024.
- Organizational domain
- The "registrable" domain a given name depends on, determined with the Public Suffix List: example.co.uk for news.example.co.uk. DMARC looks there for the policy inherited by subdomains, and it is the level at which whois is consulted. Czytaj stronę
P
- p tag (DMARC policy)
- Mandatory tag of a DMARC record that sets the requested handling of non-aligned messages: none (no action, observation only), quarantine (junk folder) or reject (refusal at reception). Moving from none to reject is done in steps, guided by aggregate reports. Czytaj stronę
- pct tag (percentage)
- DMARC tag giving the share of non-aligned messages to which the policy applies, from 0 to 100. It is used to roll out quarantine or reject gradually. A p=reject with pct=10 only rejects one message in ten; the others receive the next lower policy. Czytaj stronę
- permerror
- SPF result meaning the record is unusable: invalid syntax, several v=spf1 records on the same name, more than ten lookups or more than two void lookups. In practice, a permerror is equivalent to having no SPF, and DMARC cannot rely on it to align the message. Czytaj stronę
- Postmaster tools
- Consoles made available by some mailbox providers so that senders can view the reputation of their domains and IPs, their complaint rates and their authentication results as seen by that provider. Access requires proving ownership of the domain. Czytaj stronę
- PTR / reverse DNS
- DNS record mapping an IP address to a host name, consulted by receiving servers to check that a sending IP is identifiable. A missing reverse DNS, or one that does not point back to the same IP (FCrDNS), is a frequent reason for refusing a connection. Czytaj stronę
- Public Suffix List
- Publicly maintained list of suffixes under which third parties can register names, such as .fr, .co.uk or some hosting providers' domains. It makes it possible to tell an organizational domain from a mere suffix. DMARC and web browsers use it to delimit domains. Czytaj stronę
Q
- Qualifier of the all mechanism
- The all mechanism ends an SPF record and applies to any IP not matched before it. Its qualifier sets the result: -all (fail, rejection recommended), ~all (softfail, marking without rejection), ?all (neutral, no decision) and +all (pass for everyone, which empties the record of meaning). A domain that never sends publishes v=spf1 -all. Czytaj stronę
R
- redirect (SPF modifier)
- SPF modifier that replaces the current record entirely with another domain's record, including its all qualifier. It is used to centralise the policy of several domains in a single record. It consumes one DNS lookup and is only evaluated when no previous mechanism produced a result. Czytaj stronę
- Registrar
- Accredited body through which a domain is registered and renewed. It passes the registrant's details to the registry, manages the declared name servers and appears in the domain's whois. Changing registrar does not by itself modify the DNS zone.
- Registry
- Body that administers a top-level domain, keeps the database of names registered under that TLD and publishes the corresponding whois. It does not sell directly to registrants but works through accredited registrars.
- RFC 5321 and RFC 5322
- The two founding RFCs of modern email. RFC 5321 describes the SMTP protocol and the envelope (sender, transport recipients). RFC 5322 describes the format of the message itself: From, To, Subject, Date, Message-ID headers and body. SPF acts at the 5321 level, DMARC at the 5322 level.
- rua tag (aggregate reports)
- DMARC tag holding one or more mailto: addresses that receive aggregate reports. Without rua, the domain owner has no visibility on alignment failures. If the address is in another domain, that domain must publish an authorisation record to accept the reports. Czytaj stronę
- ruf tag (forensic reports)
- DMARC tag holding the addresses that receive forensic reports, sent message by message on failure. Many receivers do not send them, for privacy reasons. A ruf address must be ready to receive an unpredictable volume. Czytaj stronę
S
- Sender reputation
- Score, specific to each receiver, assigned to a sending IP and domain from observed history: complaints, bounces, spam traps, authentication, consistency of volumes. A good reputation is built slowly and lost quickly; it determines inbox placement. Czytaj stronę
- SMTP
- Simple Mail Transfer Protocol, the protocol for transmitting mail between servers, described in RFC 5321. It defines the envelope dialogue (sender, recipients, content), the response codes and extensions such as STARTTLS. Port 25 serves exchanges between MTAs, port 587 serves submission. Czytaj stronę
- Soft bounce / hard bounce
- A hard bounce is a permanent refusal (non-existent address, invalid domain, 5xx code); the address must be removed immediately. A soft bounce is a temporary failure (full mailbox, server unavailable, 4xx code); the MTA retries for a limited period before giving up.
- softfail (~all)
- SPF result obtained when the sending IP is not authorised and the record ends with ~all. The receiver is invited to accept the message while marking it as suspicious. For DMARC, a softfail is not a pass: the message must then be aligned through DKIM to pass. Czytaj stronę
- sp tag (subdomain policy)
- Optional DMARC tag that defines the policy applied to subdomains without a record of their own. When absent, subdomains inherit p. An sp=none under a p=reject leaves every subdomain, existing or invented, open to spoofing. Czytaj stronę
- Spam trap
- Email address that belongs to no real person and never subscribed to anything, maintained to identify senders who mail without consent or without cleaning their lists. Sending to a spam trap often leads to a blacklist listing. Czytaj stronę
- SPF (Sender Policy Framework)
- Authentication mechanism described in RFC 7208: a domain owner publishes, in a TXT record, the list of servers allowed to send mail with that domain as envelope sender. The receiving server compares the connecting IP address with that list and obtains a result (pass, fail, softfail, neutral, permerror). SPF only covers the envelope address, not the visible From header. Czytaj stronę
- SPF macro
- Variable of the form %{i}, %{d} or %{s} that RFC 7208 allows inside an SPF mechanism, and which is replaced by the IP, the domain or the sender address of the message being evaluated. Macros allow dynamic records but make the result depend on each message, which complicates static analysis. Czytaj stronę
- STARTTLS
- SMTP command that upgrades a connection established in cleartext to an encrypted TLS session. Its use is opportunistic: if either server does not offer it, transmission continues in cleartext. MTA-STS and DANE exist precisely to make this encryption mandatory. Czytaj stronę
- Subdomain
- Name located under a domain, such as news.example.com under example.com. Each subdomain may have its own MX, SPF and DKIM, but inherits the organizational domain's DMARC policy if it publishes none. Forgotten sending subdomains are a classic source of authentication gaps. Czytaj stronę
T
- Throttling (rate limiting)
- Limit on the number of connections or messages a receiver accepts from a given source over a period. Temporary 4xx response codes signal that the sender should slow down; a properly configured sending MTA adapts its pace per destination. Czytaj stronę
- TLD (top-level domain)
- Last element of a domain name: .fr, .com, .org, .email. Country-code TLDs (ccTLD) are tied to a country; generic ones (gTLD) are not. Some TLDs include second-level suffixes, such as .co.uk, which the Public Suffix List records.
- TLS-RPT
- Mechanism described in RFC 8460 that lets a domain receive reports about TLS negotiation failures when mail is delivered to its MX hosts. It is published in a _smtp._tls.<domain> record and complements MTA-STS or DANE. Czytaj stronę
- TTL (Time To Live)
- Duration, in seconds, for which a DNS resolver may keep an answer in cache. After a record change, the old value may remain visible until the TTL expires. Lowering the TTL before a planned change speeds up propagation.
- TXT record
- DNS record holding free text. SPF, DKIM, DMARC, BIMI, MTA-STS and TLS-RPT are all published as TXT records, each at a specific name. A TXT string is limited to 255 characters; longer records are split into several concatenated strings.
V
- VMC (Verified Mark Certificate)
- Certificate issued by a certification authority attesting that a BIMI logo matches a registered trademark. Some mailbox providers only display the logo when a valid VMC is referenced by the a= tag of the BIMI record. Czytaj stronę
- Void lookup
- SPF DNS lookup that returns NXDOMAIN or an empty answer, for instance an include pointing at a domain that no longer exists. RFC 7208 limits void lookups to two per evaluation; beyond that, the receiver must return permerror. A void lookup almost always indicates a provider no longer used or a typo. Czytaj stronę
W
- Warm-up (ramp-up)
- Practice of gradually increasing the volumes sent from a new IP or a new domain, over several weeks, so that receivers can build a reputation. A high volume sent at once from an unknown source is treated as suspicious. Czytaj stronę