-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
set up an email account #12
Comments
@Changaco Since Gratipay is managing registration and DNS for the |
Liberapay's email is currently hosted on my personal server, so I can easily add an account for Aspen. The tricky part would be sharing access to the mailbox, I haven't figured that out yet (liberapay/salon#11). |
@Changaco Can you just forward [email protected] (or whatever) to yourself, @pjz and me? |
Or we can share a password. |
Yes, I can easily forward an address. We can also share the password of course. I don't have a webmail set up at the moment though, I just use an IMAP client. |
IMAP is fine with me. I use Gmail, which I'm pretty sure I've used as an IMAP client before. |
I'd rather just have it be an alias that forwards to our individual e-mail addresses. Sharing a password can get dicey when adding or removing people. |
I've configured my server, but we need to configure aspen.io's DNS records before proceeding. |
@Changaco What are the records to add? |
You need to modify the SPF and add an MX. Pointing both to |
@Changaco I'm not seeing a DKIM record. Are you referring to the DMARC record?
|
@whit537 Yes, I meant the DMARC record, sorry. |
@Changaco We're going to hear about it under #3 if we don't configure DMARC for aspen.io (that's why it's there now; see https://hackerone.com/reports/117159, pending public disclosure in a few days). How valuable is it to configure DMARC with just SPF? |
I'm not sure a DMARC record is actually useful, but I don't see how it could hurt, so if it saves us from receiving reports on HackerOne then let's do keep one I guess. We should also specify in the security policy that we don't want reports about DKIM not being set up, and hope researchers actually read all those boilerplate policies. |
Alright, so what should our DMARC record be? :-) |
This should do the trick: |
Done! The previous record was @Changaco How's it look? |
Looks good. I don't remember seeing an MX record with a priority of I'm testing my setup now, working out issues in my forwarding script. |
Cool. MX priority is used for sorting multiple MX records. The values are sorted numerically. The values need only be properly ordered relative to each other, there's no absolute meaning to them. |
I know, I was just pointing out that in my experience a value of zero is unusual. :-) |
So, my simple forwarding script works, but basically it's a stupid mailing list software, and MLs can mess up SPF/DKIM/DMARC, so emails might not always make it to your inboxes, but I'll have them in the team's inbox and my personal one, so we won't lose messages. |
Works for me. !m @Changaco |
I've added your email addresses to the list, I'm sending a test message to [email protected], let me know if you get it. |
I've added the following section to https://hackerone.com/aspen:
|
!m @Changaco |
A few instances have cropped up where having an email account for AspenWeb would be useful:
The text was updated successfully, but these errors were encountered: