Site AI Auditвід Internet Solutions

How to Protect Parked and Unused Domains from Email Abuse

22 вересня 2026 р.Час читання: 8 хвДоставлюваність e-mail
How to Protect Parked and Unused Domains from Email Abuse

Short answer: A domain that never sends or receives e-mail should say so in DNS, or criminals can use it for convincing spoofed messages. Publish three records on every parked or unused domain: an SPF record of v=spf1 -all, a DMARC record of v=DMARC1; p=reject; at _dmarc, and a null MX record (MX 0 .). Together they tell receivers that no server may send as the domain, that anything claiming to be from it should be rejected, and that it accepts no mail.

Why unused domains are attractive to criminals

Most businesses own more domains than they use: old brand names after a rename, country versions bought for protection, typo variants, domains registered for a campaign or product that never launched, and domains kept after an acquisition. They often have a website redirect and nothing else.

To a criminal, these domains are useful. They carry your brand, they look legitimate and, crucially, nobody is watching them. If a domain publishes no SPF and no DMARC record, receiving servers have no instruction from the owner, and spoofed mail from it is judged only on other signals. A message from [email protected] announcing new bank details can look entirely plausible to a long-standing customer.

Brand protection domains bought specifically to keep them out of criminals’ hands are a particular irony: without e-mail records, the very domains meant to protect the brand can be used against it, because owning a domain does not stop others from writing it in a From address.

Locking these domains down costs a few minutes per domain and no money. It is one of the best security returns available in e-mail.

Record 1: SPF that authorises nobody

Publish a TXT record at the root of the domain:

v=spf1 -all

This says that no server is allowed to send mail using this domain in the envelope sender. Any message claiming to come from it fails SPF immediately. There is no reason to use the softer ~all here, because there is no legitimate mail that could be affected by forwarding or forgotten senders.

For extra coverage, some administrators also publish v=spf1 -all on commonly abused subdomain names, but the DMARC record below already covers subdomains for the visible From address.

Record 2: DMARC that rejects everything

Publish a TXT record at _dmarc.yourparkeddomain.com:

v=DMARC1; p=reject;

Because nothing legitimate can pass SPF or DKIM for the domain, every message using it in the From address fails DMARC, and the policy tells receivers to reject it. Subdomains inherit the policy, so invented names such as billing.yourparkeddomain.com are covered too. You may add sp=reject to make that explicit.

Optionally add a rua report address. Reports for a parked domain show whether anyone is trying to abuse it, which can be useful intelligence. If the report address is on a different domain, remember that the receiving domain must authorise it with a special DNS record, or reports will not be sent.

Record 3: null MX

A null MX record, defined in RFC 7505, is a single MX record with priority 0 and a host of just a dot:

yourparkeddomain.com. MX 0 .

It tells sending servers that the domain accepts no mail at all. They bounce messages immediately instead of trying the domain’s A record or retrying for days. It also signals to receivers that the domain is not a legitimate sender, since a domain that cannot receive mail cannot receive replies or bounces.

The null MX is the least known of the three records, and for many parked domains it is optional: SPF and DMARC already stop the domain being used convincingly as a sender. It is still worth adding, because it makes the domain’s status unambiguous for every system that looks at it.

Some DNS panels do not accept a lone dot as an MX target. If yours does not, ask the provider how to publish a null MX, or at least make sure no MX records point anywhere unintended.

The three records together

RecordNameValueEffect
SPF (TXT)Rootv=spf1 -allNo server may send
DMARC (TXT)_dmarcv=DMARC1; p=reject;Reject mail claiming the domain
MXRoot0 .No mail accepted

All three records are ordinary DNS entries that any DNS panel can hold, and they do not affect the website or its redirect in any way. They can be added in a single session for a whole portfolio of domains.

If the domain does forward mail to your main mailboxes, for example because customers still write to an old address, do not publish a null MX. Keep working MX records for receiving, and publish only the SPF and DMARC records if the domain never sends mail.

Building an inventory of your domains

The hardest part is usually knowing which domains you own. Sources to check:

Also look at domains registered in personal names. Founders, former marketing staff and agencies sometimes registered a company domain in their own account years ago. Those domains are part of your brand but outside your control, and moving them into a company-owned account should come before, or together with, the e-mail lockdown.

For each domain, note whether it sends mail, receives mail, or neither, and apply the right combination of records. Consolidating domains in one registrar account with two-factor authentication also protects them against hijacking.

Common mistakes with unused domains

An annual review of all domains, with a quick lookup of the three records on each, catches almost all of these.

Domains that might send mail again

Sometimes a parked domain comes back to life: a new product launches on it, or a regional office starts using it. Before any mail is sent from the domain, replace the lockdown records with a proper setup: SPF listing the new senders, DKIM for each sending service, DMARC starting at p=none with reports, and working MX records. If you forget, the first real messages will be rejected by your own policy, which is at least an obvious and quickly fixed failure rather than a silent one.

Warm up the domain gradually once it starts sending. A domain that has never sent mail has no reputation, and a sudden burst of messages looks suspicious to mailbox providers.

Checking your domains

You can verify each domain with three lookups: dig TXT domain, dig TXT _dmarc.domain and dig MX domain. For a quicker overview, Site AI Audit checks SPF (including validity and the lookup limit), DKIM, DMARC and MX records for a domain and explains each finding in plain words. Run a free check on each domain you own; paid plans on the pricing page cover several websites and alert you when records change, which is useful for spotting a lockdown record removed by accident.

Related reading

The bottom line

Every domain you own can be used to impersonate you unless it says otherwise. For domains that never handle e-mail, publish v=spf1 -all, a DMARC record with p=reject and a null MX. Keep an inventory of all your domains, apply the records consistently, and replace them with a full setup if a domain ever starts sending mail.

FAQ

Do parked domains need SPF and DMARC?

Yes. Without them, criminals can spoof the domain more easily. v=spf1 -all and a DMARC record with p=reject tell receivers to reject any mail claiming to be from it.

What is a null MX record?

A single MX record with priority 0 and a target of “.” that declares the domain accepts no e-mail. Senders then bounce messages immediately.

Should I use -all or ~all on a parked domain?

Use -all. There is no legitimate mail to protect, so a hard fail has no downside.

Does a redirect-only domain need these records?

Yes. A web redirect has nothing to do with e-mail. The domain can still be used in spoofed From addresses unless SPF and DMARC say otherwise.

What if my parked domain still receives some mail?

Keep working MX records for receiving and publish only the SPF and DMARC records if the domain never sends mail.

Do I need DMARC reports for a parked domain?

They are optional. Reports can show abuse attempts, which is useful information, but the reject policy protects the domain either way.

#DMARC#Email Security#MX Records#SPF
Перевірте свій сайт — безкоштовно.Що виправити на вашому сайті — і з чого почати.
Почати безкоштовно

Ще з блогу

Усі статті →
Internet Solutions

Інші продукти нашої команди

Створено Internet Solutions. Спробуйте й інші наші продукти — кожен заощаджує час по-своєму.

internet-solutions.net ↗
01Автопостинг у соцмережі
PostRSS

Нові записи з вашого RSS-фіду автоматично публікуються у Facebook, X, LinkedIn, Telegram та ще 60+ мережах.

Безкоштовний тариф · з 2014Перейти →
02AI-чат для сайтів
Talkmio

Ваш сайт відповідає відвідувачам 24/7 на основі вашого контенту та їхньою мовою.

Безкоштовний тариф · без карткиПерейти →
03AI-асистент
Ask Mio

Чат, код, дизайн, тексти та дослідження. Mio добирає найкращу модель для кожного завдання.

Безкоштовний тарифПерейти →
04AI-автопілот для блогу й соцмереж
AI Blog Autopilot

AI пише SEO-статті на 2000–3000 слів і публікує кожну в 58+ соцмережах.

Перші 3 статті безкоштовноПерейти →
05Глибокий SEO-аудит
Site SEO AI Audit

Повне SEO-сканування за 7 напрямами, зокрема видимість в AI-пошуку, з виправленнями за силою впливу.

Перший аудит безкоштовноПерейти →
06RSS і товарні фіди
RSS Feed Creator

Створюйте RSS з будь-якої вебсторінки, а також товарні фіди для Google і Meta, що оновлюються самі.

Безкоштовний тарифПерейти →
07Розробка сайтів і SEO
Internet Solutions

Сайти, інтернет-магазини та індивідуальні системи — проєктує, створює й супроводжує наша команда.

З 2011Перейти →
Site AI Audit
Огляд конфіденційності

Цей сайт використовує cookie, щоб ми могли забезпечити вам найкращий користувацький досвід. Інформація cookie зберігається у вашому браузері й виконує такі функції, як розпізнавання вас під час повернення на сайт, а також допомагає нашій команді зрозуміти, які розділи сайту вам найцікавіші та найкорисніші.