feat(site): unfoldhq.dev handles no mail; drop the registrar's forwarding #230

Merged
ryangr0 merged 1 commit from ryangr0/dns-no-mail into development 2026-10-04 16:52:26 +00:00 AGit
Owner

unfoldhq.dev handles no mail, and the registrar's email forwarding goes.

  • What goes: five Namecheap eforward MX records and their SPF include. The config never declared them; you dropped them on 2026-10-04.
  • What the config now declares:
    • a null MX (MX 0 ., RFC 7505), so mail to the domain bounces at once;
    • SPF v=spf1 -all and DMARC p=reject, so nobody can send mail as @unfoldhq.dev.
    • If you want mail on this domain later, replace these three lines.
  • Trailer: the commit carries DNS-Allow-Delete: unfoldhq.dev. The homelab dns-reconciler refuses deletions without it, and refused them once already (job dns-reconciler-manual-1).
  • Docs: the deploy guide and the site's AGENTS.md now describe the reconciler, which is live.

What happens after merge: within the hour the reconciler applies the following. This is the read-only preview, rc 0:

  • modifies 2 records: MX → 0 ., SPF → -all;
  • deletes 3 MX;
  • creates _dmarc, the www → apex redirect, and staging.unfoldhq.dev.

Tested: dnscontrol check and mise run docs-check pass.

🤖 Generated with Claude Code

`unfoldhq.dev` handles no mail, and the registrar's email forwarding goes. - **What goes:** five Namecheap `eforward` MX records and their SPF include. The config never declared them; you dropped them on 2026-10-04. - **What the config now declares:** - a null MX (`MX 0 .`, RFC 7505), so mail to the domain bounces at once; - SPF `v=spf1 -all` and DMARC `p=reject`, so nobody can send mail as `@unfoldhq.dev`. - If you want mail on this domain later, replace these three lines. - **Trailer:** the commit carries `DNS-Allow-Delete: unfoldhq.dev`. The homelab `dns-reconciler` refuses deletions without it, and refused them once already (job `dns-reconciler-manual-1`). - **Docs:** the deploy guide and the site's AGENTS.md now describe the reconciler, which is live. **What happens after merge:** within the hour the reconciler applies the following. This is the read-only preview, rc 0: - modifies 2 records: MX → `0 .`, SPF → `-all`; - deletes 3 MX; - creates `_dmarc`, the `www` → apex redirect, and `staging.unfoldhq.dev`. **Tested:** `dnscontrol check` and `mise run docs-check` pass. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
feat(site): unfoldhq.dev handles no mail; drop the registrar's forwarding
Some checks failed
[Workflow] On Pull Request / checks (pull_request) Failing after 3m27s
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 30s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 17s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
28264b5d4b
The zone still carried Namecheap's email forwarding (five eforward MX
records and its SPF include), which the config never declared. The
owner dropped them on 2026-10-04. The config now says the domain
handles no mail: a null MX (RFC 7505), SPF -all and DMARC p=reject, so
mail to it bounces at once and nobody can send as @unfoldhq.dev.

The homelab dns-reconciler applies development hourly and refuses
deletions without a trailer; this commit carries it. Preview with the
read-only token: two MX and the SPF TXT modified, three MX deleted,
_dmarc, the www redirect and staging created.

DNS-Allow-Delete: unfoldhq.dev
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ryangr0 merged commit 3585f470d5 into development 2026-10-04 16:52:26 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!230
No description provided.