kpp.in.th: Cloudflare DNS and a Free thMail Inbox

kpp.in.th (short for the k-pp logo) is registered at THNIC, which also gives one free mailbox on the domain through thMail. I wanted DNS on Cloudflare and mail that lands in Gmail's inbox.

DNS to Cloudflare

  1. Cloudflare → Add a domain → note the two assigned nameservers.
  2. THNIC portal → ตั้งค่า DS: delete any old DS first. A stale DS with new nameservers causes SERVFAIL.
  3. THNIC portal → ตั้งค่า NS: set the Cloudflare pair.

Check the delegation at the registry:

dig NS kpp.in.th @a.thains.co.th +norec

thMail

One mailbox, 1 GB, free for a year. I took ponpawit@kpp.in.th. The only required record is MX @ → mail.thnic.co.th.

SPF: Trim It

The starting record was:

v=spf1 +a +mx include:_spf.thmail.thnic.co.th ~all
  • a → my apex is proxied, so this authorized Cloudflare's edge IPs to send as me.
  • mx → 122.155.0.144, already covered by the include:
dig +short TXT _spf.wavify.com
# "v=spf1 ip4:122.155.0.144 ip4:122.155.0.240 ip4:122.155.0.245 ip4:122.155.0.246 ~all"

Final:

v=spf1 include:_spf.thmail.thnic.co.th ~all

Headers Tell the Truth

A test mail to Gmail → Show original:

spf=pass (… designates 122.155.0.240 as permitted sender)
dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=kpp.in.th

SPF passes via the include (sent from gateway.wavify.com), and since the envelope sender and From: are both @kpp.in.th, DMARC passes too, even at p=reject.

thMail doesn't sign with DKIM (dkim=none), and I'm fine with that. DMARC only needs one aligned pass, and SPF covers it. The only gap is forwarded mail, which is rare for a personal inbox.

Final Records

TypeNameContent
MX@mail.thnic.co.th (1)
TXT@v=spf1 include:_spf.thmail.thnic.co.th ~all
TXT_dmarcv=DMARC1; p=reject; rua=…