kpp.in.th (short for the k-pp logo) is registered at THNIC, which also gives one free mailbox on the domain through thMail. I wanted DNS on Cloudflare and mail that lands in Gmail's inbox.
DNS to Cloudflare
- Cloudflare → Add a domain → note the two assigned nameservers.
- THNIC portal → ตั้งค่า DS: delete any old DS first. A stale DS with new nameservers causes
SERVFAIL. - THNIC portal → ตั้งค่า NS: set the Cloudflare pair.
Check the delegation at the registry:
dig NS kpp.in.th @a.thains.co.th +norec
thMail
One mailbox, 1 GB, free for a year. I took ponpawit@kpp.in.th. The only required record is MX @ → mail.thnic.co.th.
SPF: Trim It
The starting record was:
v=spf1 +a +mx include:_spf.thmail.thnic.co.th ~all
a→ my apex is proxied, so this authorized Cloudflare's edge IPs to send as me.mx→122.155.0.144, already covered by the include:
dig +short TXT _spf.wavify.com # "v=spf1 ip4:122.155.0.144 ip4:122.155.0.240 ip4:122.155.0.245 ip4:122.155.0.246 ~all"
Final:
v=spf1 include:_spf.thmail.thnic.co.th ~all
Headers Tell the Truth
A test mail to Gmail → Show original:
spf=pass (… designates 122.155.0.240 as permitted sender) dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=kpp.in.th
SPF passes via the include (sent from gateway.wavify.com), and since the envelope sender and From: are both @kpp.in.th, DMARC passes too, even at p=reject.
thMail doesn't sign with DKIM (dkim=none), and I'm fine with that. DMARC only needs one aligned pass, and SPF covers it. The only gap is forwarded mail, which is rare for a personal inbox.
Final Records
| Type | Name | Content |
|---|---|---|
| MX | @ | mail.thnic.co.th (1) |
| TXT | @ | v=spf1 include:_spf.thmail.thnic.co.th ~all |
| TXT | _dmarc | v=DMARC1; p=reject; rua=… |