Email security
How can I change email DNS records without breaking legitimate mail?
Short answer: Inventory every sending service, save your current records and verify authentication before tightening your policy.
The full answer
List your mailbox provider, newsletters, billing tools, support desk and any website that sends messages. A forgotten service is a common reason legitimate messages fail after a policy change. Get the exact SPF and DKIM instructions from each provider rather than copying an unrelated example.
Save the current DNS values and identify who controls your DNS. Add or update records carefully: the host field may expect _dmarc rather than a full domain, and an SPF change normally means editing the existing record rather than adding another one. Follow the DNS host’s instructions.
Start DMARC in monitoring mode, inspect aggregate reports and test actual messages from each service. Review the visible From domain and the Authentication-Results header for alignment. Move to enforcement only when you understand the remaining failures, and have a rollback plan.
DNS caches mean changes are not visible everywhere immediately. Recheck authoritative records and multiple resolvers after the relevant TTL. A green publication check is useful evidence, but it is not an end-to-end delivery test.
