Situatie: u heeft uw domein getest op internet.nl en scoort 67% of lager. Er zijn rode en oranje vinkjes waar u niet direct een actie op weet.
Oplossing: werk de categorieën systematisch af. Website (moderne encryptie + beveiligde headers): zet bij uw hoster HSTS, CSP, X-Content-Type-Options en X-Frame-Options aan, activeer TLS 1.2/1.3 en schakel TLS 1.0/1.1 uit. Forceer HTTPS-redirect. Mail (SPF, DKIM, DMARC, DANE, STARTTLS): bij uw DNS-provider voegt u een SPF-record toe dat alleen uw bekende verzenders toestaat (Odoo-SMTP, Microsoft 365, Mailgun, etc.). DKIM activeert u per mailprovider en publiceert u als TXT-record. DMARC zet u minimaal op p=quarantine, bij voorkeur p=reject. Voor DANE hebt u een TLSA-record nodig. Connectie: laat uw hoster IPv6 (AAAA-records) en DNSSEC inschakelen — bij de meeste Europese hosters is dit een tickbox.
Stappenplan:
- Start met DNSSEC en IPv6 — grootste 'quick wins', vrijwel geen risico.
- Dan SPF + DKIM + DMARC (begin met
p=nonevoor monitoring, verhoog naarrejectna 4 weken testen). - Dan STARTTLS en DANE op uw mailserver.
- Afsluitend web-security headers en TLS-hardening.
Tip: laat het niet bij 100% — plan ieder kwartaal een hertest. Providers wijzigen configuraties (bv. nieuwe mailserver-IP), en uw SPF-record kan stilletjes breken. Een gecrashte DMARC kan betekenen dat uw mails op de spam belanden zonder dat u het merkt. Rapporteer met DMARC-aggregaten (gratis bij bv. Postmark of Dmarcian) om inzicht te houden in wie er namens uw domein probeert te versturen.
Situation: you have tested your domain on internet.nl and score 67% or lower. There are red and orange checkmarks for which you don't immediately know an action.
Solution: work through the categories systematically. Website (modern encryption + secure headers): at your host, enable HSTS, CSP, X-Content-Type-Options and X-Frame-Options, activate TLS 1.2/1.3 and disable TLS 1.0/1.1. Force an HTTPS redirect. Mail (SPF, DKIM, DMARC, DANE, STARTTLS): at your DNS provider, add an SPF record that only allows your known senders (Odoo SMTP, Microsoft 365, Mailgun, etc.). Activate DKIM per mail provider and publish it as a TXT record. Set DMARC to at least p=quarantine, preferably p=reject. For DANE you need a TLSA record. Connection: have your host enable IPv6 (AAAA records) and DNSSEC — at most European hosts this is a tickbox.
Step-by-step plan:
- Start with DNSSEC and IPv6 — the biggest 'quick wins', virtually no risk.
- Then SPF + DKIM + DMARC (start with
p=nonefor monitoring, raise torejectafter 4 weeks of testing). - Then STARTTLS and DANE on your mail server.
- Finally web-security headers and TLS hardening.
Tip: don't stop at 100% — schedule a retest every quarter. Providers change configurations (e.g. a new mail server IP), and your SPF record can silently break. A broken DMARC can mean your emails end up in spam without you noticing. Report with DMARC aggregates (free at e.g. Postmark or Dmarcian) to keep insight into who is trying to send on behalf of your domain.