Point the domain at the server (Infomaniak DNS)

Your domain and its www answer with the VPS in IPv4 and IPv6, only Let's Encrypt (and optionally ZeroSSL) may issue certificates for it, and nobody can send mail in its name — or your Infomaniak mailbox keeps working, with DMARC on top. Clicks in the Manager, checks with dig.

beginner~20 min hands-on
#dns#infomaniak#caa#dmarc#spf#dnssec#ipv6

Not validated end to end yet — be the first.Report a problem

Draft — not yet run end to end. This page was written but its author has not yet run it on a real machine. Commands may be wrong: read before you run, and tell us what breaks.

The gistWho answers, and with what
Infomaniak
OVH
?A · AAAA ?HTTPS (next page)reads CAA
A visitorhttps://
ResolverISP · 1.1.1.1 · 9.9.9.9
DNS zonens11 / ns12.infomaniak.ch
Your VPS
Let's EncryptACME CA

A visitor's resolver asks the Infomaniak zone where ${DOMAIN} lives and gets the VPS's addresses. The same zone tells certificate authorities who may issue for the domain, and mail servers whether a message in its name is genuine.

The VPS has an address; now the domain has to lead to it. This page edits the DNS zone of in the Infomaniak Manager: the bare name (, nothing in front) and www point at the server, one record at a time, a CAA record says which certificate authorities may issue for the domain, and the mail records either lock the domain against spoofing or protect the mailbox you already have. Everything is checked from the laptop with dig. The certificate itself comes on the next page, and it can only be issued once this DNS is live.

Before you start

You need a login to the Infomaniak Manager (manager.infomaniak.com), the server's IPv4 and IPv6 from the page "Order the VPS at OVH" filled in the values panel, the result of the ping -6 test from the page "Secure the server in the first hour" (it decides the AAAA record), and a terminal on the laptop. dig is already installed on macOS.

Check
$dig +short NS  | sort
Expected output
ns11.infomaniak.ch.
ns12.infomaniak.ch.

Take stock of the current zone

Open manager.infomaniak.com → Domaines → click → Zone DNS in the left menu. Note every record on the bare name (empty Source, or @) or on www, and every MX and TXT record.

On a domain fresh from the registrar, the list often shows only two NS lines (ns11.infomaniak.ch and ns12.infomaniak.ch): nothing to keep. The NS lines have no edit button: that is normal, Infomaniak manages them.

You can list the same thing from the laptop, asking Infomaniak's server directly:

Mac
$for t in A AAAA MX TXT CAA; do dig +noall +answer $t @ns11.infomaniak.ch; done
$dig +noall +answer www. @ns11.infomaniak.ch

Lower the TTL (only if records already exist)

If the zone holds only the NS lines, skip this step: you create every record below directly with a TTL of 5 min.

Otherwise, for each record on the bare name or on www that you are about to change, edit it and set its TTL to 5 min (300 seconds). Then wait for the old TTL to run out (often one hour) before the real change.

Create the records

Here is everything this page creates. Each line of the table is one record, and gets its own sub-step below.

#Type to pickSourceValueOnly if
1A(empty)
2AAAA(empty)ping -6 answered on page 3
3CNAMEwww
4CAA(empty)Flag 0, Tag issue, letsencrypt.org
5CAA(empty)Flag 0, Tag issue, sectigo.comZeroSSL allowed in the panel
6TXT(empty)v=spf1 -all
7DMARC(set by the form)v=DMARC1; p=reject; pct=100

Every record is created the same way, in Zone DNS:

  1. Click Ajouter un enregistrement.
  2. Pick the type in the list.
  3. Click Suivant.
  4. Fill the fields given in the sub-step, with the TTL at 5 min.
  5. Click Enregistrer, then check that the new line shows in the zone list before the next record.

The Source field is what goes in front of the domain. Left empty, it means the domain itself, , nothing in front: that is what you want for every record here except www.

The bare name to the server (A)

Ajouter un enregistrement → A → Suivant → Source: leave empty → address: → TTL 5 min → Enregistrer.

If an A record already exists on the bare name, edit it (do not add a second one) so it points at .

Infomaniak's own server answers at once, without waiting for any propagation:

Check
$dig +short A  @ns11.infomaniak.ch
Expected output

IPv6 (AAAA), only if ping -6 answered

On the page "Secure the server in the first hour", ping -6 from the server either answered or did not.

  • It answered: Ajouter un enregistrement → AAAA → Suivant → Source: leave empty → address: → TTL 5 min → Enregistrer.
  • It did not: create nothing, and delete any AAAA already on the bare name.
Mac
$dig +short AAAA @ns11.infomaniak.ch

The answer is if you created the record, nothing otherwise.

www (CNAME)

People type www. in front of a domain by reflex; here www is only a redirect to , which Caddy sets up on the next page.

Delete any A or AAAA record on www first, then: Ajouter un enregistrement → CNAME → Suivant → Source: www → target: → TTL 5 min → Enregistrer.

In the zone list, the new line shows the service "Domain Connect": that is normal, nothing to change.

CAA for Let's Encrypt

Ajouter un enregistrement → CAA → Suivant → Source: leave empty → Flag: 0 → Tag: issue → Valeur: letsencrypt.org → TTL 5 min → Enregistrer.

CAA for ZeroSSL

A second CAA record, separate from the first: one value per record. sectigo.com is the name ZeroSSL certificates are issued under.

Ajouter un enregistrement → CAA → Suivant → Source: leave empty → Flag: 0 → Tag: issue → Valeur: sectigo.com → TTL 5 min → Enregistrer.

Mac
$dig +short CAA @ns11.infomaniak.ch
One line per CAA record: 0 issue "letsencrypt.org" and 0 issue "sectigo.com".

No mail: SPF (TXT)

Nothing sends or receives mail for this domain, so publish that fact. Receiving servers then reject anything claiming to come from .

Otherwise, delete the leftover Infomaniak MX records and any TXT starting with v=spf1: a domain must have only one SPF record.

The Manager has no "SPF" type: SPF is a TXT record. In the type list, SSHFP sits right next to it and has nothing to do with it (it publishes SSH host fingerprints).

Ajouter un enregistrement → TXT → Suivant → Source: leave empty → value: v=spf1 -all → TTL 5 min → Enregistrer.

No mail: DMARC

The Manager has a dedicated DMARC type: use it rather than typing the TXT by hand.

Ajouter un enregistrement → DMARC → Suivant → keep the policy at reject → TTL 5 min → Enregistrer.

It writes v=DMARC1; p=reject; pct=100 on _dmarc.. In the zone list, the line shows as "TXT (DMARC)" with the service "Messagerie": that is normal.

Optional extras

The page works without these three records, and the check script only notes their absence. Add them if you want every door closed.

  • CAA iodef: CAA → Source empty → Flag 0 → Tag iodef → Valeur mailto: followed by , with no space. If the Tag list does not offer iodef, skip it.
  • Null MX: MX → Source empty → priority 0 → target . (a single dot).
  • DKIM revocation: TXT → Source *._domainkey → value v=DKIM1; p=.

Check from the laptop

Infomaniak's own server first: it shows the zone as soon as you click Enregistrer, with no propagation delay.

Mac
$dig +short A @ns11.infomaniak.ch
$dig +short CNAME www. @ns11.infomaniak.ch
$dig +short TXT @ns11.infomaniak.ch
$dig +short TXT _dmarc. @ns11.infomaniak.ch

Then ask two public resolvers what the world now sees. The first run may show old answers until the old TTL runs out.

Check
$dig +short A  @1.1.1.1
Expected output
Check
$dig +short CNAME www. @1.1.1.1
Expected output
.
Check
$dig +short CAA  @1.1.1.1 | grep letsencrypt | tr -d '\042'
Expected output
0 issue letsencrypt.org
Check
$dig +short TXT _dmarc. @1.1.1.1 | tr -d '\042' | cut -d';' -f1
Expected output
v=DMARC1

If you created the AAAA, it answers too:

Mac
$dig +short AAAA @1.1.1.1

Repeat with @9.9.9.9 in place of @1.1.1.1: two resolvers run by different operators agreeing is a good sign the change is out.

If dig still shows the old address

In order of likelihood:

  • The old TTL has not run out yet. Ask Infomaniak directly with @ns11.infomaniak.ch: if that shows the new value, the zone is right and waiting fixes the rest.
  • Your Mac cached the old answer (without @server). Flush it with sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder.
  • Two records exist on the same name: the old one was added to, not replaced. Look again at the zone.
  • @ns11.infomaniak.ch shows the old value: the edit was not saved (Enregistrer), or you edited the zone of another domain.
  • dig prints lines starting with \# for CAA: the macOS dig is too old to decode the type. brew install bind gives a current one.

Turn on DNSSEC

In the Manager, open → DNSSEC → activate. Infomaniak generates the keys, signs the zone and sends the DS record to the registry of the TLD.

The DS record can take a few hours, sometimes up to 48, to reach the registry. Then a validating resolver marks its answers as authenticated (the ad flag):

Check
$dig +dnssec +noall +comments A  @1.1.1.1 | grep -o 'flags: qr rd ra ad'
Expected output
flags: qr rd ra ad

Reverse DNS at OVH (optional)

Make the server's IP answer with when looked up backwards. In the OVH control panel: Network → Public IP addresses → ... next to → Modify the reverse → . Do the same for if it is listed.

Raise the TTL back

Once the checks pass and the site works on the next page, set the TTL of the records you created or changed to 1 h (3600 seconds).

Done

and www lead to the VPS (in IPv6 too if ping -6 answered), and only the certificate authorities you listed may issue certificates for them. Mail claiming to come from the domain is rejected. The zone is signed.

Next page: Serve the site with Caddy and HTTPS. Caddy requests the certificate for both names on its first start, which works only because this DNS is live.

Did everything work?

If you followed this page to the end on a real machine, say so. Your validation is dated and records your stack, so the next reader on the same path knows it still works.

This copy is read-only. To report that it works, or that it does not, open an issue

Only your stack choices are recorded, never your values. The pseudonym stays on this browser.