The VPS has an address; now the domain has to lead to it. This page edits the DNS zone of in the Infomaniak Manager: the bare name (, nothing in front) and www point at the server, one record at a time, a CAA record says which certificate authorities may issue for the domain, and the mail records either lock the domain against spoofing or protect the mailbox you already have. Everything is checked from the laptop with dig. The certificate itself comes on the next page, and it can only be issued once this DNS is live.
Before you start
You need a login to the Infomaniak Manager (manager.infomaniak.com), the server's IPv4 and IPv6 from the page "Order the VPS at OVH" filled in the values panel, the result of the ping -6 test from the page "Secure the server in the first hour" (it decides the AAAA record), and a terminal on the laptop. dig is already installed on macOS.
$dig +short NS | sortns11.infomaniak.ch. ns12.infomaniak.ch.
Take stock of the current zone
Open manager.infomaniak.com → Domaines → click → Zone DNS in the left menu. Note every record on the bare name (empty Source, or @) or on www, and every MX and TXT record.
On a domain fresh from the registrar, the list often shows only two NS lines (ns11.infomaniak.ch and ns12.infomaniak.ch): nothing to keep. The NS lines have no edit button: that is normal, Infomaniak manages them.
You can list the same thing from the laptop, asking Infomaniak's server directly:
$for t in A AAAA MX TXT CAA; do dig +noall +answer $t @ns11.infomaniak.ch; done$dig +noall +answer www. @ns11.infomaniak.chLower the TTL (only if records already exist)
If the zone holds only the NS lines, skip this step: you create every record below directly with a TTL of 5 min.
Otherwise, for each record on the bare name or on www that you are about to change, edit it and set its TTL to 5 min (300 seconds). Then wait for the old TTL to run out (often one hour) before the real change.
Create the records
Here is everything this page creates. Each line of the table is one record, and gets its own sub-step below.
| # | Type to pick | Source | Value | Only if |
|---|---|---|---|---|
| 1 | A | (empty) | | |
| 2 | AAAA | (empty) | | ping -6 answered on page 3 |
| 3 | CNAME | www | | |
| 4 | CAA | (empty) | Flag 0, Tag issue, letsencrypt.org | |
| 5 | CAA | (empty) | Flag 0, Tag issue, sectigo.com | ZeroSSL allowed in the panel |
| 6 | TXT | (empty) | v=spf1 -all | |
| 7 | DMARC | (set by the form) | v=DMARC1; p=reject; pct=100 |
Every record is created the same way, in Zone DNS:
- Click Ajouter un enregistrement.
- Pick the type in the list.
- Click Suivant.
- Fill the fields given in the sub-step, with the TTL at 5 min.
- Click Enregistrer, then check that the new line shows in the zone list before the next record.
The Source field is what goes in front of the domain. Left empty, it means the domain itself, , nothing in front: that is what you want for every record here except www.
The bare name to the server (A)
Ajouter un enregistrement → A → Suivant → Source: leave empty → address: → TTL 5 min → Enregistrer.
If an A record already exists on the bare name, edit it (do not add a second one) so it points at .
Infomaniak's own server answers at once, without waiting for any propagation:
$dig +short A @ns11.infomaniak.chIPv6 (AAAA), only if ping -6 answered
On the page "Secure the server in the first hour", ping -6 from the server either answered or did not.
- It answered: Ajouter un enregistrement → AAAA → Suivant → Source: leave empty → address:
→ TTL 5 min → Enregistrer. - It did not: create nothing, and delete any AAAA already on the bare name.
$dig +short AAAA @ns11.infomaniak.chThe answer is if you created the record, nothing otherwise.
www (CNAME)
People type www. in front of a domain by reflex; here www is only a redirect to , which Caddy sets up on the next page.
Delete any A or AAAA record on www first, then: Ajouter un enregistrement → CNAME → Suivant → Source: www → target: → TTL 5 min → Enregistrer.
In the zone list, the new line shows the service "Domain Connect": that is normal, nothing to change.
CAA for Let's Encrypt
Ajouter un enregistrement → CAA → Suivant → Source: leave empty → Flag: 0 → Tag: issue → Valeur: letsencrypt.org → TTL 5 min → Enregistrer.
CAA for ZeroSSL
A second CAA record, separate from the first: one value per record. sectigo.com is the name ZeroSSL certificates are issued under.
Ajouter un enregistrement → CAA → Suivant → Source: leave empty → Flag: 0 → Tag: issue → Valeur: sectigo.com → TTL 5 min → Enregistrer.
$dig +short CAA @ns11.infomaniak.ch0 issue "letsencrypt.org" and 0 issue "sectigo.com".
No mail: SPF (TXT)
Nothing sends or receives mail for this domain, so publish that fact. Receiving servers then reject anything claiming to come from .
Otherwise, delete the leftover Infomaniak MX records and any TXT starting with v=spf1: a domain must have only one SPF record.
The Manager has no "SPF" type: SPF is a TXT record. In the type list, SSHFP sits right next to it and has nothing to do with it (it publishes SSH host fingerprints).
Ajouter un enregistrement → TXT → Suivant → Source: leave empty → value: v=spf1 -all → TTL 5 min → Enregistrer.
No mail: DMARC
The Manager has a dedicated DMARC type: use it rather than typing the TXT by hand.
Ajouter un enregistrement → DMARC → Suivant → keep the policy at reject → TTL 5 min → Enregistrer.
It writes v=DMARC1; p=reject; pct=100 on _dmarc.. In the zone list, the line shows as "TXT (DMARC)" with the service "Messagerie": that is normal.
Optional extras
The page works without these three records, and the check script only notes their absence. Add them if you want every door closed.
- CAA iodef: CAA → Source empty → Flag
0→ Tagiodef→ Valeurmailto:followed by, with no space. If the Tag list does not offeriodef, skip it.
- Null MX: MX → Source empty → priority
0→ target.(a single dot). - DKIM revocation: TXT → Source
*._domainkey→ valuev=DKIM1; p=.
Check from the laptop
Infomaniak's own server first: it shows the zone as soon as you click Enregistrer, with no propagation delay.
$dig +short A @ns11.infomaniak.ch$dig +short CNAME www. @ns11.infomaniak.ch$dig +short TXT @ns11.infomaniak.ch$dig +short TXT _dmarc. @ns11.infomaniak.chThen ask two public resolvers what the world now sees. The first run may show old answers until the old TTL runs out.
$dig +short A @1.1.1.1$dig +short CNAME www. @1.1.1.1.
$dig +short CAA @1.1.1.1 | grep letsencrypt | tr -d '\042'0 issue letsencrypt.org
$dig +short TXT _dmarc. @1.1.1.1 | tr -d '\042' | cut -d';' -f1v=DMARC1
If you created the AAAA, it answers too:
$dig +short AAAA @1.1.1.1Repeat with @9.9.9.9 in place of @1.1.1.1: two resolvers run by different operators agreeing is a good sign the change is out.
If dig still shows the old address
In order of likelihood:
- The old TTL has not run out yet. Ask Infomaniak directly with
@ns11.infomaniak.ch: if that shows the new value, the zone is right and waiting fixes the rest. - Your Mac cached the old answer (without
@server). Flush it withsudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder. - Two records exist on the same name: the old one was added to, not replaced. Look again at the zone.
@ns11.infomaniak.chshows the old value: the edit was not saved (Enregistrer), or you edited the zone of another domain.- dig prints lines starting with
\#for CAA: the macOS dig is too old to decode the type.brew install bindgives a current one.
Turn on DNSSEC
In the Manager, open → DNSSEC → activate. Infomaniak generates the keys, signs the zone and sends the DS record to the registry of the TLD.
The DS record can take a few hours, sometimes up to 48, to reach the registry. Then a validating resolver marks its answers as authenticated (the ad flag):
$dig +dnssec +noall +comments A @1.1.1.1 | grep -o 'flags: qr rd ra ad'flags: qr rd ra ad
Reverse DNS at OVH (optional)
Make the server's IP answer with when looked up backwards. In the OVH control panel: Network → Public IP addresses → ... next to → Modify the reverse → . Do the same for if it is listed.
Raise the TTL back
Once the checks pass and the site works on the next page, set the TTL of the records you created or changed to 1 h (3600 seconds).
Done
and www lead to the VPS (in IPv6 too if ping -6 answered), and only the certificate authorities you listed may issue certificates for them. Mail claiming to come from the domain is rejected. The zone is signed.
Next page: Serve the site with Caddy and HTTPS. Caddy requests the certificate for both names on its first start, which works only because this DNS is live.