todo

GPG Best Practice

GPG default settings need a bit of adjustment to use the recommended hashing and encryption algorithms.

Use RSA with 4096 bits or EC key. Transitioning from one key to another can be done with a transition statement signed by old and new keys (the new key might not really be needed in that signing? What benefit does it provide?)

Edit or create the gpg.conf file and add this towards the end:

Specifying a domain does not receive or send email with DNS (and SPF for good measure)

There are a number of times when a domain is being used for something else other than web sites and emails. It should never send email, nor should it ever need to receive it because it does not generate abuse.

Telling everyone else about your choice never to send email from this domain means that it has less chance of being abused in a Joe Job, and you have less to worry about when it comes to that domain. It might even save a few people on the internet from seeing a couple more spam messages.

Subscribe to RSS - todo