#!/bin/bash
# =============================================================================
# DMARC Record
# Targets: Ubuntu 22.04/24.04/26.04, Trisquel 11/12/13
# Requires: PowerDNS running, domain zone created
# =============================================================================
set -euo pipefail
# --- Configuration ---
domain_name="tuxmail.io"
# --- Debugging helpers ---
LOG_FILE="/var/log/dmarc-install.log"
PASS_COUNT=0
FAIL_COUNT=0
log() {
echo "[$(date '+%Y-%m-%d %H:%M:%S')] $*" | tee -a "$LOG_FILE"
}
die() {
log "FATAL: $*" >&2
exit 1
}
check() {
local desc="$1"
local cmd="$2"
if eval "$cmd" &>/dev/null; then
log " [PASS] $desc"
((PASS_COUNT++)) || true
else
log " [FAIL] $desc"
((FAIL_COUNT++)) || true
fi
}
verify() {
log "--- VERIFICATION ---"
}
# =============================================================================
# Section 1: DMARC Record
# =============================================================================
section_dmarc() {
log "=== SECTION: DMARC Record ==="
if pdnsutil list-zone "$domain_name" 2>/dev/null | grep -q "v=DMARC1"; then
log "DMARC record already exists, skipping"
else
pdnsutil add-record "$domain_name" _dmarc TXT '"v=DMARC1; p=reject; pct=100; rua=mailto:dmarc-reports@'"$domain_name"'"'
log "DMARC record added"
fi
verify
check "DMARC record in zone" "pdnsutil list-zone '$domain_name' | grep -q 'v=DMARC1'"
check "DMARC resolvable locally" "dig @127.0.0.1 _dmarc.$domain_name TXT +short | grep -q 'v=DMARC1'"
check "DMARC policy is reject" "dig @127.0.0.1 _dmarc.$domain_name TXT +short | grep -q 'p=reject'"
}
# =============================================================================
# Main
# =============================================================================
ALL_SECTIONS=(
section_dmarc
)
if [ $# -gt 0 ]; then
for section in "$@"; do
case "$section" in
section_*)
log "Running: $section"
"$section"
;;
all)
for s in "${ALL_SECTIONS[@]}"; do
log "Running: $s"
"$s"
done
;;
*)
die "Unknown section: $section"
;;
esac
done
else
for s in "${ALL_SECTIONS[@]}"; do
log "Running: $s"
"$s"
done
fi
# --- Summary ---
log "=============================================="
log " PASSED: $PASS_COUNT"
log " FAILED: $FAIL_COUNT"
log "=============================================="
if [ "$FAIL_COUNT" -gt 0 ]; then
log "WARNING: Some checks failed. Review [FAIL] entries above."
log "Full log: $LOG_FILE"
exit 1
else
log "All checks passed."
fi
log "=== DMARC configuration complete ==="
