Skip to content

add OSV-1, Email sending and receiving - #1840

Merged
pawel-kow merged 2 commits into
Domain-Connect:masterfrom
ankrstak:add-osv-1-email
Sep 14, 2026
Merged

pawel-kow merged 2 commits into
Domain-Connect:masterfrom
ankrstak:add-osv-1-email

Conversation

@ankrstak

@ankrstak ankrstak commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

Description

New template for OSV-1 (osv-1.com), service email: the DNS records an organization needs to send and receive its email through OSV-1 (Resend / Amazon SES underneath) on the hostname it chooses — typically a subdomain such as notify.example.com, apex allowed.

  • sending: DKIM TXT at resend._domainkey (p=%dkim%), bounce-path MX at send (feedback-smtp.%region%.amazonses.com), SPFM at send (include:amazonses.com), and the sending-host CNAME rsendsend.forge.rmta.net that the email provider now requires for new domains and checks directly (fixed target, as in update SendBeam, SendBeam sending domain (version 2) #1827)
  • receiving: MX at the host itself (inbound-smtp.%region%.amazonaws.com) — requested only for domains that receive mail
  • dmarc: fixed v=DMARC1; p=none; with Prefix matching, essential: OnApply

Variables are scoped narrowly: region only varies the SES region inside fixed hostnames; dkim is the key material after a fixed p= prefix. Synchronous flow with signed requests (syncPubKeyDomain osv-1.com, key published at _dck1.osv-1.com); syncRedirectDomain osv-1.com (redirect_uri lives on app.osv-1.com).

Type of change

Please mark options that are relevant.

  • New template
  • Bug fix (non-breaking change which fixes an issue in the template)
  • New feature (non-breaking change which adds functionality to the template)
  • Breaking change (fix or feature that would cause existing template behavior to be not backward compatible)

How Has This Been Tested?

Please mark the following checks done

  • Template functionality checked using Online Editor
  • Template file name follows the pattern <providerId>.<serviceId>.json
  • resource URL provided with logoUrl is actually served by a webserver

Checklist of common problems

Mark all the checkboxes after conducting the check. Comment on any point which is not fulfilled.
See Template Quality Guidelines for details and rationale on each rule.

  • syncPubKeyDomain is set — this is mandatory; omitting it requires explicit justification in the PR description or the PR will be rejected
  • warnPhishing is not set alongside syncPubKeyDomain — the two must not appear together
  • syncRedirectDomain is set whenever the template uses redirect_uri in the synchronous flow
  • no TXT record contains SPF content ("v=spf1 ...") — use the SPFM record type instead
  • txtConflictMatchingMode is set on every TXT record that must be unique per label or content prefix (e.g. DMARC)
  • no variable is used as a bare full record value (e.g. @ TXT "%foo%") unless necessary — prefer @ TXT "service-foo=%foo%"; if bare, justify in the PR description
  • no bare variable is used as the full host label — the non-variable parts are fixed to limit misuse (e.g. %dkimkey%._domainkey, not %dkimhost%); if bare, justify in the PR description
  • no variable is used in the host field to create a subdomain — use the host parameter or multiInstance instead
  • %host% does not appear explicitly in any host attribute
  • essential is set to OnApply on records the end user may need to modify or remove without breaking the template (e.g. DMARC)

Online Editor test results

Editor test link(s):

🤖 Generated with Claude Code

New template for OSV-1 (osv-1.com), service "email": the DNS records an
organization needs to send and receive its email through OSV-1 (Resend /
Amazon SES underneath) on the hostname it chooses.

Groups: sending (DKIM TXT at resend._domainkey, bounce MX at send, SPFM at
send), receiving (MX at the host itself), dmarc (fixed v=DMARC1; p=none;
with Prefix matching, essential OnApply). Variables are scoped narrowly:
region only varies the SES region inside fixed hostnames; dkim is the key
material after a fixed "p=" prefix.

syncPubKeyDomain osv-1.com (key published at _dck1.osv-1.com),
syncRedirectDomain osv-1.com, synchronous flow, hostRequired false.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

PR Description Check Passed

All required sections are filled in correctly.

Details
  OK  Type of change: 1/4 checkboxes ticked
  OK  How Has This Been Tested?: all 3 checkboxes ticked
  OK  Checklist of common problems: 10/10 checkboxes ticked
  OK  Online Editor test results: 3 link(s) found
  OK  Template coverage: all 1 template(s) covered
Labels to remove: Checklist of common problems not complete, Forged editor links, PR description incomplete, Test links missing

PR description check PASSED

@github-actions

Copy link
Copy Markdown

JSON Filename Check Passed

@github-actions

Copy link
Copy Markdown

JSON Schema Validation Passed

@github-actions github-actions Bot added the automerge-possible Label indicating, that restrictive linter checks all pass. For now it's PoC. label Sep 13, 2026
@github-actions

Copy link
Copy Markdown

Linter OK

osv-1.com.email.json

Level Code Note

github-actions[bot]
github-actions Bot previously approved these changes Sep 13, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Linter passed all checks — approving for auto-merge.

Resend now requires a CNAME rsend → send.forge.rmta.net for new sending
domains and checks its target directly (the same record SendBeam added in
Domain-Connect#1827); without it a domain configured through the template would never
verify at the provider. Added to the sending group with the provider's fixed
target; nothing else changes. Editor tests re-run against this file.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Linter passed all checks — approving for auto-merge.

@pawel-kow
pawel-kow added this pull request to the merge queue Sep 14, 2026
Merged via the queue into Domain-Connect:master with commit a6f0fcf Sep 14, 2026
8 checks passed
@github-actions

Copy link
Copy Markdown

Thanks @ankrstak for contributing to the template. 🎉

This template has been reviewed and merged by @pawel-kow. 🙌

This template repository and its review process are maintained by independent individuals in their spare time, not as part of a paid role. If you or your company benefit from this protocol and its tools, please show your appreciation by buying a beer for @pawel-kow: https://github.com/sponsors/pawel-kow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automerge-possible Label indicating, that restrictive linter checks all pass. For now it's PoC.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants