A custom domain email threat model is three families: someone else publishes MX (DNS hijack or leftover confusion), someone else AUTH as you (SMTP theft), and someone floods or harvests a published alias (abuse). Controls: registrar locks, exclusive MX you can screenshot, env secrets not in git, named aliases, HOLD unknown, rotate on offboard. MailerZ is not SOC 2. The security page is the honest control set. No inboxing percentage.
Quick answer for custom domain email threat model
If they own NS, they own inbound. Registrar security is email security.
If they own SMTP secrets, they send as you. Env and rotate.
If they have a published string, they can flood it. Disable and HOLD.
RFC 1035 and 5321 are the physics.
Leftover MX is a hijack you did to yourself.
Start free and screenshot MX as a baseline.
Authoritative mail transport is defined in IETF RFC 5321 — Simple Mail Transfer Protocol. Product path: security, features, and aliases and catch-all.
User problem and decision criteria
Decision criteria: who can change NS, who can see SMTP, which strings are public.
Website builders that also do DNS are a concentrated risk.
Shared registrar logins are a threat.
Agencies must return NS access on offboard.
No HIPAA.
No open relay “decoy.”
Catch-all increases abuse surface.
Public personal names on a domain increase guessability.
Technical mail flow
Hijack: NS or MX change → mail to attacker.
Theft: AUTH → send as alias.
Abuse: inbound firehose to a destination.
Detection: two-resolver MX watch, AUTH anomalies, HOLD/history volume.
Response: revert MX, rotate SMTP, disable alias.
Step-by-step setup / decision path
- Registrar lock + 2FA.
- Baseline MX screenshot. Exclusive.
- SMTP in env. Gitignore.
- Named aliases. HOLD.
- Offboard rotate.
- Disable abused strings.
- Watch two resolvers after changes.
- Write the threat model in one page.
Classify the next failure before a second DNS edit.
HOLD unknown unless you wrote a FORWARD reason.
Quote live pricing before promising alias counts.
Failure modes and proof
Unlocked registrar.
Leftover MX.
Committed .env.
Catch-all FORWARD.
Shared registrar email.
Unrotated contractor SMTP.
Invented SOC 2.
MX flap as “hardening.”
Header rewrite.
Self-send as monitoring.
No disable path.
Inboxing as security KPI.
MailerZ workflow and product boundary
MailerZ is custom-domain aliasing and forwarding with optional paid send-as. Secuno LLC operates mailerz.net. The app is mail.mailerz.net. Not Workspace, not IMAP, not an open relay, not a campaign ESP.
Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME stay intact. Exclusive MX. Hold unknown on Free. Copy SMTP host, port, and TLS or STARTTLS from the dashboard when you send.
Free: one domain, three aliases, one seat, fourteen-day store, fifty outgoing a month, no send-as. Solo forty dollars a year, fifteen aliases, ninety-day store, one hundred outgoing, five send-as per hour. Starter eight or eighty. Business nineteen or one hundred ninety. Agency thirty-nine or three hundred ninety. Quote pricing. No SOC 2, ISO, HIPAA, SLA, or inboxing percentage.
Cost, alternatives, and trade-offs
A hijacked MX is a business-ending week.
Registrar lock is cheap.
Secret leaks are reputation.
Catch-all is attention tax.
Agencies: threat model in kickoff.
Paid store is not a SIEM.
No fake certs.
Disable is cheaper than a new domain.
Operational depth
Put registrar 2FA on a person who is not the only founder laptop.
Agencies: least privilege on Route 53 and Cloudflare.
Monitor public MX after every launch. Leftovers come back.
Staging secrets ≠ production secrets.
HOLD is an abuse control, not just convenience.
Security page for enterprise questions. Do not mint ISO in Slack.
If NS changes unexpectedly, treat it as P1. History may show a new hop or emptiness.
Probe after you reclaim MX.
Vendor list per alias for abuse.
No legal advice. Counsel for real incidents.
Quarterly access review.
Quote plans; more seats can mean more humans to offboard.
Field notes for a custom domain email threat model
If they own nameservers, they own inbound. Registrar lock and 2FA are email controls. A shared registrar login in a founder group chat is a threat, not a convenience. Put 2FA on a person who is not the only laptop. Agencies must return NS access on offboard. An unlocked registrar is a hijack waiting for a tired click.
Leftover MX is a hijack you performed on yourself. Old Google or builder hosts still answering means some senders never reach MailerZ. Two owners in public is a split. Delete leftovers. Demoting priority is not a control. Screenshot the exclusive set as a baseline you can compare after every launch.
SMTP secrets are outbound identity. Env files, platform vaults, never git. Never Slack. Rotate when people leave. A contractor’s leftover WordPress plugin is how you send phishing as hello@. Copy dashboard host, port, and TLS or STARTTLS. Do not invent ports. Free has no send-as, so a leaked Free “secret” should not exist—if someone made one up, they are on the wrong plan.
Published aliases are abuse surface. One shop, one string, so disable is easy. HOLD unknown so dictionary guesses do not train Gmail. Catch-all FORWARD increases the surface and the junk. Role aliases need a replacement window before disable. Shop aliases can die immediately.
Detection is boring: two public resolvers after every DNS change, hop history volume, AUTH failures, held-list spikes. If NS changed and you did not do it, treat it as P1. History may show a new hop or emptiness. Reclaim MX, then probe from a third mailbox.
Do not rewrite Header From to “fix” spoof. MailerZ will not. Spoof at receivers is a receiver report, not a From rewrite. Intact From is the contract that keeps real customers visible. Envelope SRS is the hop’s SPF story. See IETF RFC 7208 — Sender Policy Framework (SPF) for SPF on the envelope domain, not as a hijack myth.
Website builders that also host DNS concentrate risk. One password resets the site and the MX. Know which NS are public. Edit that panel only. A pretty zone on the unused registrar is fiction and a false sense of control.
Staging secrets must not be production secrets. Preview deploys that use production SMTP are scheduled abuse. Rate-limit apps so a loop cannot look like a stolen credential burst against Solo’s five send-as per hour.
Enterprise reviewers will ask for SOC 2, ISO, HIPAA. MailerZ does not claim them. Send security. Do not mint badges in a threat-model slide. That is the enterprise-friendly answer: honest controls, no stickers.
Inboxing is not a security KPI. A green checker is not a hijack detector. Exclusive MX and a stored 550 are evidence. A folder after 250 is a filter. Do not mix them in the model.
Offboard is part of the model. Revoke SMTP, seats, and NS. Unpaid leftover MX with your hosts still published is you operating their inbound after the contract ended. Date the exit. Confirm public MX.
Kids and personal domains: catch-all FORWARD is a safety issue as well as a junk issue. HOLD plus named aliases is the professional personal setup. Do not publish every child’s first name if you do not want those aliases guessed.
Write the model on one page: NS owners, SMTP secret owners, public alias list, disable path, leftover-MX check, store clocks (fourteen Free, ninety paid). Review quarterly when people leave. Counsel for real incidents. This article is not legal advice.
Open relay “honeypots” are not a control. Unauthorized send is 550 5.7.1. Do not ask MailerZ to accept any From. That is the opposite of a threat model.
Practice reclaim: change MX on a rehearsal domain, watch two resolvers, probe, change back. The team should not learn NS panic on a production restaurant domain.
Worked scenarios for the email threat model
Registrar login in a shared inbox. A phishing mail resets NS to an attacker zone. Public MX moves. Your MailerZ history goes quiet. Customers still send. Mail goes elsewhere. Detection is two resolvers after every week and after every vendor change. Response is registrar recover, 2FA, exclusive MX restore, probe, then tell customers some mail hit the attacker. You cannot pull it back. That sentence is the model.
Contractor WordPress still has production SMTP. They are gone. A plugin update or a stolen laptop sends as hello@. Recipients see your brand. Rotate the secret in the dashboard. Update env. Review history for volume you did not intend. Free should not have had send-as. If AUTH worked, you were on paid and you left a secret behind.
Shop alias harvested. Inbound firehose into a founder Gmail. Disable shop-x@. Create shop-x2@ only for vendors you still need. Update those vendors. HOLD unknown so cousins do not arrive. Do not flap MX. Do not FORWARD to watch the abuse. That trains junk and keeps the firehose.
Leftover Google MX after a cancelled seat. Half of inbound never hits MailerZ. You call it mysterious. Two resolvers call it leftover MX. Self-hijack. Delete. Demote is not delete. Screenshot the exclusive set as the new baseline.
Staging Vercel env pointed at production SMTP. A preview bot mails customers. Cap heat. Reputation heat. Staging uses a sink or a dedicated test alias. Production secrets are not preview secrets.
Someone proposes rewriting Header From so spoof “looks less real.” You refuse. MailerZ will not. Spoof is a receiver problem. Intact From is how real people stay visible. Envelope SRS is the hop. Mixing those in a panic makes the threat worse.
Builder DNS plus site in one password. Reset email goes to an old personal Gmail. Attacker takes NS and the site. Split registrar and DNS access. 2FA. Recovery mailbox that is not the same as the public hello@. Document it offline.
Agency offboard without NS return. You still can publish MX. That is residual control you should not have. Return access. Confirm public NS. Residual control is a threat to the client and a liability to you.
Enterprise asks for SOC 2 during a threat-model workshop. You open /security and say no. You list registrar lock, exclusive MX, env SMTP, HOLD, store clocks, seat offboard. You do not print a badge. If they require a certified host, they need a different product.
Catch-all FORWARD on a public figure domain. Harassment arrives. HOLD was the control. Named press@ and booking@. Disable leaked names. Catch-all is not a monitoring strategy. It is an abuse amplifier.
Loop in an app hits five send-as per hour and retries like a bot. Looks like stolen credentials. Rate-limit the app. Caps are published. Upgrade or slow down. Do not treat MailerZ as an open relay to clear a queue.
Quarterly access review finds an ex-employee still has a MailerZ seat and registrar recovery codes. Offboard is part of the model. Seats, SMTP, NS, password manager. The same day they leave, not the next quarter if you can help it.
Kids’ personal domain with catch-all so they can invent addresses. Scanners and creeps invent too. HOLD plus parent-chosen names. This is a safety scenario, not a cute DNS trick.
Practice reclaim on a rehearsal domain. Change MX, watch resolvers, probe, revert. The first time the team sees NS panic should not be production. Write the one-page model after the drill: NS owners, secret owners, public aliases, disable path, leftover check, clocks.
Practice and anti-patterns for the threat model
Anti-pattern: shared registrar login in a founder chat. Phish resets NS. Mail goes elsewhere. 2FA. Recovery mailbox that is not public hello@. You cannot recover attacker-received mail. Say so.
Anti-pattern: leftover Google MX after a seat cancel. Self-hijack. Delete. Screenshot exclusive baseline. Two resolvers weekly and after every vendor change.
Anti-pattern: contractor WordPress with production SMTP after they left. Rotate dashboard secret. Update env. Review unexpected volume. Offboard the same day as HR.
Anti-pattern: preview deploys using production SMTP. Bots mail customers. Staging sink. Different secrets.
Anti-pattern: Header From rewrite to fight spoof. Refuse. MailerZ will not. Intact From is the real-sender contract. Envelope SRS is the hop.
Anti-pattern: catch-all FORWARD as a honeypot. Abuse amplifier. HOLD. Named aliases. Disable leaks. Do not watch a firehose on purpose.
Anti-pattern: open relay honeypot. 550 5.7.1. Not available. Not a control.
Anti-pattern: SOC 2 sticker in the workshop. /security and a no. Honest controls: lock, exclusive MX, env SMTP, HOLD, clocks, seat offboard.
Anti-pattern: inboxing as a security KPI. Green checkers are not hijack detectors. Stored 550s and public MX are evidence.
Anti-pattern: residual NS access after agency exit. Return it. Residual control is a client threat and your liability.
Anti-pattern: kids catch-all. Safety issue. HOLD plus chosen names.
Anti-pattern: app loop retrying like a stolen credential. Rate-limit. Caps are published. Do not clear a queue through fantasy relay.
Practice: one-page model. NS owners, SMTP owners, public aliases, disable path, leftover check, fourteen/ninety clocks. Review when people leave.
Practice: reclaim drill on a rehearsal domain. Change MX, watch resolvers, probe, revert. First NS panic should not be production.
Practice: vendor list per alias so abuse response is an update list, not archaeology.
Practice: quarterly access review. Seats, registrar codes, password manager. Counsel for real incidents. This page is not legal advice.
Operator closeout for the custom-domain threat model
Three families remain: NS and MX integrity, SMTP secret theft, published-alias abuse. If they own nameservers they own inbound. If they own AUTH they send as you. If they have a leaked local-part they can flood a destination. Controls are registrar lock, exclusive MX, env secrets, named aliases, HOLD, rotate on leave, disable leaks.
Leftover MX is self-hijack. Old Google or builder hosts still answering means history stays empty for those senders. Two resolvers after every launch and weekly thereafter. Delete leftovers. Demote is not a control. Screenshot the exclusive set as a baseline you can diff.
Registrar 2FA belongs on a human who is not the only laptop. Recovery mailbox is not public hello@. Shared registrar chat passwords are how phishing moves NS. You cannot pull mail that already hit an attacker. Say that in the first status sentence. Practice reclaim on a rehearsal domain before you need it live.
SMTP lives in env and platform vaults. Never git. Never Slack. Never a shared zip. Staging is not production. Rate-limit apps so a loop does not look like a stolen-credential burst against five send-as per hour. Copy dashboard host, port, TLS or STARTTLS. Free has no send-as. Rotate the day people leave, including WordPress plugins.
Abuse response cuts the string, not the human inbox. Shop aliases die immediately. Role aliases get a replacement window and a vendor list. HOLD unknown so cousins do not arrive. Do not FORWARD to watch. Do not flap MX. Do not rewrite Header From to fight spoof. MailerZ will not. Envelope SRS is the hop. Intact From is the real sender.
Open relay honeypots are not a control. Unauthorized send is 550 5.7.1. Catch-all FORWARD as a honeypot is an abuse amplifier. Kids plus catch-all is a safety issue. Named aliases plus HOLD is the professional personal setup.
Detection is boring: public MX, hop volume, AUTH failures, held-list spikes. Unexpected NS change is P1. Reclaim, probe, then tell the truth about mail you did not see. Store clocks are fourteen days Free and ninety paid. Act inside them. Do not invent infinite retention.
Enterprise questions get /security and a no on SOC 2, ISO, HIPAA, and inboxing percentages. Honest controls beat stickers. If they require a certified mailbox host, they need another product. Inboxing is not a hijack detector. Green SPF checkers are not either.
Agencies return NS access on exit. Residual control is a client threat and your liability. Confirm public NS. Unpaid leftover MX with your hosts is you still operating inbound. Date the exit. Revoke seats and SMTP in the same packet.
Write one page: NS owners, SMTP owners, public alias list, disable path, leftover check, clocks. Review when people leave. Counsel for real incidents. This article is not legal advice. Start free, lock the registrar, and keep MX exclusive enough to screenshot every time.
Handoff memo for the next operator
Threat models rot when they live in a slide deck. Write a one-page memo that names the current registrar, the current DNS host, who can change MX, who can change TXT, and where recovery codes live. If those answers are "a contractor from 2022," you have a finding, not a footnote. Fix the finding before you file the memo.
List the last three suspicious events even if they were false alarms: a surprise MX, a password reset you did not request, a bounce storm. The next operator needs the pattern, not a clean bill of health. Clean bills of health are how hijacks stay invisible for a weekend.
Include the abuse contacts you already used: registrar, MailerZ support, hosting abuse, and the bank that once rejected a forged invoice. Phone numbers and ticket URLs belong in the memo. Searching for them during an incident wastes the hour you do not have.
End with the drill date. If you have never practiced a registrar recovery, schedule one. A threat model without a drill is literature. MailerZ can hold unknown mail while you recover DNS, but only if someone still has the workspace login.
FAQ
- What is the safest way to handle custom domain email threat model?
- Lock registrar and NS changes. Keep MX exclusive and monitored. Store SMTP only in env. Rotate on leave. Named aliases. HOLD unknown. Disable leaks. Do not dual-publish. Do not invent badges.
- Does this require a new mailbox?
- No. MailerZ is not IMAP. Keep Gmail or Outlook unless you need a suite for other reasons.
- Will it work with Gmail or Outlook?
- Yes as destinations. Self-send is not proof. Use a third mailbox and open original.
- What DNS records are involved?
- Exclusive MX, verification TXT, one SPF if you send-as. Leftover MX is a hard stop. Dashboard values only for sending.
- What should I test before production?
- A uniquely titled probe from an unrelated provider to each public alias. Confirm Header From and hop history.
Key takeaways
- NS is inbound.
- SMTP secret is outbound.
- Named aliases plus HOLD.
- Exclusive MX.
- Rotate on leave.
- No leftover MX.
- No invented badges.
- One-page model.
Conclusion
Threat model the hop you actually run: delegation, secrets, and published strings. Then stop adding folklore.
Start free, lock the registrar, and keep MX exclusive enough to screenshot.