+all or ?all — these allow any server to send on your behalf. Use -all (hard fail) or ~all (soft fail). quarantine or reject required p=none only monitors — it provides no protection against spoofing.rua=) is configured recommended Without this, you have no visibility into spoofing attempts or delivery issues.
https://mta-sts.[yourdomain]/.well-known/mta-sts.txt with mode: enforce._smtp._tls DNS record enables reporting on email delivery failures.
X-Frame-Options , X-Content-Type-Options , Content-Security-Policy .admin username is not in use required It's the first username attackers try.wp-login.php is protected recommended Apply rate limiting, 2FA, or relocate the login URL to reduce brute-force exposure./xmlrpc.php is a frequent target for brute-force and DDoS amplification attacks.