Compare commits

...

3 Commits

Author SHA1 Message Date
b5503d22c0 sam-4screen-desktop 2026-8-31:16:24:8 2026-08-31 16:24:08 +10:00
cdf9c20162 sam-4screen-desktop 2026-8-31:15:9:8 2026-08-31 15:09:08 +10:00
0fc570af3d sam-4screen-desktop 2026-8-31:14:54:8 2026-08-31 14:54:08 +10:00
4 changed files with 114 additions and 4 deletions

View File

@@ -212,6 +212,7 @@
},
"active": "8018aa52f0591df9",
"lastOpenFiles": [
"200 projects/220 Web Host Migration/Cloudflare Record Set — audasmedia.com.au.md",
"200 projects/220 Web Host Migration/audasmedia.com.au — DNS Baseline.md",
"300 areas/360 Dev-Ops Network Computers/Home Voice Assistant System.md",
"300 areas/360 Dev-Ops Network Computers/Docker Containers.md",
@@ -237,7 +238,6 @@
"200 projects/220 Web Host Migration/Migration Plan — InMotion to Local + AWS Offsite.md",
"300 areas/360 Dev-Ops Network Computers/Backup Health Check Commands.md",
"300 areas/360 Dev-Ops Network Computers/Backup System — Borg, Kopia & Restic.md",
"300 areas/360 Dev-Ops Network Computers/Bumblebee - The Open-Source Scanner for Messy Dev Machines.md",
"000 daily/ThinkPad Recommendations",
"500 archive/510 Daily",
"300 areas/305 Ideas Businesses",

View File

@@ -0,0 +1,69 @@
---
created: 2026-08-31
modified: 2026-08-31
type: reference
client: sam
project: web-host-migration
status: active
priority: 1
tags:
- dns
- cloudflare
- ses
- email-routing
- audasmedia
aliases:
- cloudflare-record-set
id: 1848129026-CF
---
# Cloudflare Record Set — audasmedia.com.au (ready to paste)
> Prepared 2026-08-31. To be applied in **Cloudflare** DNS once nameservers are authoritative.
> Email: **SES outbound** + **Cloudflare Email Routing inbound (→ Gmail)**. **$0/month.**
## A. Existing site records (PRESERVE — do not change)
| Type | Name | Value | Proxy |
|---|---|---|---|
| A | `@` | `173.231.229.92` | DNS only (grey cloud) |
| A | `cpanel` | `173.231.229.92` | DNS only |
| A | `webmail` | `173.231.229.92` | DNS only |
| A | `ftp` | `173.231.229.92` | DNS only |
| CNAME | `www` | `@` | DNS only |
| CNAME | `mail` | `@` | DNS only |
> ⚠️ Keep these on **DNS only** (grey cloud) — do NOT proxy/orange-cloud them, to avoid surprises while sites are on InMotion.
## B. SES outbound records (from SES console 2026-08-31)
### DKIM (3 CNAMEs)
| Type | Name | Value |
|---|---|---|
| CNAME | `3hcitiezqbwlyyrqhvuovye47ybnbheq._domainkey.audasmedia.com.au` | `3hcitiezqbwlyyrqhvuovye47ybnbheq.dkim.amazonses.com` |
| CNAME | `lswlbc3gsmshm4b22bpyfn5k2evdgrdh._domainkey.audasmedia.com.au` | `lswlbc3gsmshm4b22bpyfn5k2evdgrdh.dkim.amazonses.com` |
| CNAME | `ac5j6wxukvq6b5dacrp5xgzkdsovmm2e._domainkey.audasmedia.com.au` | `ac5j6wxukvq6b5dacrp5xgzkdsovmm2e.dkim.amazonses.com` |
### DMARC
| Type | Name | Value |
|---|---|---|
| TXT | `_dmarc.audasmedia.com.au` | `"v=DMARC1; p=none;"` |
> MAIL FROM custom-domain records: **SKIP for now** (low volume; default SES works fine).
## C. Cloudflare Email Routing (inbound → Gmail)
Enable in Cloudflare dashboard: **Email → Email Routing → Enable**.
- It auto-creates: **2 MX records** (route1/route2.mx.cloudflare.net) + **TXT** `v=spf1 include:_spf.mx.cloudflare.net ~all`.
- **Add routing rule:** `sam@audasmedia.com.au` → `samuelrolfe@gmail.com`
- Optionally a catch-all → Gmail.
## D. Resulting SPF (combine providers)
After B+C: SPF must include SES + Cloudflare. Simplest working value (single TXT):
```
v=spf1 include:_spf.mx.cloudflare.net include:amazonses.com ~all
```
(Replace the old InMotion SPF.)
## Verification
- MXToolbox: DNS lookup → MX/SPF/DKIM/DMARC all pass
- Test: send to `sam@audasmedia.com.au` → arrives in Gmail; send via SES → delivered, DKIM=pass
---
*Part of [[Migration Plan — InMotion to Local + AWS Offsite]] Phase 2. Track in [[Migration Work Log]].*

View File

@@ -79,6 +79,23 @@ id: 1848129023-LOG
| P1 | **Safety net now:** sync 23:00-05:00 → verify 05:15 (alert if no progress) → monitoring page every 15 min. Silent-failure mode is closed. | armed |
## Pending next action
## PHASE 2 EMAIL — progress log (2026-08-31)
| Item | Status |
|---|---|
| DNS moved to Cloudflare (audasmedia.com.au) | ✅ NS = jo/osmar.ns.cloudflare.com; A/wwww/cpanel/ftp preserved; **wildcard `*.lab` → 144.6.86.11 re-added (was missing after import — caught it, home sites restored)** |
| SES identity `audasmedia.com.au` | ✅ created; 3 DKIM CNAMEs + DMARC added to Cloudflare |
| Email Routing (free inbound → Gmail) | ✅ enabled; MX route1/2/3.mx.cloudflare.net live; catch-all → samuelrolfe@gmail.com; **test delivery confirmed (arrived in All Mail)** |
| SPF | ✅ `v=spf1 ip4:173.231.229.92 include:_spf.mx.cloudflare.net include:amazonses.com ~all` |
| Zoho | ❌ abandoned (SMS OTP never arrives) |
| MXroute | ⏸ deferred (no funds today; Cloudflare Email Routing covers inbound for $0) |
| SES outbound test | ⏳ next: send test email via SES → verify DKIM/SPF pass |
| SES production access | ⏳ later (free, ~hrs) so sites can send to anyone |
## Next steps (email)
1. SES console → Send test email (audasmedia.com.au → samuelrolfe@gmail.com); check delivery + DKIM/SPF pass.
2. Request SES production access (free).
3. Then return to Phase 3 (local infra) / CMS migration project.
- **Build:** create bucket `sam-offsite-backup` + lifecycle (S3→Glacier Flexible@30d→Glacier DA@90d), then wire local Borg/rclone→S3 on `.13`, seed, test restore.
- **Security:** enable root MFA; consider rotating access key after seeding (it was pasted in chat).

View File

@@ -41,9 +41,33 @@ id: 1848129025-DNS
- After Cloudflare migration: A records stay identical (site remains on InMotion VPS until CMS migration); only MX/SPF/TXT/DKIM/DMARC change for email.
## Email target (Phase 2)
- **Inbound:** Zoho Mail free tier — mailbox `sam@audasmedia.com.au`
- **Outbound:** Amazon SES (already have AWS account)
- **MX → Zoho, SPF → Zoho + SES, DKIM → Zoho + SES, DMARC → new**
- **Inbound:** ~~Zoho Mail free tier~~ — **FAILED (SMS OTP never arrives after 1h; Zoho is SMS-only verification). Abandoned. Fallback: MXroute (~US$30-45/yr flat, unlimited domains).**
- **Outbound:** **Amazon SES** — identity created ✅ (domain `audasmedia.com.au`, region ap-southeast-2)
- **MX → (provider TBD: MXroute), SPF → include provider + SES, DKIM → SES (3 CNAMEs below) + provider, DMARC → new**
## SES records to add (from console, 2026-08-31)
These go into **Cloudflare** once NS switch propagates (still InMotion now).
### DKIM (3 CNAMEs)
| Type | Name | Value |
|---|---|---|
| CNAME | `3hcitiezqbwlyyrqhvuovye47ybnbheq._domainkey.audasmedia.com.au` | `3hcitiezqbwlyyrqhvuovye47ybnbheq.dkim.amazonses.com` |
| CNAME | `lswlbc3gsmshm4b22bpyfn5k2evdgrdh._domainkey.audasmedia.com.au` | `lswlbc3gsmshm4b22bpyfn5k2evdgrdh.dkim.amazonses.com` |
| CNAME | `ac5j6wxukvq6b5dacrp5xgzkdsovmm2e._domainkey.audasmedia.com.au` | `ac5j6wxukvq6b5dacrp5xgzkdsovmm2e.dkim.amazonses.com` |
### MAIL FROM (optional — recommend SKIP for now, low volume)
| Type | Name | Value |
|---|---|---|
| MX | `audasmedia.com.au.audasmedia.com.au` | `10 feedback-smtp.ap-southeast-2.amazonses.com` |
| TXT | `audasmedia.com.au.audasmedia.com.au` | `"v=spf1 include:amazonses.com ~all"` |
### DMARC
| Type | Name | Value |
|---|---|---|
| TXT | `_dmarc.audasmedia.com.au` | `"v=DMARC1; p=none;"` |
## DNS state (2026-08-31)
- audasmedia.com.au NS = **still InMotion** (ns1/ns2.inmotionhosting.com). Cloudflare account+domain created but registrar NS switch not yet propagated. Records above wait for Cloudflare to be authoritative.
---
*Part of [[Migration Plan — InMotion to Local + AWS Offsite]] Phase 2. Track in [[Migration Work Log]].*