Hostingfree100m/free 5GB (1 address) MXPLAN 1 without DKIM/MTA-STS

This may help someone whenever to choose OVH as a registrar
for their domain name with the offer of "free" 100MB web hosting
and one 5GB e-mail address and 2000 e-mail re-directs.
https://www.ovhcloud.com/en-gb/domains/free-web-hosting/


While when signing up for the free old "start10m" 10MB hosing plan/5GB 1 e-mail in
OVH Control Panel there was a note that
"The Start 10M plan is included with your solution, but it only comes with basic features."
it is not clear exactly that DKIM/MTA-STS will not be supported.


Enabling "hostingfree100m" still includes the above message:
The Start 10M plan is included with your solution, but it only comes with basic features.


Also on the "free-web-hosting" below:
https://www.ovhcloud.com/en-gb/domains/free-web-hosting/
you can read about all the benefits of registering domain with OVH and get:

"A 5 GB email account"
Use your business email address linked to your domain name with a POP/IMAP account,
and get a 5 GB disk space to store all your emails.


"Communicate with a professional email address"
You have a 5 GB email account linked to your domain name, so you can send
and receive emails from a professional email address that your contacts
will recognise and associate with your brand. You can check your mailbox
from your computer, smartphone or directly via your web browser, and we
also keep your account secure with anti-spam and anti-virus protection.



But what it does not tell you is, that your "free" professional email address
with 5 GB email account will not support DKIM/MTA-STS!



In the section of "Your questions answered" you will not find it either!

However, there are interesting question included :wink:

"Which services are not available with the free hosting?"
Some services are only available with Personal or Professional hosting plans,
such as pre-installed CMSs (WordPress, Drupal, Joomla!, PrestaShop, etc.),
multiple website hosting, unlimited FTP or SSH access, and mailing lists.

So you do not need unlimited FTP or SSH access, CMS and mailing lists so
you think this sounds great, but if you are planning to also send e-mails
with your professional email address you will soon be disappointed.



You probably now asking why do I need DKIM/MTA-STS?

DKIM (DomainKeys Identified Mail)
---------------------------------
(only available to Exchange and Email Pro plans) !!!

Well, if your e-mails that you sent are not "signed with DKIM key",
they will always end up in the recipients SPAM folder and
your professional email address will not look that professional any more!

There may be some companies that do not take SPAM seriously and have
not implemented DKIM, but majority of big players have and suddenly
you FREE e-mail will be free but not professional, but if you upgrade
to "paid for service" you can get access to such a future:
https://help.ovhcloud.com/csm/en-dns-zone-dkim?id=kb_article_view&sysparm_article=KB0058258


Should OVH let potential customers know that it's a trap before
they purchase in good faith?


Is offering "free" e-mail service without having a DKIM working today
second class/broken service?







MTA-STS (Mail Transfer Agent Strict Transport Security)
-------------------------------------------------------
(only available to Exchange and Email Pro plans) !!!
as you can not on "hostingfree100m" create certificates for sub-domain
"mta-sts.domain.name".

I have asked OVH support to remove "www" subdomain and only use naked domain
and replace the "www" with "mta-sts" but been advised that it's not possible!

I have been unable to find any article related MTA-STS on OVH Help pages either :frowning:



Google has a good article on how to "Help prevent spoofing, phishing, and spam"
https://support.google.com/a/topic/9061731
that includes SPF, DKIM, DMARC and BIMI.

Also on "Advanced Gmail security"
https://support.google.com/a/topic/2683828
that includes article on increase email security with MTA-STS and TLS reporting



Hardenize also offer great article with regards to "Policy for Email Infrastructure"
https://www.hardenize.com/labs/policy

and what your e-mail should be supporting:
https://www.hardenize.com/downloads/hardenize-policy-for-email-infrastructure-preview3-20210519.pdf
- Support STARTTLS
- Configure TLS appropriately for SMTP
- Use valid TLS certificates issued by public CAs
- Keep detailed SMTP server connection logs
- Consider requiring STARTTLS
- Use DMARC reporting
- Use DMARC to quarantine or reject spoofed email
- Use SMTP TLS Reporting
- Use SPF
- Use DKIM
- Use DANE if using DNSSEC
- Use MTA-STS
- Monitor for look-alike domain names
- Be aware of BIMI


but it looks like OVH does not think that supporting DKIM/MTA-STS is a must on free accounts :frowning:

Thank you for your good explanations.

Yes, it really seems as if OVH thinks that they can leave all owners of existing email accounts and probably future ones in the dark about the fact that they cannot send emails to recipients who require DKIM, as the German Telekom recently did.

As an old customer since 2008, I was even told clearly that I could not be offered an email solution for the package I purchased that would enable me to continue corresponding with my contacts with t-online.de email accounts.

I don't want to leave OVH with my 9 domains and a Pro-Hosting with 250GB.

I'm still in hope, that OVH find's a way to enable me to send emails to german Telekom users with t-online.de adresses.

**If you have a PRO account, you "CAN" configure the DKIM, **
it's just the "FREE" accounts with MX1 plan and one e-mail address and 5GB that are not able to do so along with MTA-STS :frowning:

I can only find "one" reasonable explanation as to why not,
OVH wants me to upgrade to PAID plan, but that is not going to happen.



AndreasR,
what you need to realise is that this is exactly the type of customer that OVH wants,
one that would never leave, it's bit like if you get tangled in the Amazon eco system.
(It has taken me several years to leave Amazon tenticles and it was not easy).

All the companies want to "lock you in" so you do not leave, or find it hard to do so.
(Heard of OpenRAN pushed by Vodafone? - slightly different but it's about the not being "locked in").

If you need basic web [static] and robust e-mail, why not give a try to Mail In A Box, just get a VPS with reliable provider or possibly community run and possibly based in Germany (to support home project).

I host my valuable domains with also FR company, but better credentials = gandi.net and run my own MIAB on community run VPS and use OVH just for side projects (but also looking to move from them because of the crippled e-mail they offer, yes I know its free, but still, it's crippled).

Also If you are lucky enough and live in part of DE that has FTTP infrastructure (with decent upload) and your ISP offers static IPv4 and PTR record you can host it all (MIAB) at home on old PC or RPi or simmilar.
Or even if your FTTP ISP does not offer static IPv4 with PTR record, you can purchase IPv4 that can be router via tunnel to your device from independent provider :wink:

Also reading the community forum here many questions just stay unanswered so what is the OVH staff/moderators doing here if not helping the community?
(Look at what they do and not what they say/write on their website or glossy leaflets)


Update - Tuesday, December 05 2023
Just checked gandi.net and looks like they are slipping into the red (orange now) as well
https://uk.trustpilot.com/review/gandi.net