Add dmarcing_spf_netblock resource and dmarcing_dns_records data source #12

Merged
alice merged 1 commit from feat/spf-netblocks-dns-records into main 2026-08-28 08:46:39 +00:00
Owner

Summary

  • Adds dmarcing_spf_netblock — adds a raw IPv4/IPv6 address or CIDR block to a domain's allowed SPF senders (mirrors dmarcing_spf_service's add/remove-only shape, no update endpoint).
  • Adds dmarcing_dns_records data source — looks up the NS hostname(s), MTA-STS CNAME target, and static SPF include record a verified domain's own zone needs to delegate to dmarc.ing.
  • Converts dmarcing_dmarc_policy from a single raw policy string to structured p/sp/pct/adkim/aspf/fo attributes, matching how dmarcing_sts_policy already exposes mode/mx/max_age instead of a raw body. rua/ruf are intentionally not exposed since the platform always overrides them server-side.
  • All backed by the new/changed org-scoped API routes in service-dmarc-api#17.

Test plan

  • go build ./...
  • go vet ./...
  • go test ./...
  • Manual: terraform plan/apply against a real org+domain for the new resource, data source, and the reshaped dmarcing_dmarc_policy
## Summary - Adds `dmarcing_spf_netblock` — adds a raw IPv4/IPv6 address or CIDR block to a domain's allowed SPF senders (mirrors `dmarcing_spf_service`'s add/remove-only shape, no update endpoint). - Adds `dmarcing_dns_records` data source — looks up the NS hostname(s), MTA-STS CNAME target, and static SPF include record a verified domain's own zone needs to delegate to dmarc.ing. - Converts `dmarcing_dmarc_policy` from a single raw `policy` string to structured `p`/`sp`/`pct`/`adkim`/`aspf`/`fo` attributes, matching how `dmarcing_sts_policy` already exposes `mode`/`mx`/`max_age` instead of a raw body. rua/ruf are intentionally not exposed since the platform always overrides them server-side. - All backed by the new/changed org-scoped API routes in service-dmarc-api#17. ## Test plan - [x] `go build ./...` - [x] `go vet ./...` - [x] `go test ./...` - [ ] Manual: `terraform plan`/`apply` against a real org+domain for the new resource, data source, and the reshaped `dmarcing_dmarc_policy`
Add dmarcing_spf_netblock resource and dmarcing_dns_records data source
All checks were successful
Go lint / lint (pull_request) Successful in 2m39s
da0be4710d
The provider had no way to add a raw sending IP/CIDR to SPF (only
named ESP includes via dmarcing_spf_service) and no data source
returning the NS/CNAME/SPF records a domain's own zone needs to
delegate to the platform, both of which the web UI already supports.
Adds dmarcing_spf_netblock (mirrors dmarcing_spf_service: add/remove
only, no update endpoint) and dmarcing_dns_records, backed by two new
org-scoped API routes.
alice merged commit efe4d4115a into main 2026-08-28 08:46:39 +00:00
alice deleted branch feat/spf-netblocks-dns-records 2026-08-28 08:46:40 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
dmarc-ing/terraform-provider-dmarcing!12
No description provided.