Context
A domain with no MX (mail exchange) records cannot receive email. If a user signs up with user@no-mail-server.com and that domain has no MX records, the email address is effectively invalid — the confirmation email will never arrive.
This is a lightweight DNS check (not SMTP verification, not mailbox probing). It catches:
- Completely fake domains
- Parked domains
- Domains that exist but aren't configured for email
Proposed behavior
Signal name
noMxRecord
Detection
Perform a DNS MX lookup on the domain. If no MX records are found, flag it:
const result = await guard.verify('user@no-mail-server.com');
// {
// isMatch: true,
// matchedOn: ['noMxRecord'],
// domain: 'no-mail-server.com',
// ...
// }
Configuration
const guard = await BurnerGuard.create({
checkMxRecords: false, // default: false (opt-in, requires network)
mxLookupTimeout: 5000, // DNS timeout in ms (default: 5000)
treatNoMxAsMatch: true // default: true (no MX = match)
});
Opt-in because:
- Requires a network call (DNS), which breaks the offline/sync contract for static mode
- Adds latency to
verify()
- May not be available in all environments (browsers, some edge runtimes)
Implementation notes
- Use
dns.resolveMx() from Node.js dns/promises — dynamically imported like the fs module
- Cache results per domain to avoid repeated DNS lookups within the same instance
- Consider fallback: if DNS lookup times out, don't flag (fail open, not closed)
- Some domains use an A record as an implicit MX fallback (RFC 5321 §5.1) — decide whether to honor this
- Not available in browser environments — should gracefully skip when
dns module isn't available
Interaction with other signals
A domain could trigger both blocklist and noMxRecord. Both appear in matchedOn.
Acceptance criteria
Priority: 🟡 Medium — cheap signal that catches fake domains, but requires network
Context
A domain with no MX (mail exchange) records cannot receive email. If a user signs up with
user@no-mail-server.comand that domain has no MX records, the email address is effectively invalid — the confirmation email will never arrive.This is a lightweight DNS check (not SMTP verification, not mailbox probing). It catches:
Proposed behavior
Signal name
noMxRecordDetection
Perform a DNS MX lookup on the domain. If no MX records are found, flag it:
Configuration
Opt-in because:
verify()Implementation notes
dns.resolveMx()from Node.jsdns/promises— dynamically imported like thefsmodulednsmodule isn't availableInteraction with other signals
A domain could trigger both
blocklistandnoMxRecord. Both appear inmatchedOn.Acceptance criteria
dns/promisesnoMxRecordsignal inmatchedOncheckMxRecordsopt-in config with timeout and match behavior optionsdnsmodule (browsers)Priority: 🟡 Medium — cheap signal that catches fake domains, but requires network