Oracle CloudStatic-verified

Sending Mail that Receivers Trust, from Approved Senders

A domain without DKIM sends mail that looks forged and lands in spam; without a custom return path, bounces go to Oracle's domain and DMARC alignment fails; and a From address that is not an approved sender is refused by the API. DKIM key created, return path created, senders listed and checked against the domain, and every DNS record to publish exported in one output.

terraformOracle Cloudoci
oci-email-deliveryvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-14 · how we verify

Use it from the registry

terraform · opentofu
module "email_delivery" {
  source  = "www.iac-bazaar.com/iac-bazaar/oci-email-delivery/oci"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

oci-email-delivery

An Email Delivery domain with DKIM, a return path, and approved senders. Works with Terraform and OpenTofu (>= 1.6), oci provider >= 8.0, < 9.0.

A domain without DKIM sends mail that looks forged. The signing key is created here and its DNS record exported.

A domain without a return path bounces to Oracle and fails DMARC alignment. Created here; going without needs accept_oracle_return_path.

A sender that is not approved is refused. Senders are listed and must belong to the domain; a domain with none needs accept_no_senders.

The SMTP credential is an IAM user's, with the policy in policy_required.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules