Blogs
-
DMARC
Email Authentication Adoption Across the Top 1 Million Domains: Month Two Data
Month two data on DMARC, MTA-STS, DANE, and BIMI adoption across the top 1 million domains. Here is where the industry stands and what the numbers mean for your email security strategy.
-
BIMI
Tips for progressing to BIMI: what most guides skip
Most BIMI guides stop at publishing a DNS record. This post covers the practical steps that trip up operators, from DNS timing and certificate requirements to SVG logo validation and legacy mail handling.
-
DMARC
DMARC Aggregate Reports and RFC 9990 Compliance: What Changed and What It Means for Your Monitoring
RFC 9990 updated DMARC aggregate reporting in May 2026. Here is what changed from RFC 7489, what the XML report fields actually mean, and how to make sure your DMARC monitoring is up to date.
-
Deliverability
Why Your Phishing Reporting Button Disappears on Mobile (And What Your Rollout Checklist Is Missing)
Enterprise phishing reporting add-ins often vanish from Outlook mobile after deployment. Here is why that happens and how to test for it before a real phish slips through.
-
DMARC
What Breaks When You Move to DMARC p=reject: The Forgotten-Sender Trap
Switching DMARC to p=reject breaks legitimate email when third-party senders are misaligned. Here is how to find them, fix them, and make the transition without losing mail.
-
DMARC
I Wrote DMARC Guides for Years. Then My Own Monitoring Caught Me With My Pants Down.
A DMARC expert who writes the guides discovered their own monitoring had missed their own domain for months. Here is what the self-catch revealed and what every email security team should check today.
-
DMARC
Email Security Adoption Across 10,020 Italian Domains: What the 2026 Measurement Data Shows
A passive measurement study of 10,020 Italian (.it) domains reveals actual SPF, DKIM, DMARC, MTA-STS, and BIMI adoption rates. Here is what the data means for your email security strategy.
-
Deliverability
Should You Build a Copilot Agent for Phishing Detection? A Framework for IT Teams
Practical framework for IT teams on Microsoft 365 evaluating whether a custom Copilot or Power Automate agent adds real phishing detection value or just more noise.
-
DMARC
Why Your Domain Can Still Be Spoofed Even With SPF, DKIM, and DMARC
SPF, DKIM, and DMARC all passing does not mean your domain cannot be spoofed. The direct send attack exploits a gap between these protocols that many administrators do not realize exists.
-
DMARC
Why Third-Party Email Security Services Reject Emails from Domains with No DMARC Policy
When a vendor like Proofpoint or Mimecast rejects your emails because your domain has no DMARC policy, here is what is happening and how to fix it.