Blogs
-
DMARC
What to Do With DMARC Aggregate Reports: A Practical Triage Workflow
A step-by-step triage workflow for DMARC aggregate reports -- what to look for first, what to fix, and when to ignore the noise.
-
SPF
How to Verify SPF, DKIM, and DMARC Are Correctly Configured for a Domain
A step-by-step guide for checking SPF, DKIM, and DMARC records for any domain using command-line tools and free web checkers. Written for email administrators and MSPs.
-
DMARC
How to Move Your DMARC Policy from p=none to p=quarantine or p=reject Safely
A practical step-by-step guide for upgrading your DMARC policy from monitoring-only (p=none) to enforcement (p=quarantine or p=reject) without breaking legitimate email.
-
Deliverability
How Many Mail Servers Actually Require TLS? (A Survey of 200 MX Hosts)
A survey of roughly 200 mail servers found 22% require TLS. Here is what that means for your email security posture and TLS enforcement decisions.
-
Deliverability
How Many Mail Servers Actually Require TLS? (A Survey of 200 MX Hosts)
A survey of roughly 200 mail servers found 22% require TLS. Here is what that means for your email security posture and TLS enforcement decisions.
-
DMARC
What the CoMIT Study Reveals About MSP Email Authentication Maturity
A study of 37,548 MSPs found that CoMIT MSPs are 2.4x more likely to have properly configured SPF, DKIM, and DMARC. Here is what the data means for your MSP email security strategy.
-
How to Stop a Persistent Zero-Click Apple Mail DoS Attack
A zero-click Apple Mail DoS attack floods your inbox without any user interaction. Here is how to identify it, stop it, and recover.
-
DMARC
Does DMARC at p=none Protect Against Spoofing? What It Actually Does
DMARC at p=none monitors email authentication failures but does not block or prevent spoofing. Here is what p=none actually does and how to move beyond decorative monitoring to real protection.
-
DMARC
Why Your SPF DKIM and DMARC Records Pass DNS Checks But Receivers Still Disagree
When your SPF DKIM and DMARC DNS records look correct but different email receivers give different authentication results, the cause is usually selector state, cached records, alignment timing, or forwarding. Here is how to diagnose which receiver is right.
-
Deliverability
How Many MX Servers Actually Refuse Mail Without TLS?
Testing 366,215 MX servers revealed that only 0.2 percent refuse non-TLS mail. Here is what that means for your TLS enforcement policy.