Blogs
-
DMARC
How DMARC Reject Policy Silently Blocks Your Own Subdomain Mail (And How to Catch It)
A DMARC expert explains how p=reject on your root domain silently blocks subdomain mail that lacks its own SPF and aligned DKIM, and how monitoring your DMARC reports is the only way to catch it before users complain.
-
DMARC
Why Even DMARC Experts Still Get Caught by the Subdomain Inheritance Trap
A DMARC expert who writes guides for a living recently caught his own subdomain failing DMARC because it had no SPF record and no aligned DKIM. The mail was silently rejected by Outlook. Here is the exact rule that caused it and how to prevent it.
-
DMARC
Why Your Legitimate Email Gets Rejected by Proofpoint Citing DMARC (And How to Fix It)
Proofpoint rejects legitimate email citing DMARC even when SPF and DKIM pass individually. Here is the specific failure that causes it and how to fix it.
-
DMARC
How a Forgotten Catch-All MX Domain Becomes Your Email Security Blind Spot
Catch-all MX records on forgotten domains are a silent security gap. Here is how to find them using DMARC reports and how to stop them becoming a phishing risk.
-
Deliverability
How Email Gateways Prefetch Links and Trigger False Phishing Flags for Legitimate Senders
Your email passes every authentication check but still generates phishing complaints. Here is what is happening when recipient email gateways prefetch your tracked links and how to fix it.
-
DMARC
How to Safely Move to DMARC p=reject Without Breaking Your Email
Flipping DMARC to p=reject too early will break legitimate email. This guide covers the pre-flight checks, aggregate report reading, and phased transition path you need before you switch.
-
DMARC
How to Find and Retire Orphaned Email Domains Before They Become an Attack Surface
Campaign microsites get decommissioned. Their email infrastructure often does not. Learn how orphaned domains with open MX records and no DMARC become attack vectors, and what to do before someone exploits them.
-
Deliverability
How to Automatically Encrypt Outbound Emails with Medical Terminology in Microsoft 365
What Microsoft 365 DLP actually does for medical term detection at each license tier, what E5 Purview costs, and what smaller healthcare teams can do right now without it.
-
DMARC
Why Internal Domain Spoofing Still Happens After Disabling Microsoft 365 Direct Send
Direct send is a transport rule, not an authentication check. Here is why disabling it does not stop internal spoofing and what actually does.
-
DMARC
Why Does DMARC Fail for One Domain When All Others Pass?
One domain failing DMARC while all others pass is almost always an alignment problem specific to that domain. Here are the five most common causes and how to find which one is hitting your mail.