Blogs
-
SPF
Why Microsoft Blocks Your GoPhish Simulations (And How to Fix SPF Alignment)
Microsoft is blocking your GoPhish phishing simulation emails. The root cause is SPF alignment failure. Here is how to diagnose it and fix it.
-
Why Your BIMI Record Is Not Showing: The Prerequisites That Must Be Met
BIMI logos depend on more than just a DNS record. This post walks through the full prerequisite chain and explains how to find which step is blocking yours.
-
DMARC
Why DMARC Aggregate Reports Are Missing the envelope_from Element (And What to Do About It)
Yahoo and Google omit the envelope_from element from DMARC aggregate reports, breaking forensic analysis. Here is what RFC 9990 requires, which providers are affected, and how to work around the gap.
-
Deliverability
Why Email Goes to Spam Even When SPF, DKIM, and DMARC All Pass
Authentication passing means your email is authorized -- not that it will reach the inbox. Here is why spam filters still block legitimate mail and what actually drives deliverability.
-
DMARC
Why Forwarded Emails Fail When You Set DMARC to Quarantine
Setting DMARC p=quarantine seems like a safe step toward enforcement, but forwarded emails break because the forwarding server becomes the new sender and fails DMARC alignment. Here is why it happens and how to diagnose it.
-
DMARC
How to Enforce DMARC p=reject Without Breaking Your Copier or Printer Scan-to-Email
Legacy copiers and printers break when you enforce DMARC p=reject. Here is why and three practical fixes that do not require replacing your hardware.
-
DMARC
Why Your Own Legitimate Mail Gets Rejected by Your DMARC Policy
A DMARC expert with 20 years of experience had his own subdomain mail silently rejected by his own p=reject policy. Here is exactly why this happens, why your logs miss it, and how to prevent it.
-
Deliverability
Why Your Mail Starts Temp-Failing After You Rename a Cloud VM or NAT Device
Renamed your cloud VM or NAT device? If your PTR record still points to the old hostname, mail receivers may start rejecting your messages -- and the bounce code will not say why.
-
DMARC
Why OAuth App Consent Lets Attackers Keep Access After You Close a M365 Mailbox Incident
When a M365 mailbox is compromised, resetting the password does not automatically revoke OAuth app grants. Here is what actually closes the gap.
-
Deliverability
Why Phishing Feels Safer in a Shared Ops Mailbox and How to Fix the Detection Gap
Shared mailboxes create a cognitive trap where analysts lower their guard on phishing because the context makes the mail feel legitimate. Here is how to close that detection gap.