Blogs
-
DMARC
How to Move from DMARC p=none to p=reject Without Breaking Mail Flow
-
DMARC
DMARC Alignment Survives Setup but Dies When Your Tool Changes
-
DMARC
Why DMARC Reporting Domains Expire Without Warning
Your DMARC aggregate reports may have stopped arriving because the reporting domain in your DMARC record expired. Here is what happened, why the spec does not protect you, and how to check whether it is happening to you.
-
DMARC
Why Your DMARC Report Shows Thousands of Failures But Your Mail Seems to Be Getting Through
-
DMARC
Safe Sender Lists Can Override Your DMARC p=reject Policy
When your own safe sender list includes a domain an attacker spoofs, DMARC p=reject does not fire. Here is why, and how to audit your configuration before it is used against you.
-
DMARC
Why You Are Not Receiving DMARC Failure Reports (and How to Start Receiving Them)
DMARC failure reports are supposed to arrive by email, but many administrators never see them. This guide explains where they go and how to start receiving them.
-
DMARC
Where Do DMARC Reports Get Delivered? A Plain-English Guide
DMARC reports are not shown in any admin portal. They are sent to email addresses you specify in your DMARC DNS record. Here is what that means and what to do when reports stop arriving.
-
DMARC
Why Email Forwarding Breaks DMARC (And What to Do About It)
Forwarded emails fail DMARC when the forwarding server reshuffles SPF and DKIM alignment. Here is exactly why it happens, what the failure rate looks like, and how to fix it.
-
Deliverability
Is Unencrypted SMTP a Real Security Vulnerability for On-Prem Exchange?
Explains why unencrypted SMTP on Exchange Server is a real risk in specific scenarios, what the actual attack surface looks like, and how to enforce TLS properly.
-
SPF
Why SPF, DKIM, and DMARC Use TXT Records Instead of Dedicated DNS Record Types
SPF, DKIM, and DMARC all live in DNS TXT records. It sounds like a design mistake. Here is why it happened, and what it means for your email authentication setup.