Blogs
-
DMARC
How MSPs Can Manage DMARC Across Hundreds of Client Domains Without Losing Their Minds
MSPs managing email authentication across dozens or hundreds of client domains face a scaling problem. Here is the operational approach that makes multi-tenant DMARC management viable.
-
DMARC
What the Data Actually Shows About MX Server TLS Enforcement Rates
Measurement data from hundreds of thousands of MX servers shows what percentage actually require TLS connections, and why most senders are still sending over plaintext without knowing it.
-
DMARC
DKIM2 and DMARCbis: What Changed and How to Implement Them
Two email authentication standards are moving forward at the same time. Here is what each one changes and exactly how to implement the practical updates.
-
SPF
How to Set Up SPF for a Custom Domain When Sending Through Brevo, SendGrid, or Mailgun
SPF records for custom domains with third-party senders are commonly misunderstood. Here is what actually determines whether your email passes SPF, and what matters more for inbox delivery.
-
DMARC
Why Forwarded Emails Fail DMARC Authentication and What to Do About It
Forwarded emails fail DMARC because the forwarding mail server rewrites the SMTP envelope while the original From header stays in place, breaking SPF and DKIM alignment. Here is what actually causes it and what both senders and recipients can do.
-
How to Resolve Microsoft 365 Duplicate Proxy Address Errors When Sharing SMTP Between Accounts
When two Microsoft 365 accounts need to share the same SMTP address, you may hit a duplicate proxy address error. Here is the root cause and how to fix it.
-
Deliverability
What Percentage of MX Servers Require TLS? Measuring 366,215 Mail Servers
Of 366,215 MX servers measured, 0.2 percent refused STARTTLS-less connections. Here is what that finding means and how DMARC aggregate reports help you monitor TLS failures in your own domain.
-
DMARC
Why Your DMARC p=reject Policy Is Not Blocking Phishing Emails (And What Is)
Safe sender lists and transport rules can override DMARC p=reject at the receiving server. Here is how to diagnose it from mail headers and audit your environment for these standing bypasses.
-
Deliverability
How Many Mail Servers Actually Require TLS in 2026? (The MTA-STS and DANE Reality Check)
A measurement of 366,000 MX hostnames found that only 0.2% of mail servers that support STARTTLS actually refuse plaintext connections. Here is what MTA-STS and DANE actually achieve.
-
DMARC
How Many Mail Servers Actually Require TLS in 2026?
A measurement of 366,000 MX servers found that only 0.2% refuse plaintext connections. Here is what MTA-STS and DANE actually achieve in 2026.