Blogs
-
DKIM
Can I Use 1024-Bit DKIM Keys? Security Risks, Vendor Constraints, and Your Real Options
Many enterprise vendors only support 1024-bit DKIM keys. This guide explains the real cryptographic risks, what RFC 8301 says about them, and the practical options for email administrators caught between best practice and vendor reality.
-
DMARC
Why DMARC Fails When Emails Are Forwarded (And What Actually Fixes It)
Forwarded emails fail DMARC even when SPF and DKIM pass. Here's why it happens and what you can actually do about it.
-
Deliverability
Why Gmail Still Blocks Your Email Despite SPF, DKIM, and DMARC All Passing
Gmail's 421 blocks happen when authentication passes but content signals fail. The fix is different from what most admins expect.
-
DMARC
How Long Should You Monitor DMARC Reports Before Moving a Dormant Domain to p=reject?
After a merger or acquisition, you may inherit domains with unknown sending histories and no ability to send test mail. Here is how to use DMARC aggregate reports to determine the right observation window before moving a domain to p=reject — and what the actual risk is when you do.
-
Deliverability
Why Postfix masquerade_domains Doesn't Apply to Mail From Other Systems
Postfix masquerade_domain only rewrites sender addresses for locally submitted mail. For mail relayed from other hosts, you need sender_canonical_maps instead. Here's the fix and why the original approach fails.
-
DMARC
Why Most DMARC Aggregate Reports Are Still Not RFC Compliant (and What It Means for Operators)
Most large senders — including Google, Microsoft, and Amazon — still send DMARC aggregate reports that violate the RFC specification. Here's what breaks and what operators can do about it.
-
DMARC
Why 37% of DMARC-Protected Domains Still Sit at p=none — and What the Data Actually Tells Us
Most domains with DMARC records are still in monitoring mode, not enforcement mode. Here's what the statistics reveal about real email authentication progress.
-
DMARC
How to Manage DMARC Across Dozens of Domains (Without Breaking Legitimate Mail)
Organizations with large domain portfolios after acquisitions often inherit authentication gaps they can't see. This guide covers the DMARC observation window, the checklist before moving dormant domains to p=reject, and how to manage the third-party sender discovery problem at scale.
-
DMARC
Why Free DMARC Report Tools Are Disappearing (And What to Use Instead)
Several widely-used free DMARC report tools have ended their free tiers or shut down. Here's what happened, what your options are now, and how to choose the right tool for monitoring your domain's email authentication.
-
SPF
The Temporary SPF Include from 2019 That Nobody Will Let Me Remove
Why SPF records accumulate "temporary" includes from 2019, what the 10-DNS-lookup limit means in practice, and how to safely audit and reduce your SPF record without breaking email delivery.