Blogs
-
DMARC
How Gov.uk Uses DMARC to Protect Domains That Don't Exist — And Why It Matters for Your Organization
Gov.uk publishes DMARC and SPF reject records for non-existent subdomains — a namespace-level anti-phishing pattern no one documented publicly until now. Here's what it means and how to apply the lesson.
-
DMARC
How to Move a Domain from p=none to p=reject Safely — A Practical Guide
Moving your domain's DMARC policy to p=reject is a security win — but skip the preparation and you'll break legitimate email. This guide walks through the three-phase migration model used by practitioners who got it right.
-
DMARC
Why DMARC Reports Are Often Not RFC Compliant (And How to Fix Yours)
Most DMARC reports violate RFC 6591. Learn why that happens, what problems it creates, and how to validate your reports are correctly formed.
-
DMARC
Why Your DMARC-Reject Domain Still Can't Stop Wire Fraud
Even with DMARC at enforcement, wire fraud still succeeds. Here's what DMARC protects, what it doesn't, and why BEC bypasses domain authentication entirely.
-
DMARC
Why Your DMARC p=reject Policy Doesn't Protect Subdomains (And How to Fix It)
Setting DMARC to p=reject without adding the sp= parameter leaves your subdomains wide open to spoofing. Here's what the gap is, how it works, and how to close it.
-
DMARC
Why Most DMARC Reports Fail RFC Compliance (And What to Do About It)
Most DMARC aggregate reports contain RFC 7489 violations that cause parsing failures in monitoring tools. Here's what causes them and how to handle them.
-
DMARC
Why Your First DMARC Report Looks Like a Catastrophe (And Why That's Actually Good News)
Your first DMARC aggregate report shows hundreds of sending sources failing authentication. This is normal. Here's what those failures mean, which ones matter, and how to use your early DMARC data to migrate safely to enforcement.
-
DMARC
Why International Mail Gets Rejected After You Set DMARC to Reject
Setting DMARC to p=reject blocks external domain spoofing, but it can break email delivery to international recipients when forwarding chains break DKIM alignment or receiving servers apply strict inbound DMARC policies.
-
DMARC
Why Microsoft 365 Shows an Internal Sender Address from an External IP
Microsoft 365 message trace sometimes shows an internal sender address alongside an external source IP. This is not a bug - it reflects how email addressing works at the envelope layer versus the application layer. Here is what it means for SPF, DKIM, and DMARC.
-
DMARC
How to Move from DMARC p=none to p=reject Without Being Buried by Your Report Backlog
Inherited a DMARC p=none setup with thousands of backlogged reports? Here's how to triage, prioritize, and move to enforcement without the chaos.