Blogs
-
DMARC
Why Big Companies Skip DMARC (And Why That Security Gap Becomes Your Problem)
Large companies often skip DMARC enforcement. Here's why that creates downstream risk for everyone who receives email from them -- and what you can do about it.
-
DMARC
Why Your DMARC Report Parser Keeps Breaking (And What the Major Providers Get Wrong)
Most DMARC parsers break on reports from major providers because those reports contain RFC violations — missing fields, invalid values, malformed XML attachments. Here's what's actually wrong and how to handle it.
-
DMARC
Why Entra B2B Invitation Emails Fail DMARC (And How to Fix Them After Microsoft's January 2026 Change)
Microsoft's January 2026 sender change made B2B invitation emails align to your tenant domain — which breaks DMARC if you haven't configured SPF or DKIM for Microsoft's relay. Here's why, and what to do about it.
-
Deliverability
Why Your Exchange Hybrid Environment Generates Thousands of HIERARCHY_SYNC_NOTIFICATIONS
If your Exchange Hybrid public folder mailboxes are flooding with HIERARCHY_SYNC_NOTIFICATIONS, here's what causes it and how to stop the replication storm.
-
DMARC
Why Microsoft 365 Shows an Internal Sender When the Source IP Is External
Microsoft 365 marks emails as internal based on tenant membership, not IP range. Source IP shows the last hop before Exchange Online — which is often a third-party relay, not your network.
-
DMARC
How gov.uk Uses DMARC Reject Records to Protect Non-Existent Domains (And What You Can Learn From It)
Gov.uk publishes DMARC reject records for subdomains that don't exist. It's not an error — it's deliberate anti-phishing infrastructure. Here's what it means and how to apply it to your own domain namespace.
-
DMARC
Why Phishing Emails Still Get Through Despite SPF, DKIM, and DMARC
Strict email authentication doesn't stop all phishing. Here is why these protocols fail against real attacks — and what layered email security actually requires.
-
Why Phishing Simulations Are Mostly Security Theater (And What Actually Works)
Phishing simulations catch clicks, not compromises. Here’s why your simulation program isn’t improving security outcomes — and what actually does.
-
SPF
How to Format an SPF Record When You Use Multiple Email Service Providers
When your domain sends through more than one email provider, SPF formatting gets tricky fast. Here is what actually matters.
-
DMARC
Why Most DMARC Reports Are Failing RFC Compliance (And What It Means for Your Setup)
Most DMARC reports have RFC compliance errors that go undetected. Here is what RFC 7489 requires, why reports fail, and how to check yours.