Blogs
-
DMARC
Why 37% of DMARC-Protected Domains Are Still at p=none and What That Means for Email Security
<p>Most domains with DMARC records don't actually enforce them. Here's why so many organizations get stuck at p=none, and what that leaves unprotected.</p>
-
DMARC
Why "DMARC Compliant" Emails Are Still Getting Wire Fraudmed - And What Alignment Actually Protects
<p>An email can pass DMARC authentication perfectly and still be part of a business email compromise attack. Here's what DMARC actually protects against - and what it doesn't.</p>
-
Deliverability
How to Fully Decommission Exchange Server After Your Microsoft 365 Migration
Step-by-step guide to fully removing on-premises Exchange Server after your Microsoft 365 migration — including pre-checks, removal sequence, and what breaks if you move too fast.
-
DMARC
How to Forward DMARC Reports to Your Own Infrastructure
DMARC reports show exactly who is sending email on your behalf — useful for security and required for compliance. If your organization needs to keep that data in-house, here is how to route reports to your own infrastructure without breaking the spec.
-
DMARC
What Germany's GMX, WEB.DE, and mail.com DMARC Enforcement Means for Your Email (And How to Fix It)
GMX, WEB.DE, and mail.com are now enforcing DMARC alignment on inbound mail. If your emails to German recipients are failing or landing in spam, here's what changed and how to fix it.
-
DMARC
How to Set Up MTA-STS and DMARC Reporting for Your MSP Clients (Without Breaking Email)
A practical guide for MSPs deploying MTA-STS policy and DMARC reporting across multiple client domains — in the right sequence, with the right tools.
-
DMARC
What Your First DMARC Report Actually Reveals (And Why New Users Are Stunned by the Numbers)
Your first DMARC aggregate report usually contains far more failures than expected. This guide explains what's normal, what isn't, and what to do with the data.
-
DMARC
How Publishing p=reject Without sp= Got a Company Spoofed for Two Weeks
Publishing p=reject without sp= leaves delegated subdomains outside your DMARC policy. Here's why and how to close the gap.
-
How to Create a BIMI-Compliant SVG Logo (That Actually Passes Validation)
<p>BIMI requires a specific SVG profile. Most converters produce files that validate structurally but fail at mail servers. Here's what actually works.</p>
-
SPF
How to Remove a Legacy SPF Include When Stakeholders Won't Approve It
Most organizations have at least one SPF include from a vendor or migration they no longer use. This guide shows how to audit, validate, and document the safe removal of a legacy SPF include — even when stakeholders require proof before signing off.