Blogs
-
DMARC
Why DMARC Fails Even When SPF Passes: The Missing Link
SPF passing does not mean DMARC passes. Here is why alignment is the missing piece and how to read your DMARC reports correctly.
-
Deliverability
How to Decommission Exchange Server After Migrating to Exchange Online Without Breaking Mail
A practical checklist for sysadmins who have migrated mailboxes to Exchange Online and need to safely shut down the on-premises Exchange Server without disrupting mail flow or third-party integrations.
-
DMARC
Is Your Cloudflare + iCloud+ Email Setup Actually Secure? A Practical Guide
Your Cloudflare and iCloud+ setup can be quite secure, but p=reject is just the beginning. Here is what it protects, what it does not, and what to check.
-
DMARC
How AI-Powered Business Email Compromise Works - and Why DMARC Is Your Best Defense
AI is automating business email compromise at scale. Here is exactly what it changes, what traditional email security gets wrong, and how DMARC p=reject stops the domain spoofing that underpins most BEC campaigns.
-
DMARC
How to Migrate Your DMARC Policy from p=none to p=reject Without Breaking Mail
A practical step-by-step guide to safely tightening your DMARC policy from monitor-only to reject, including the checks to run first and how to roll back if something breaks.
-
DMARC
Are AI-Enabled DMARC Tools a Security Risk? What Practitioners Need to Know
AI-enabled DMARC tools promise smarter monitoring but may introduce new attack surface. Here is how to evaluate whether one makes your email security stronger or weaker.
-
DMARC
How to Move Your DMARC Policy from p=none to p=reject Without Breaking Email
Step-by-step guide to tightening DMARC from monitoring-only to full rejection policy while keeping all legitimate email flowing.
-
DMARC
Someone Used My Email for Online Purchases. Is It a Scam?
Received a purchase confirmation you did not make? Here is what it means, why it usually is not a scam, and what to do next.
-
How to Fix SPF Records That Exceed the 10 DNS Lookup Limit
SPF records with too many third-party includes can exceed RFC 7208's 10 DNS lookup limit, causing email failures. This guide explains the limit and your practical options for fixing it.
-
How CVE-2025-66376 Turns Zimbra Classic Into an Attack Surface: What Admins Need to Know
CVE-2025-66376 exploits Zimbra Classic's view-only mode to execute malicious content when a victim simply previews an email. No link click, no attachment open. Here is how the exploit works and what every Zimbra admin needs to do right now.