Blogs
-
DMARC
Why the DMARC np Tag Does Not Work When DNSSEC Is Enabled
RFC 9989 introduced the DMARC np tag for non-existent subdomain policies, but it breaks on domains that use DNSSEC because the two protocols make conflicting assumptions about how DNS negative responses work.
-
DMARC
Why DMARC Fails Even When SPF Passes
Your SPF record can show a perfect pass while your DMARC report still shows failures. Here is exactly why this happens and how to fix it.
-
DMARC
Why Proofpoint Breaks DMARC Alignment and How to Fix It
Proofpoint rewrites the RFC5321.MailFrom domain during mail processing. This breaks DMARC alignment at the receiving server, causing legitimate mail to be rejected even when SPF and DKIM pass. Here is what happens and how to fix it.
-
DMARC
Why You Get Backscatter Emails After Setting DMARC to Reject (and How to Stop Them)
Setting DMARC to p=reject can flood your inbox with bounce notifications for spam you never sent. Here is what causes it and how to stop it.
-
DMARC
Azure Copilot Agent Access: Email Security Implications for M365 Tenants
Azure Copilot Agent Access lets AI agents read and send email inside Microsoft 365. Here is what that means for your DMARC alignment, data exposure, and compliance posture.
-
DMARC
How Exchange Online Sender-Domain Connectors Create a Spoofing Blind Spot
Exchange Online sender-domain connectors rewrite the RFC 5321 Mail From address, which silently breaks DMARC alignment. The admin center shows the connector as authenticated, but receiving servers see a From header mismatch. Here is how that gap works and how to find it in your DMARC reports.
-
Deliverability
Device-Code Phishing: How Attackers Bypass MFA Through OAuth
OAuth device-code phishing is an attack technique that tricks users into authenticating on a legitimate Microsoft login page, bypassing most MFA methods. Here is how it works and how to detect it.
-
DMARC
Why ARC Is Being Retired in 2026 - and What Email Operators Need to Do Before Then
The IETF is marking ARC (RFC 8617) as Historic in 2026. Here is what email operators need to know about the timeline, what breaks, and how to prepare.
-
DMARC
Why Your Email Security Filter Keeps Rejecting Legitimate Messages (And How to Fix DMARC)
Third-party email security filters (Proofpoint, Mimecast, etc.) reject legitimate email citing DMARC even when SPF and DKIM pass. Here is why this happens and how to fix it.
-
SPF
Why SPF Passing Does Not Mean an Email Is Safe (And What Actually Secures Your Inbox)
SPF passing is often treated as proof an email is legitimate. It is not. Here is what SPF actually checks, what it misses, and how DKIM and DMARC close the gap.