Blogs
-
DMARC
Device-Code Phishing: Why Mailbox Persistence Changes the Risk Profile
Device-code phishing tricks users into authenticating via an attacker-controlled device code. This explainer covers how the attack works, why mailbox persistence makes it far more dangerous than standard token theft, and how defenders can detect it.
-
DMARC
How Exchange Online Sender-Domain Connectors Become a Spoofing Risk on Shared Relays
Domain-scoped Exchange Online connectors without IP or certificate constraints let any customer on a shared relay send as your domain. Here is how to find and fix this gap.
-
DKIM
Why Your DKIM Signatures Break After an OpenDKIM Upgrade (and How to Fix It)
Upgrading OpenDKIM can silently break DKIM validation if the private key path changes. Here is what to check and how to recover fast.
-
DMARC
How to Move Your DMARC Policy from p=none to p=reject Without Breaking Mail
Step-by-step guide to tightening your DMARC policy from monitor mode to reject, without disrupting legitimate email. Covers reading aggregate reports, classifying sending sources, fixing common failures, and knowing when you are ready.
-
DMARC
Why Third-Party Email Security Gateways Cause Sudden DMARC Failures on Legitimate Mail
Third-party email security gateways can silently break DMARC for your legitimate mail by changing how they relay messages. Here is why it happens, how to spot it, and what to do about it.
-
Deliverability
What Happens to Your Email Security When You Switch from Mimecast to Proofpoint
Switching SEG vendors sounds straightforward until you realize your DMARC monitoring depends on whoever processes your aggregate reports. Here is what changes when you move from Mimecast to Proofpoint.
-
Deliverability
What Gmail Postmaster Tools Tells You About Your Sending Reputation (and Why It Matters)
Gmail Postmaster Tools shows your custom domain's sending reputation. Here is what the metric means, why your domain might not appear, and how to improve your score.
-
How to Decommission Exchange Server When Mail-Enabled Security Groups Control NTFS File Permissions
Moving mail-enabled security groups to Microsoft 365 when those groups also control NTFS file share permissions requires a specific sequence. Here is the step-by-step process that keeps file access intact while migrating mail to the cloud.
-
Deliverability
Why Gmail Postmaster Tools Shows Compliance Needs Improvement When Authentication Is Perfect
Gmail Postmaster Tools sometimes shows a compliance score of "needs improvement" even when SPF, DKIM, and DMARC all pass at 100 percent. Here is why and what to do about it.
-
DMARC
How a Forgotten SPF Record Silently Breaks DMARC p=reject on Your Sending Subdomain
A sending subdomain with a missing SPF include silently fails DMARC alignment under p=reject, blocking legitimate mail with no bounce notification. Here is how to find it and fix it.