Blogs
-
DMARC
The DMARC Blind Spot That Breaks Your Mail Before You Know Something Is Wrong
Your DMARC aggregate reports might be telling you less than you think. Subdomains that inherit your p=reject policy can silently fail DMARC without any application log showing a problem. Here is what the blind spot looks like and how to close it.
-
Deliverability
How Device-Code Phishing Grants Persistent Mailbox Access in Microsoft 365
Device-code phishing lets attackers steal Microsoft 365 tokens that survive password resets. Here is how the attack works, why token rotation does not stop it, and which Entra ID controls actually break it.
-
Deliverability
Why Forwarded Emails Land in Gmail Spam Even When Your SPF, DKIM, and DMARC Are Correct
Gmail auto-forwarding breaks email authentication in a way that is invisible to most senders. Here is what happens and how to detect it.
-
DMARC
Why Email Transit Security Is More Than a Decade Behind Sender Authentication
Monthly measurements across the top million domains show a widening gap between sender authentication (DMARC) and transit security (MTA-STS, DANE). Here is what drives that gap and what it means for your domain.
-
DMARC
What Breaks When You Move to DMARC p=reject (And How to Fix It First)
Moving to DMARC p=reject silently breaks legitimate email when SPF or DKIM alignment is not configured first. Here is how to audit your sending sources and fix alignment before you flip the switch.
-
Deliverability
Why Your Newsletter Triggers Phishing Alerts: How Recipient Gateway Prefetching Breaks Your Mail
Gateway scanners prefetch your tracked newsletter links and file false phishing complaints. Here is why it happens, how to diagnose it, and what you can do about it without removing link tracking.
-
DMARC
Why Exchange Online Sender-Domain Connectors Make Your Email Security Look Better Than It Is
Exchange Online sender-domain connectors pass DMARC alignment in a way that looks like good email hygiene, but the underlying sending infrastructure is controlled by Microsoft. Here is what practitioners miss and how to see the real picture.
-
DMARC
How Exchange Online Connectors Create a Spoofing Blind Spot (And What DMARC Reports Reveal)
The Exchange Online admin center shows a connector as safe when it matches your sending domain. What it does not show is the shared relay infrastructure behind that connector, and how a misconfiguration there opens your domain to spoofing even when your DMARC policy is set to reject.
-
Deliverability
What Does an RFC 822 Failure Mean for Email Delivery? Diagnosis and Fix
An RFC 822 failure usually means a mail server rejected your message because the headers do not meet the email format standard. Here is how to find the cause and fix it.
-
DMARC
How Exchange Online Connectors Create a Spoofing Blind Spot (And What DMARC Reports Reveal)
The Exchange Online admin center shows a connector as safe when it matches your sending domain. What it does not show is the shared relay infrastructure behind that connector, and how a misconfiguration there opens your domain to spoofing even when your DMARC policy is set to reject.