Blogs
-
Deliverability
Should You Build a Copilot Agent for Phishing Detection? A Framework for IT Teams
Practical framework for IT teams on Microsoft 365 evaluating whether a custom Copilot or Power Automate agent adds real phishing detection value or just more noise.
-
DMARC
Why Your Domain Can Still Be Spoofed Even With SPF, DKIM, and DMARC
SPF, DKIM, and DMARC all passing does not mean your domain cannot be spoofed. The direct send attack exploits a gap between these protocols that many administrators do not realize exists.
-
DMARC
Why Third-Party Email Security Services Reject Emails from Domains with No DMARC Policy
When a vendor like Proofpoint or Mimecast rejects your emails because your domain has no DMARC policy, here is what is happening and how to fix it.
-
The State of Email Security Across the Top Million Domains
A monthly research project measured DMARC, MTA-STS, DANE, and BIMI adoption across the top one million domains for two months running — here is what the data shows.
-
DMARC
Why Your Postfix Emails Still Get Rejected by Gmail Even When SPF and DKIM Pass
SPF and DKIM both pass but your email still fails DMARC. The issue is alignment. Here is what alignment means, why Postfix servers trip it up, and how to fix it.
-
DMARC
What DMARC, MTA-STS, DANE, and BIMI Adoption Actually Looks Like Across the Top Million Domains
Measurement data from the top million domains reveals where email security protocols actually stand - and why published adoption numbers often overstate enforcement.
-
DKIM
DKIM2 and DMARCbis: What the New Standards Change for Email Authentication
DKIM2 and DMARCbis are incoming standards that will reshape how email authentication works. Here is what each changes, what stays the same, and how to prepare.
-
Deliverability
How to Find and Fix an Undocumented Mail Relay That Bypasses Gmail Spam Filters
Gmail is letting spam through from your domain, but your email security setup looks fine. The culprit is usually an undocumented or forgotten internal mail relay forwarding mail through Gmail in a way that bypasses the normal spam filter chain. Here is how to find it and close the gap.
-
Deliverability
Ghost Send: How M365 URL Decryption Enables OAuth Token Theft
Ghost Send exploits M365 URL rewriting to trick the security scanner into triggering an OAuth flow that hands tokens to attackers.
-
DMARC
The Hidden Risks of AI in DMARC Monitoring: What Can Go Wrong
AI-enabled DMARC tools promise automation and ease, but they introduce specific risks: misconfigured policies, false confidence from summaries, and diagnostic blind spots. Here is what practitioners need to know.