Blogs
-
DMARC
Why Email Authentication Passing Does Not Mean the Sender Is Safe
Email authentication (SPF, DKIM, DMARC) proves a sender is authorized to use a domain. It does not prove the message is trustworthy. Here is what the difference means for your security posture.
-
Deliverability
Chat-Based DNS Change Approvals Are a Security Risk
Approving DNS changes over Slack or Teams is common but risky. Here is what can go wrong, what a secure approval workflow needs, and how to detect problems when they happen anyway.
-
DMARC
Why Exchange Online Shared Mailboxes Fail DMARC When p=reject Is Enabled
Exchange Online shared mailboxes send through M365 infrastructure, causing DMARC alignment failures when p=reject is enforced. Here is the root cause and how to fix it.
-
DMARC
Why Third-Party Senders Break DMARC and How to Fix Subdomain Delegation
Third-party senders (CRM, marketing, billing) often break DMARC because they send from their own servers using your From domain. This guide explains why it happens and how to fix it using subdomain delegation.
-
DMARC
Why Your Own DMARC Monitoring Missed That Your Domain Was About to Be Rejected
A real near-miss reveals why DMARC monitoring setups still miss the signals that predict mail rejection, even when reports are configured.
-
DMARC
Why a Passing DMARC Record Does Not Mean Your Email Is Secure
DMARC pass only proves a sender was allowed to use a domain name. It does not prove the message is legitimate, the sender's account is uncompromised, or the content is safe.
-
DMARC
Can someone spoof my email address even with DMARC?
DMARC stops direct domain spoofing but has a specific blind spot: forwarded mail and mailing lists that re-envelope the message. Here is exactly what it can and cannot catch.
-
DMARC
Why a Passing DMARC Record Does Not Mean Your Email Is Safe
DMARC pass only tells you the sender was authorized to use that domain name. It says nothing about whether the message is legitimate, the account is uncompromised, or the content is safe. Here is what DMARC actually guarantees.
-
DMARC
Why Mail Still Fails After You Set DMARC to p=reject (And How to Find the Subdomain SPF Gaps First)
Moving to DMARC p=reject breaks legitimate mail when subdomains send without their own SPF records. Here is how to find and fix subdomain SPF gaps before they cause an outage.
-
DMARC
What SMB1001:2026 Changed for MSP Email Authentication
SMB1001:2026 gives MSPs a structured baseline for email authentication across client domains. Here is what changed, what it covers, and how to start applying it.