Blogs
-
Deliverability
The OAuth Device Code Attack That Slips Past Every Email Filter
Attackers are using Microsoft's own OAuth device authorization flow to bypass MFA and steal session tokens. Here is how the attack works and which Conditional Access policies actually stop it.
-
DMARC
Why DMARC Fails When SPF Passes (And What to Do About It)
SPF checks if the sending server is authorized. DMARC checks if the envelope sender domain aligns with the From header domain. When those two domains differ, SPF passes but DMARC fails. Here is why and how to fix it.
-
Deliverability
How to Replace Manual PST Contact Exports in Hybrid Exchange Environments
Manual PST exports for contact sync are a 2019-era workaround that becomes technical debt at scale. Here is how to replace them with automated, rotation-aware contact synchronization in hybrid Exchange environments.
-
BIMI
How to Get BIMI Working: The Prerequisites Most Teams Skip
BIMI looks simple on paper. Add a logo record, wait for inboxes to pick it up. The reality is a strict prerequisite chain that trips up most teams before they see a single logo. Here is what you need first.
-
Deliverability
Why the iOS Native Mail App Cannot Access Shared Mailboxes in Microsoft 365 (2026)
The iOS native Mail app cannot connect to shared mailboxes in Exchange Online because Apple uses a protocol Microsoft no longer fully supports for that scenario. Here is why and what to use instead.
-
DMARC
How to Know When You Are Ready to Move to DMARC p=reject
A practical checklist for moving from DMARC p=none to p=reject without breaking legitimate email.
-
Deliverability
Opening an Email Should Not Mean Handing Over Your Session: Zimbra Stored XSS Explained
A stored XSS vulnerability in Zimbra Classic Web Client lets an attacker hijack a user session by sending a crafted email. No link click required. Here is what administrators need to know.
-
How Attackers Bypass AI Email Filters with Invisible Unicode Text
AI-powered email security filters can be defeated using invisible Unicode characters. Here is how the attack works and which defenses hold up.
-
DMARC
The DMARC Implementation Mistakes That Break Email (And How to Avoid Them)
Moving to DMARC p=reject without proper preparation is the number one way to break legitimate email. This guide covers the five most common DMARC implementation mistakes and the step-by-step process to migrate safely.
-
Deliverability
Why Your Phishing Report Button Is Missing from Outlook Mobile
The phishing report add-in shows as deployed in Microsoft 365 admin, but the button never appears in Outlook mobile. Here is what causes this and how to fix it.