Blogs
-
DMARC
Why Third-Party Email Security Gateways Cause Sudden DMARC Failures on Legitimate Mail
Third-party email security gateways can silently break DMARC for your legitimate mail by changing how they relay messages. Here is why it happens, how to spot it, and what to do about it.
-
Deliverability
What Happens to Your Email Security When You Switch from Mimecast to Proofpoint
Switching SEG vendors sounds straightforward until you realize your DMARC monitoring depends on whoever processes your aggregate reports. Here is what changes when you move from Mimecast to Proofpoint.
-
Deliverability
What Gmail Postmaster Tools Tells You About Your Sending Reputation (and Why It Matters)
Gmail Postmaster Tools shows your custom domain's sending reputation. Here is what the metric means, why your domain might not appear, and how to improve your score.
-
How to Decommission Exchange Server When Mail-Enabled Security Groups Control NTFS File Permissions
Moving mail-enabled security groups to Microsoft 365 when those groups also control NTFS file share permissions requires a specific sequence. Here is the step-by-step process that keeps file access intact while migrating mail to the cloud.
-
Deliverability
Why Gmail Postmaster Tools Shows Compliance Needs Improvement When Authentication Is Perfect
Gmail Postmaster Tools sometimes shows a compliance score of "needs improvement" even when SPF, DKIM, and DMARC all pass at 100 percent. Here is why and what to do about it.
-
DMARC
How a Forgotten SPF Record Silently Breaks DMARC p=reject on Your Sending Subdomain
A sending subdomain with a missing SPF include silently fails DMARC alignment under p=reject, blocking legitimate mail with no bounce notification. Here is how to find it and fix it.
-
DMARC
The DMARC Blind Spot That Breaks Your Mail Before You Know Something Is Wrong
Your DMARC aggregate reports might be telling you less than you think. Subdomains that inherit your p=reject policy can silently fail DMARC without any application log showing a problem. Here is what the blind spot looks like and how to close it.
-
Deliverability
How Device-Code Phishing Grants Persistent Mailbox Access in Microsoft 365
Device-code phishing lets attackers steal Microsoft 365 tokens that survive password resets. Here is how the attack works, why token rotation does not stop it, and which Entra ID controls actually break it.
-
Deliverability
Why Forwarded Emails Land in Gmail Spam Even When Your SPF, DKIM, and DMARC Are Correct
Gmail auto-forwarding breaks email authentication in a way that is invisible to most senders. Here is what happens and how to detect it.
-
DMARC
Why Email Transit Security Is More Than a Decade Behind Sender Authentication
Monthly measurements across the top million domains show a widening gap between sender authentication (DMARC) and transit security (MTA-STS, DANE). Here is what drives that gap and what it means for your domain.