Practical guides to email authentication — SPF, DKIM, DMARC, and the safe path to p=reject.
August 11, 2026
BIMI displays a brand's logo next to its emails in supporting inboxes — but only if the domain is at DMARC enforcement. What BIMI is, how to publish it, and why it's the reward for p=reject.
Read →August 10, 2026
An online merchant plays two stakes on its domain: the deliverability of transactional email, and customer trust against spoofing. DMARC serves both. Why and how.
Read →August 10, 2026
Hospitals, labs, insurers and practices handle some of the most sensitive data and command immediate trust — an ideal cocktail for spoofing. Why healthcare is targeted, and how to close the door.
Read →August 08, 2026
Councils, agencies and public bodies are among the most spoofed — and often the least protected — identities. Why the public sector is a target, what the data shows, and how to act despite limited resources.
Read →August 07, 2026
SPF, DKIM and DMARC all live in DNS. Without DNSSEC, anyone able to poison resolution can serve a permissive SPF or make the policy disappear. What zone signing actually protects — and what it does not.
Read →August 06, 2026
GDPR meets DMARC in two ways: email authentication is a security measure under Article 32, and DMARC reports themselves can contain personal data. How to handle both properly.
Read →August 05, 2026
ISO 27001 rewards controls that produce verifiable evidence. DMARC is a textbook case: public posture, continuous reports, cryptographic key management. How to map it to Annex A.
Read →August 05, 2026
DORA requires EU financial entities to demonstrate digital operational resilience, and a spoofable domain is an obvious risk. What the regulation covers, why DMARC fits, and how to implement it.
Read →August 05, 2026
NIS2 never names DMARC, yet it mandates anti-phishing and resilience measures where email authentication is an obvious, auditable control. Who is in scope, what changes, and what to do about it now.
Read →August 04, 2026
Phishing that uses a company's own domain name hijacks the trust its customers place in the brand. How this attack vector works, and the concrete measures to prevent it.
Read →August 04, 2026
A three-minute test to know whether anyone can send an email claiming to come from a given domain. What to check, how to read the result, and the next step.
Read →August 03, 2026
CEO fraud exploits hierarchical trust to extort urgent wire transfers. How the attack works, why it still succeeds, and the technical and organizational defenses that stop it.
Read →August 03, 2026
Email spoofing hits organizations of every size. Here are the concrete defenses — technical and organizational — that actually protect a domain, beyond DMARC alone.
Read →August 03, 2026
Spoofing means forging an email's sender to deceive the recipient. How it works technically, why it stayed possible for decades, and how DMARC ends it.
Read →August 01, 2026
By default Mailchimp signs with its own domain: nothing aligns for DMARC. The CNAME records to publish, what RUA reports show before and after, and the dedicated subdomain.
Read →August 01, 2026
SendGrid's domain authentication rests on three delegated CNAMEs. How it works, key rotation, SPF and DKIM alignment, common mistakes and RUA verification.
Read →August 01, 2026
TLS-RPT reports encrypted-connection failures between mail servers — the DMARC-report counterpart for MTA-STS. What it contains, how to configure it, and why it's essential before hardening MTA-STS.
Read →July 29, 2026
MTA-STS enforces SMTP transport encryption and prevents a downgrade to plaintext. What it protects, how to deploy it, and its relationship to DMARC.
Read →July 29, 2026
Domain validation at Mailjet, the SPF include, the mailjet._domainkey DKIM record and DMARC alignment: the full path, with the mistakes seen in real DNS zones.
Read →July 28, 2026
After Gmail and Yahoo, Microsoft tightened its own rules for Outlook.com and Hotmail. What's required, how it differs from Google, and how to comply.
Read →July 28, 2026
Without domain-aligned DKIM, Brevo campaigns hit a deliverability ceiling. The mail._domainkey setup, the SPF envelope question and the proof in RUA reports.
Read →July 27, 2026
DKIM is off by default on a Google Workspace domain. Generating the 2048-bit key, publishing the google._domainkey TXT, header checks and DMARC alignment.
Read →July 27, 2026
SPF and DKIM pass, DMARC is aligned, and yet the mail lands in junk. This diagnostic guide covers the causes authentication alone doesn't solve.
Read →July 26, 2026
Microsoft 365 signs with onmicrosoft.com by default — a signature DMARC cannot align. Defender portal, PowerShell, the two CNAMEs: the full walkthrough.
Read →July 26, 2026
Why emails land (or don't) in Gmail's Primary tab. Authentication, reputation, engagement: everything that determines deliverability, explained in depth.
Read →July 25, 2026
Cloudflare hosts the DNS zone, whatever mailbox sits behind it. Placing the _dmarc and SPF TXT records, DKIM selector CNAMEs, proxy status and flattening.
Read →July 25, 2026
A DMARC record is published, but no reports arrive. Here are the possible causes, in the order to check them, from the most common to the most subtle.
Read →July 24, 2026
The rua address receives the DMARC aggregate reports. The syntax is simple, but sending to an external domain hides an authorization trap many discover too late.
Read →July 24, 2026
GandiMail, LiveDNS, the _mailcust.gandi.net include, the gm1 to gm3 DKIM selectors: the complete path to authenticating email for a domain hosted at Gandi.
Read →July 23, 2026
Ready-to-paste DMARC record templates — monitoring, quarantine, reject, parked domain — with per-provider settings and the publishing pitfalls to avoid.
Read →July 23, 2026
MX Plan, Email Pro or Exchange: each OVHcloud email plan has its own SPF and DKIM records. DNS zone, the default SPF trap, CNAME selectors and verification.
Read →July 22, 2026
Hardening the root domain isn't enough if the subdomains stay open. How the sp and np tags close that side door — including non-existent subdomains.
Read →July 21, 2026
The pct tag hardened DMARC in percentage steps. DMARCbis removed it. Here's how to run a safe, gradual rollout without it.
Read →July 20, 2026
The two enforcing DMARC policies don't share the same risk profile. What each actually does to failing mail, and how to decide for a given domain.
Read →July 19, 2026
A concrete checklist of the conditions to meet before hardening a DMARC policy from p=none to p=reject — enforcement without a single legitimate email bounced.
Read →July 18, 2026
DMARC RUF reports can contain personal data from senders. What RUF contains, why few ISPs still send them, and how to stay GDPR-compliant.
Read →July 17, 2026
The ri= parameter in DMARC controls the desired reporting interval. In practice, ISPs often ignore it. What ri= means, real-world values, and why 86400 is the standard.
Read →July 16, 2026
DMARC reports are raw XML. Tools exist to aggregate, visualize and turn them into an action plan. An overview of free and paid options, and how to choose.
Read →July 15, 2026
A DMARC RUA report is a compressed XML file. This guide dissects the structure, explains each useful tag, and shows how to turn that XML into an action plan.
Read →July 15, 2026
SPF macros with the exists mechanism authorize an unlimited number of IPs in a single DNS lookup — the only technique that truly bypasses the limit of 10. How it works, and its real trade-offs.
Read →July 14, 2026
DMARC generates two types of reports: RUA (aggregate, statistical) and RUF (forensic, per-message). What they contain, who sends them, and which one actually matters.
Read →July 13, 2026
Verifying a DKIM signature means reading the DKIM-Signature header and the Authentication-Results, then confirming alignment. The methods, the key tags, and why a signature fails.
Read →July 12, 2026
2048 bits is the recommended DKIM standard, more robust than the aging 1024. But 2048 raises a DNS trap (the 255-character limit). How to choose and publish without error.
Read →July 11, 2026
Rotating DKIM keys regularly limits the impact of a leak. The right method (dual selector), the frequency, the trap of removing the old one too early, and where to store the private keys.
Read →July 10, 2026
Generating a DKIM key means creating a private/public key pair, keeping one secret and publishing the other in DNS. The steps, the size choice, and the alignment trap.
Read →July 09, 2026
The DKIM selector is what lets a receiver find the right public key to verify a signature. What it is, where it appears, and why a domain often has several.
Read →July 08, 2026
Configuring SPF for Microsoft 365 and Google Workspace, separately or together, without exceeding the 10-lookup limit. The right includes, the pitfalls, and the strategy for third parties.
Read →July 07, 2026
An SPF PermError means the record is impossible to evaluate — so it's ignored. The causes (10 lookups, syntax, void lookups, duplicate record), how to diagnose and repair them.
Read →July 06, 2026
Checking an SPF record isn't just confirming it exists: it's reading its syntax, resolution count, qualifier and alignment. The complete, step-by-step guide.
Read →July 05, 2026
The terminal mechanism of an SPF record (-all, ~all, ?all, +all) tells receivers what to do with unlisted mail. What each one means, how they interact with DMARC, and which to publish.
Read →July 04, 2026
SPF flattening replaces includes with the IP addresses they resolve to, to get back under the 10-lookup limit. How it works, its maintenance risks, and the alternatives.
Read →July 03, 2026
The PermError 'too many DNS lookups' breaks an SPF record the moment it exceeds 10 resolutions. Why the limit exists, what counts, and how to get back under it without breaking mail.
Read →July 02, 2026
DMARCbis replaces RFC 7489 but stays backward-compatible. What should (and shouldn't) change in the record, in what order, and how to verify everything is fine.
Read →July 01, 2026
DMARCbis removes the pct tag and replaces it with a binary testing mode, the t= tag. Why pct is gone, how t=y works, and how to roll out DMARC gradually today.
Read →June 30, 2026
DMARCbis replaces the Public Suffix List with the DNS Tree Walk to determine the organizational domain. How it works, why it's more robust, and what it changes in practice.
Read →June 29, 2026
DMARCbis adds the np tag for non-existent subdomains — a spoofing gap that sp never covered. What it does, how it differs from sp, and how to set it.
Read →June 28, 2026
DMARCbis is made of three RFCs that replace 7489. What each one contains, the exact list of tags added and removed, and what it means for the record.
Read →June 27, 2026
DMARCbis was published in May 2026 and replaces RFC 7489. What this 'DMARC V2' is, what changes (np, t, DNS Tree Walk), what stays the same, and whether action is needed.
Read →June 16, 2026
Banks are among the most impersonated brands on earth — yet many still don't enforce DMARC. Why finance is a prime target, what the data shows, and how to fix it.
Read →June 16, 2026
A safe, staged path from DMARC monitoring (p=none) to full enforcement (p=reject) — without blocking a single legitimate message.
Read →June 16, 2026
Since 2024, Gmail and Yahoo require bulk senders to authenticate with SPF, DKIM and DMARC. Here's exactly what's required, who's affected, and how to comply.
Read →June 16, 2026
SPF, DKIM and DMARC are not competitors — they're three layers that stack. Here's what each one does, why alignment matters, and how they combine to stop spoofing.
Read →June 16, 2026
DMARC aggregate reports are the map to enforcement. What's inside the XML, how to read it, and how daily reports turn into a path to p=reject.
Read →June 16, 2026
A plain-English guide to DMARC: what it is, how it builds on SPF and DKIM, what the policies mean, and what DMARCbis (RFC 9989) changes in 2026.
Read →June 15, 2026
A plain-English guide to DKIM (RFC 6376): the cryptographic signature, the DNS record, selectors, rotation, 1024 vs 2048 bits, and why DMARC is still needed on top.
Read →June 14, 2026
A plain-English guide to SPF (RFC 7208): what it is, the DNS record, the include/ip4/a/mx mechanisms, the 10-lookup limit, and why SPF alone isn't enough.
Read →