August 05, 2026
NIS2 and email authentication: what the directive actually expects
NIS2 never names DMARC, yet it mandates anti-phishing measures where email authentication is the obvious auditable control. Who is in scope, what to do.
Read →August 05, 2026
NIS2 never names DMARC, yet it mandates anti-phishing measures where email authentication is the obvious auditable control. Who is in scope, what to do.
Read →August 04, 2026
Phishing sent from a company's own domain hijacks the trust customers place in the brand. How the attack vector works, and the measures that prevent it.
Read →August 04, 2026
A three-minute test tells whether anyone can send mail claiming to come from a domain. What to check, how to read the result, and what comes next.
Read →August 03, 2026
CEO fraud (BEC) needs no malware: it borrows hierarchical trust to obtain an urgent transfer. How it works, its variants, and the defenses that stop it.
Read →August 03, 2026
Email spoofing hits organizations of every size. The concrete defenses in priority order: DMARC at enforcement, subdomains, lookalikes, team training.
Read →August 03, 2026
Spoofing means forging an email's sender to deceive the recipient. How it works technically, why it stayed possible for decades, and how DMARC ends it.
Read →August 01, 2026
By default Mailchimp signs with its own domain: nothing aligns for DMARC. The CNAMEs to publish, RUA reports before and after, the dedicated subdomain.
Read →August 01, 2026
SendGrid's domain authentication rests on three delegated CNAMEs. How it works, key rotation, SPF and DKIM alignment, common mistakes and RUA verification.
Read →August 01, 2026
TLS-RPT reports encrypted-connection failures between mail servers, the aggregate report of MTA-STS. Contents, setup, and why it comes before enforce.
Read →July 29, 2026
MTA-STS enforces SMTP transport encryption and prevents a downgrade to plaintext. What it protects, how to deploy it, and its relationship to DMARC.
Read →