August 26, 2026
Switching email providers without breaking DMARC
Migrating between Microsoft 365 and Google Workspace without breaking DMARC: additive SPF, DKIM proven before cutover, then purging the old provider.
Read →August 26, 2026
Migrating between Microsoft 365 and Google Workspace without breaking DMARC: additive SPF, DKIM proven before cutover, then purging the old provider.
Read →August 25, 2026
A CNAME at _dmarc resolves fine: the TXT at the end of the chain applies. Legitimate uses, the traps, the loss of policy control, verification with dig.
Read →August 25, 2026
A valid DKIM signature stays replayable as long as the body and signed headers don't change. How replay spreads spam under a borrowed reputation.
Read →August 24, 2026
A misplaced v tag, a missing p, rua without mailto:, duplicate records, stray quotes: the common DMARC record errors, and the fix for each one.
Read →August 24, 2026
Complaints, surging RUA reports, waves of bounce-backs: how a domain spoofing incident is recognized, measured and resolved, all the way to p=reject.
Read →August 24, 2026
The SPF 255-character limit is a DNS rule: 255 bytes per string of a TXT record, not per record. How splitting works, where it breaks, and the fixes.
Read →August 23, 2026
A mailing list edits each message and resends it from its own servers: DKIM breaks, SPF loses alignment, DMARC fails. List-side fixes and what ARC saves.
Read →August 23, 2026
A domain may publish only one SPF record: a second v=spf1 turns every check into permerror. How duplicates appear, the diagnosis, and the correct merge.
Read →August 22, 2026
What the monthly Observatory barometer measures across French banking domains: DMARC presence, effective policy, and the gap between groups and brands.
Read →August 22, 2026
The anatomy of a message's headers: Authentication-Results, DKIM-Signature, Received, ARC. Where to find them, how to read them, what they prove.
Read →