August 06, 2026
GDPR and email authentication: two angles not to confuse
GDPR meets DMARC twice: authentication is an Article 32 security measure, and DMARC reports themselves hold personal data. How to handle both angles.
Read →August 06, 2026
GDPR meets DMARC twice: authentication is an Article 32 security measure, and DMARC reports themselves hold personal data. How to handle both angles.
Read →August 05, 2026
DMARC is textbook ISO 27001 evidence: public posture, continuous reports, key management. How email authentication maps onto Annex A controls.
Read →August 05, 2026
DORA demands demonstrable digital resilience from EU financial entities, and a spoofable domain is an obvious risk. Where DMARC fits, and the roadmap.
Read →August 05, 2026
NIS2 never names DMARC, yet it mandates anti-phishing measures where email authentication is the obvious auditable control. Who is in scope, what to do.
Read →August 04, 2026
Phishing sent from a company's own domain hijacks the trust customers place in the brand. How the attack vector works, and the measures that prevent it.
Read →August 04, 2026
A three-minute test tells whether anyone can send mail claiming to come from a domain. What to check, how to read the result, and what comes next.
Read →August 03, 2026
CEO fraud (BEC) needs no malware: it borrows hierarchical trust to obtain an urgent transfer. How it works, its variants, and the defenses that stop it.
Read →August 03, 2026
Email spoofing hits organizations of every size. The concrete defenses in priority order: DMARC at enforcement, subdomains, lookalikes, team training.
Read →August 03, 2026
Spoofing means forging an email's sender to deceive the recipient. How it works technically, why it stayed possible for decades, and how DMARC ends it.
Read →August 01, 2026
By default Mailchimp signs with its own domain: nothing aligns for DMARC. The CNAMEs to publish, RUA reports before and after, the dedicated subdomain.
Read →