DMARC Engine
Home/Blog/Tagged “compliance”
Blog

Tagged “compliance”

12 articles

23 May 2026 · 12 min read

PCI DSS 4.0, cyber-insurance and email authentication

PCI DSS 4.0 Requirement 5.4.1 and cyber-insurance questionnaires now treat anti-phishing as a measurable control. Here is exactly how that intersects with DMARC, SPF and DKIM, what counts as evidence, and how to reach enforcement without breaking your own mail.

Read more
23 May 2026 · 13 min read

Email authentication for accountants

Accountancy practices are prime impersonation targets: you hold client bank details, your clients act on what you tell them, and the tax calendar is public. This guide covers the four fraud patterns a practice actually faces, exactly where DMARC, SPF and DKIM stop them, and a deadline-aware enforcement plan to reach p=reject without breaking client mail.

Read more
19 May 2026 · 12 min read

The 2024 and 2025 bulk-sender requirements in full

Google, Yahoo and Microsoft turned email authentication into a hard delivery gate. Here are the exact requirements, the numeric thresholds, who counts as a bulk sender, and a line-by-line compliance checklist.

Read more
17 May 2026 · 14 min read

Email authentication for e-commerce

Online shops send order, shipping and receipt mail from a dozen different systems at once. Here is how to authenticate every stream, meet the Gmail, Yahoo and Microsoft bulk-sender rules, block order-confirmation phishing, and earn your brand logo in the inbox with BIMI.

Read more
16 May 2026 · 13 min read

Email authentication for schools and universities

A practical, stage-by-stage path to DMARC enforcement on a sprawling .edu or .ac.uk estate: discovery, fixing SPF under the ten-lookup limit, aligning DKIM across many departmental senders, ramping to p=reject, and the governance traps that stall most rollouts.

Read more
14 May 2026 · 13 min read

Email authentication for financial services

For banks, insurers and fintechs, DMARC, SPF, DKIM, MTA-STS and BIMI are anti-fraud and brand-protection controls, not deliverability tweaks. How to meet regulatory expectations and reach p=reject across a multi-vendor estate without breaking OTP or statement mail.

Read more
12 May 2026 · 13 min read

Email authentication for government

Public-sector domains are prime spoofing targets because the state's authority is the most valuable brand a fraudster can wear. Here is why government email is forged, the mandates pushing departments to p=reject, and the engineering realities of getting a sprawling government estate to enforcement without cutting off citizen mail.

Read more
11 May 2026 · 14 min read

Email authentication for healthcare and HIPAA

HIPAA never names DMARC, but it asks for exactly what SPF, DKIM and DMARC deliver: protection of transmitted PHI, integrity, sender authentication and ongoing risk management. Here is how email authentication maps onto the HIPAA Security Rule, why DMARC reporting need not expose PHI, and the staged path to p=reject that does not break clinical email.

Read more
7 May 2026 · 11 min read

Email authentication for law firms

How solicitors use SPF, DKIM and DMARC to stop their domain being spoofed, protect client money on completions, and meet their confidentiality duties, with a staged, no-outage path to p=reject.

Read more
2 May 2026 · 14 min read

Email authentication for nonprofits

For charities, DMARC is donor trust and fundraising revenue expressed as DNS records: it stops attackers spoofing your appeals and lifts your own appeals out of the spam folder. Here is how to align every sender, ramp safely to p=reject, and put your logo in the inbox, including via a Common Mark Certificate when your charity logo is not a registered trademark.

Read more
28 April 2026 · 12 min read

Email authentication for SaaS companies

SaaS companies send several distinct mail streams at once: transactional, product, marketing and customer-generated. This guide shows how to structure SPF, DKIM, DMARC, MTA-STS and BIMI by subdomain so a bad day on one stream never poisons your password resets, and how to reach p=reject across every domain without an outage.

Read more
10 April 2026 · 14 min read

GDPR and DMARC reporting

DMARC reports can contain personal data: source IPs in aggregate reports, and recipients, subjects and message bodies in forensic reports. Here is which fields the UK and EU GDPR catch, why forensic (ruf) reporting is the real hazard most domains should drop, and the lawful basis, retention and transfer practices that keep aggregate (rua) collection compliant.

Read more