DMARC Engine
Home/Blog/Tagged “deliverability”
Blog

Tagged “deliverability”

33 articles

18 June 2026 · 11 min read

The Google and Yahoo sender rules, one year on

A year after Google and Yahoo made authentication mandatory for bulk senders, here is what changed, how mail failed, and where enforcement is heading.

Read more
1 June 2026 · 11 min read

How to reach DMARC p=reject without breaking email

The staged playbook to DMARC enforcement with no email outage: inventory senders, fix SPF and DKIM, ramp p=none to p=reject, and lock down subdomains.

Read more
15 July 2026 · 38 min read

DMARC and Email Migration: A Step-by-Step Guide to Preserving Deliverability

Email migration can impact deliverability, DMARC helps prevent spoofing by verifying email authenticity

Read more
9 June 2026 · 11 min read

Protecting parked and no-mail domains

Domains that never send mail are the easiest to secure and the most commonly left wide open. Here is how to lock down parked, legacy and campaign domains with SPF -all, DMARC p=reject and a null MX so they cannot be spoofed, with zero deliverability risk.

Read more
7 June 2026 · 14 min read

Amazon SES at scale: deliverability and DMARC

Amazon SES is deceptively easy to start with and deceptively hard to run well at volume. Verifying a domain, adding three DNS records and firing your first message takes an afternoon.

Read more
6 June 2026 · 16 min read

SendGrid dedicated IPs, authentication and reputation

Most teams reach for a SendGrid dedicated IP because someone told them shared IPs are bad, or because a deliverability vendor implied that owning your own IP is the professional thing to do.

Read more
5 June 2026 · 11 min read

Bounce handling and the return-path

The envelope return-path is where bounces come back to and the domain SPF authenticates. Here is how a custom return-path on your own subdomain fixes SPF alignment under DMARC, and what really happens to a bounce.

Read more
5 June 2026 · 15 min read

DMARC for Mailchimp users: a deliverability checklist

If you send marketing email through Mailchimp, you sit in an awkward spot. You do not run your own mail servers, you do not control the IP addresses your campaigns go out on, and yet your From: address still says.

Read more
3 June 2026 · 11 min read

What DMARC reports do and do not tell you

Passing DMARC is permission to be judged on your merits, not a guaranteed seat in the inbox. Here is how to read aggregate reports for exactly what they measure, identity and authentication, without mistaking a perfect pass rate for good deliverability or panicking at failures that do not matter.

Read more
2 June 2026 · 12 min read

Dedicated vs shared sending IPs

Dedicated and shared sending IPs carry very different reputation trade-offs, and the right choice hinges on sustained volume, not folklore. Here is who should use which, and how the decision changes SPF, DKIM and DMARC alignment, plus what your aggregate reports reveal.

Read more
24 May 2026 · 11 min read

One-click unsubscribe: the List-Unsubscribe requirement

Google, Yahoo and Microsoft now require working one-click unsubscribe on bulk mail. Here is what the List-Unsubscribe and List-Unsubscribe-Post headers are, how RFC 8058 one-click actually works on the wire, how to implement it correctly, and why it sits alongside SPF, DKIM and DMARC on the same deliverability checklist.

Read more
24 May 2026 · 12 min read

Double opt-in and why it matters

Confirmed (double) opt-in keeps spam-trap hits, bounces and complaints off your list, the exact reputation signals that decide whether your authenticated mail reaches the inbox and clears the Gmail and Yahoo bulk-sender rules.

Read more
23 May 2026 · 13 min read

Email authentication for accountants

Accountancy practices are prime impersonation targets: you hold client bank details, your clients act on what you tell them, and the tax calendar is public. This guide covers the four fraud patterns a practice actually faces, exactly where DMARC, SPF and DKIM stop them, and a deadline-aware enforcement plan to reach p=reject without breaking client mail.

Read more
20 May 2026 · 11 min read

Why Gmail, Yahoo and Microsoft now require DMARC

Gmail, Yahoo and Microsoft now require SPF, DKIM and DMARC from bulk senders. Here is what each demands, what "require" really means, and how to comply.

Read more
19 May 2026 · 12 min read

The 2024 and 2025 bulk-sender requirements in full

Google, Yahoo and Microsoft turned email authentication into a hard delivery gate. Here are the exact requirements, the numeric thresholds, who counts as a bulk sender, and a line-by-line compliance checklist.

Read more
18 May 2026 · 16 min read

Keeping your spam complaint rate under 0.3%

The spam complaint rate is the small, unforgiving number mailbox providers trust most. Learn how it is measured per provider, what pushes it past the 0.3% danger line, and the concrete steps that bring it back down.

Read more
17 May 2026 · 14 min read

Email authentication for e-commerce

Online shops send order, shipping and receipt mail from a dozen different systems at once. Here is how to authenticate every stream, meet the Gmail, Yahoo and Microsoft bulk-sender rules, block order-confirmation phishing, and earn your brand logo in the inbox with BIMI.

Read more
16 May 2026 · 13 min read

Email authentication for schools and universities

A practical, stage-by-stage path to DMARC enforcement on a sprawling .edu or .ac.uk estate: discovery, fixing SPF under the ten-lookup limit, aligning DKIM across many departmental senders, ramping to p=reject, and the governance traps that stall most rollouts.

Read more
14 May 2026 · 13 min read

Email authentication for financial services

For banks, insurers and fintechs, DMARC, SPF, DKIM, MTA-STS and BIMI are anti-fraud and brand-protection controls, not deliverability tweaks. How to meet regulatory expectations and reach p=reject across a multi-vendor estate without breaking OTP or statement mail.

Read more
12 May 2026 · 13 min read

Email authentication for government

Public-sector domains are prime spoofing targets because the state's authority is the most valuable brand a fraudster can wear. Here is why government email is forged, the mandates pushing departments to p=reject, and the engineering realities of getting a sprawling government estate to enforcement without cutting off citizen mail.

Read more
11 May 2026 · 14 min read

Email authentication for healthcare and HIPAA

HIPAA never names DMARC, but it asks for exactly what SPF, DKIM and DMARC deliver: protection of transmitted PHI, integrity, sender authentication and ongoing risk management. Here is how email authentication maps onto the HIPAA Security Rule, why DMARC reporting need not expose PHI, and the staged path to p=reject that does not break clinical email.

Read more
7 May 2026 · 11 min read

Email authentication for law firms

How solicitors use SPF, DKIM and DMARC to stop their domain being spoofed, protect client money on completions, and meet their confidentiality duties, with a staged, no-outage path to p=reject.

Read more
6 May 2026 · 14 min read

Why legitimate email lands in spam

Real, useful email ends up in the junk folder when its signals look untrustworthy to mailbox providers. This guide breaks misfiled mail into its four root causes (authentication, reputation, content and complaints) and shows how to diagnose and fix each with concrete tools and steps, starting with the highest-leverage fix: authentication.

Read more
2 May 2026 · 14 min read

Email authentication for nonprofits

For charities, DMARC is donor trust and fundraising revenue expressed as DNS records: it stops attackers spoofing your appeals and lifts your own appeals out of the spam folder. Here is how to align every sender, ramp safely to p=reject, and put your logo in the inbox, including via a Common Mark Certificate when your charity logo is not a registered trademark.

Read more
28 April 2026 · 12 min read

Email authentication for SaaS companies

SaaS companies send several distinct mail streams at once: transactional, product, marketing and customer-generated. This guide shows how to structure SPF, DKIM, DMARC, MTA-STS and BIMI by subdomain so a bad day on one stream never poisons your password resets, and how to reach p=reject across every domain without an outage.

Read more
21 April 2026 · 13 min read

Feedback loops and complaint handling

A feedback loop (FBL) is how a mailbox provider tells you a user marked your mail as spam. Learn what FBLs are, how Yahoo, Microsoft and Gmail differ, how to enrol against your DKIM signing domain, how to read ARF reports, and how to keep your complaint rate under the 0.3% threshold.

Read more
10 April 2026 · 14 min read

GDPR and DMARC reporting

DMARC reports can contain personal data: source IPs in aggregate reports, and recipients, subjects and message bodies in forensic reports. Here is which fields the UK and EU GDPR catch, why forensic (ruf) reporting is the real hazard most domains should drop, and the lawful basis, retention and transfer practices that keep aggregate (rua) collection compliant.

Read more
7 April 2026 · 12 min read

Using Google Postmaster Tools

Google Postmaster Tools shows you how Gmail scores your domain and IP reputation, what share of your mail authenticates, your TLS coverage, and how often Gmail users mark your messages as spam. Here is how to read each dashboard, the spam-rate and reputation thresholds that actually matter, and how to pair it with DMARC aggregate data to find and fix the source of any problem.

Read more
3 April 2026 · 11 min read

Inbox placement testing

Inbox placement testing tells you where your mail lands (inbox, spam, a tab, or nowhere), which DMARC reports cannot. Here is how seed lists and panel tools actually work, where they mislead you, and how to cross-read their output with DMARC aggregate data so authentication faults and reputation faults stop looking identical.

Read more
2 April 2026 · 12 min read

IP warming for new sending IPs

A new sending IP starts with zero reputation, so a sudden volume spike reads as spam. Here is a sensible warm-up schedule, when a dedicated IP is even worth it, and how aligned SPF, DKIM and DMARC make the reputation you build stick to your domain instead of a leased IP.

Read more
1 April 2026 · 12 min read

List hygiene and deliverability

Authentication proves who you are; list hygiene proves you are wanted. Once DMARC enforcement welds reputation to your verified domain, dead addresses, bounces and spam-trap hits stop being diffuse problems and start hitting your signed identity directly. Here is how clean lists protect the reputation your SPF, DKIM and DMARC setup earns.

Read more
31 March 2026 · 12 min read

Using Microsoft SNDS and JMRP

Microsoft gives self-hosted senders two free feedback channels into Outlook.com filtering: SNDS for IP reputation, complaint bands and spam-trap hits, and JMRP for the individual junk complaints behind them. Here is how to enrol, read the data honestly, instrument your mail so complaints are traceable, and connect it all to your DMARC alignment so an Outlook deliverability dip becomes diagnosable instead of a mystery.

Read more
19 March 2026 · 12 min read

A subdomain strategy for sending mail

Splitting transactional, marketing and corporate mail across dedicated subdomains isolates reputation and shrinks the DMARC enforcement problem into small, independently controllable streams. Here is how to design the split, the exact SPF, DKIM and DMARC records to publish, and how to migrate without an email outage.

Read more