DMARC Engine
Home/Blog/Tagged “dmarc”
Blog

Tagged “dmarc” (page 2)

111 articles, page 2 of 3

3 June 2026 · 12 min read

How invoice fraud begins with a spoofed domain

Invoice fraud usually starts with a forged sender address. Here is how exact-domain spoofing works, what DMARC at p=reject stops, and what it does not.

Read more
3 June 2026 · 11 min read

What DMARC reports do and do not tell you

Passing DMARC is permission to be judged on your merits, not a guaranteed seat in the inbox. Here is how to read aggregate reports for exactly what they measure, identity and authentication, without mistaking a perfect pass rate for good deliverability or panicking at failures that do not matter.

Read more
2 June 2026 · 12 min read

DMARC aggregate vs forensic reports

DMARC sends two kinds of feedback: aggregate (rua) reports and forensic (ruf) reports. They answer different questions and carry very different privacy risks. This guide explains exactly what each contains, why forensic reports have all but vanished, the data-protection considerations on both sides, and how to turn the aggregate data into a safe path from p=none to p=reject.

Read more
1 June 2026 · 9 min read

Subdomain policy: the DMARC sp tag

An enforced root domain at p=reject protects exactly one address and can leave every subdomain spoofable. Here is what the DMARC sp tag does, the inheritance trap that catches teams mid-migration, and how to close the gap safely without bouncing legitimate subdomain mail.

Read more
31 May 2026 · 11 min read

How email spoofing actually works

Email spoofing takes no password and no exploit: SMTP simply trusts whatever the sender types into the From field. This guide traces the mechanism from the raw SMTP conversation, through the crucial split between the envelope-from used for delivery and the header-from a human reads, to the three layered controls (SPF, DKIM and DMARC alignment) that finally make forging your domain fail.

Read more
30 May 2026 · 12 min read

Email transport security: STARTTLS, MTA-STS, DANE

DMARC proves who sent a message, but it does nothing to protect that message while it crosses the internet. Here is how opportunistic STARTTLS, MTA-STS, DANE and TLS-RPT work together to keep inbound mail encrypted in transit, why STARTTLS alone is trivially downgraded, and the safe order to deploy enforcement without bouncing legitimate mail.

Read more
30 May 2026 · 13 min read

DMARC external destination verification

Sending DMARC reports to an address outside your own domain is an external destination, and RFC 7489 requires the receiving domain to authorise it first. Here is exactly which DNS record to publish, where, and why reports silently vanish without it.

Read more
29 May 2026 · 13 min read

Why DMARC fails when SPF and DKIM pass

SPF passes, DKIM passes, yet DMARC still fails on legitimate mail. The cause is almost always alignment: both checks authenticated a domain other than the one in your From header. Here is how to find the misaligned identifier in a single message header and across all sources in your aggregate reports, then fix each cause.

Read more
28 May 2026 · 11 min read

How to enable DKIM in Microsoft 365

Microsoft 365 signs your mail with a shared Microsoft domain by default, which does nothing for DMARC alignment. This guide walks through enabling DKIM signing for your own custom domain end to end: finding the exact CNAME values, publishing the two selector records, switching signing on, and verifying the result really passes.

Read more
28 May 2026 · 10 min read

DMARC says quarantine but mail still reaches the inbox

A quarantine policy does not always mean the spam folder. Here is why failing mail still lands in the inbox: pct sampling, alignment, receiver discretion, DNS caching, and exactly what to check.

Read more
27 May 2026 · 11 min read

How to fix SPF PermError

SPF PermError means a receiver tried to evaluate your SPF record and gave up, so SPF stops counting towards DMARC. This guide diagnoses PermError, TempError and the ten-lookup limit, then walks through a step by step repair process.

Read more
27 May 2026 · 11 min read

DMARC reporting: mailto vs https URIs

The rua and ruf tags accept both mailto: and https: URIs, but almost every working DMARC record uses mailto: only. Here is why HTTPS delivery is dead in practice, how the size-limit suffix and external destination verification work, and how analysers ingest the gzipped XML.

Read more
26 May 2026 · 13 min read

Why forwarding breaks email authentication

Forwarding almost always breaks SPF and sometimes breaks DKIM too. Here is what survives a forwarding hop, why DKIM is the mechanism that carries your authentication through, how DMARC's one-aligned-pass rule copes, and where ARC rescues mailing-list mail.

Read more
26 May 2026 · 13 min read

DMARC reports show sources I do not recognise

Unknown sending IPs in your DMARC aggregate reports are normal, not an emergency. Here is a reliable four-question triage to tell shadow IT and forwarders from real spoofers, and exactly what to do with each.

Read more
25 May 2026 · 11 min read

Lookalike and cousin domains

Attackers register confusable domains that authenticate perfectly and slip past your defences, because your DMARC policy protects only the exact name it is published under. Here is how homoglyph and cousin domains work, the precise reason a p=reject policy cannot touch them, and the layered plan that actually defends your brand.

Read more
25 May 2026 · 13 min read

DMARC vs SPF vs DKIM: how they fit together

SPF, DKIM and DMARC are named together so often that they blur into one thing. They are not. This is a clear comparison of what each record actually proves, why SPF and DKIM are blind to the From line your recipients trust, and how DMARC ties them together with alignment and policy.

Read more
24 May 2026 · 11 min read

One-click unsubscribe: the List-Unsubscribe requirement

Google, Yahoo and Microsoft now require working one-click unsubscribe on bulk mail. Here is what the List-Unsubscribe and List-Unsubscribe-Post headers are, how RFC 8058 one-click actually works on the wire, how to implement it correctly, and why it sits alongside SPF, DKIM and DMARC on the same deliverability checklist.

Read more
23 May 2026 · 12 min read

PCI DSS 4.0, cyber-insurance and email authentication

PCI DSS 4.0 Requirement 5.4.1 and cyber-insurance questionnaires now treat anti-phishing as a measurable control. Here is exactly how that intersects with DMARC, SPF and DKIM, what counts as evidence, and how to reach enforcement without breaking your own mail.

Read more
22 May 2026 · 11 min read

Phishing and business email compromise

Business email compromise rarely uses malware: it borrows trust by impersonating people you already deal with. Here is how phishing and BEC work, where the money goes, and the layered defences, with DMARC at enforcement as the load-bearing wall.

Read more
22 May 2026 · 12 min read

Email authentication for ActiveCampaign: SPF, DKIM and DMARC

An ActiveCampaign-specific guide to email authentication: the exact SPF include, CNAME-based DKIM, the custom return-path that aligns SPF, and a staged path to DMARC p=reject without breaking your campaigns or automations.

Read more
21 May 2026 · 13 min read

Publishing DMARC, SPF and DKIM on common DNS hosts

Exact steps to publish SPF, DMARC and DKIM on Cloudflare, GoDaddy, Namecheap and AWS Route 53, plus the two gotchas that break most setups: TXT chunking on long DKIM keys and CNAME coexistence at the apex.

Read more
21 May 2026 · 14 min read

Email authentication for Amazon SES: SPF, DKIM and DMARC

Amazon SES passes SPF and DKIM by default but on amazonses.com, so nothing aligns under DMARC. Here is the exact SES include, Easy DKIM and its CNAME selectors, the custom MAIL FROM that fixes SPF alignment, and the staged path to p=reject.

Read more
20 May 2026 · 11 min read

Why Gmail, Yahoo and Microsoft now require DMARC

Gmail, Yahoo and Microsoft now require SPF, DKIM and DMARC from bulk senders. Here is what each demands, what "require" really means, and how to comply.

Read more
20 May 2026 · 12 min read

How sender reputation works

Mailbox providers decide where your mail lands based on sender reputation, a private estimate built from how recipients react to your messages and how cleanly you send. This guide explains domain and IP reputation, the signals that raise and lower them, how to warm up a new sender, and why aligned SPF, DKIM and DMARC are what keep the reputation you build genuinely yours.

Read more
20 May 2026 · 13 min read

Email authentication for Amazon WorkMail: SPF, DKIM and DMARC

Amazon WorkMail sends through SES, so its defaults quietly fail DMARC alignment. Here is the exact SPF include, the three Easy DKIM CNAMEs, the custom MAIL FROM domain that fixes SPF alignment, and the staged path to p=reject without an outage.

Read more
19 May 2026 · 12 min read

Email authentication for Brevo: SPF, DKIM and DMARC

A Brevo-specific guide to SPF, DKIM and DMARC: the exact spf.brevo.com include, both DKIM CNAME selectors, why the return-path means DKIM (not SPF) carries DMARC on shared IPs, custom return-path with a dedicated IP, and the staged path from p=none to p=reject without breaking delivery.

Read more
18 May 2026 · 14 min read

Email authentication for Constant Contact: SPF, DKIM and DMARC

Constant Contact sends your campaigns from its own servers under your brand's From address, so by default SPF and DKIM both align to Constant Contact, not you, and DMARC fails. This Constant Contact-specific guide covers self-authentication, the real ccsend.com DKIM CNAMEs, when SPF and a branded return-path matter, and the safe staged path from p=none to p=reject without losing a campaign.

Read more
17 May 2026 · 11 min read

The SPF 10-lookup limit, explained

SPF caps how much DNS work a receiver may do when evaluating your record. Go over the 10-lookup limit, or the separate void-lookup limit, and SPF returns a permerror that quietly stops helping your DMARC result. Here is how includes consume the budget, why exceeding it breaks SPF, and how to get safely back under the line.

Read more
16 May 2026 · 11 min read

SPF ~all vs -all vs ?all

Soft fail, hard fail, neutral and pass-all: what each SPF qualifier on the all mechanism actually instructs receivers to do, how DMARC changes the picture, and which one to publish at each stage of your rollout.

Read more
15 May 2026 · 12 min read

Email authentication for Fastmail: SPF, DKIM and DMARC

A Fastmail-specific setup guide: the exact spf.messagingengine.com SPF include, the three fm1/fm2/fm3 DKIM CNAMEs, how return-path and DKIM alignment behave, and the safe path from p=none to p=reject.

Read more
13 May 2026 · 11 min read

What is BIMI and is it worth it?

BIMI puts your brand logo beside authenticated mail, but only after DMARC enforcement and, for the big providers, a paid certificate. Here is what it shows, what it costs, and an honest view of who actually benefits.

Read more
13 May 2026 · 14 min read

Email authentication for Freshdesk: SPF, DKIM and DMARC

A Freshdesk-specific setup guide: the exact SPF include, the fdkim1 and fdkim2 DKIM CNAMEs, why the Return-Path means SPF will not align, and how to reach DMARC enforcement on support email without breaking ticket replies.

Read more
10 May 2026 · 11 min read

What is DMARC and how does it work?

DMARC is the control that stops exact-domain spoofing. Here is what it is, how it builds on SPF and DKIM through alignment, what each policy value instructs receivers to do, and how to reach p=reject safely.

Read more
10 May 2026 · 12 min read

Email authentication for HubSpot: SPF, DKIM and DMARC

A HubSpot-specific guide to email authentication: the exact SPF include, HubSpot's two CNAME-based DKIM selectors, the custom bounce subdomain for return-path alignment, and how to take a HubSpot-sending domain from p=none to p=reject without breaking email.

Read more
9 May 2026 · 16 min read

Email authentication for Intercom: SPF, DKIM and DMARC

Intercom gives you both halves of DMARC: a DKIM CNAME and a custom return-path CNAME that makes SPF align. Here is the exact selector, the two records to publish, why you do not add an SPF include, and how to reach p=reject without breaking your onboarding, campaign or support email.

Read more
8 May 2026 · 13 min read

What is SPF and how does it work?

SPF lets you publish, in DNS, the list of servers allowed to send mail for your domain. Here is how the syntax works, what the all qualifier and each mechanism mean, what SPF actually authorises, the ten-lookup limit that catches everyone, and the spoofing gap that DMARC alignment closes.

Read more
8 May 2026 · 13 min read

Email authentication for Klaviyo: SPF, DKIM and DMARC

A Klaviyo-specific guide to SPF, DKIM and DMARC: the exact _spf.klaviyomail.com include, the kl/kl2 DKIM selectors, the dedicated sending domain CNAMEs, custom return-path alignment, and the safe path from p=none to p=reject without losing a campaign or flow.

Read more
6 May 2026 · 12 min read

Email authentication for Mailchimp: SPF, DKIM and DMARC

A Mailchimp-specific guide to SPF, DKIM and DMARC: the exact mcsv.net include, how to publish Mailchimp's DKIM CNAMEs, why default bounce addresses break SPF alignment, and how to reach p=reject without losing a campaign.

Read more
5 May 2026 · 15 min read

Email authentication for Mailgun: SPF, DKIM and DMARC

A complete, Mailgun-specific walkthrough: the exact SPF include, how to enable and publish DKIM with Mailgun's real selector, why the default return-path breaks SPF alignment, and how to reach DMARC enforcement when sending through Mailgun's subdomain model without an email outage.

Read more
4 May 2026 · 15 min read

Email authentication for Mailjet: SPF, DKIM and DMARC

A Mailjet-specific guide to SPF, DKIM and DMARC: the exact spf.mailjet.com include and why you can skip it, the mailjet._domainkey DKIM record, why the bnc3.mailjet.com return-path breaks SPF alignment, how to set a custom return-path, and the staged path to p=reject without losing mail.

Read more
3 May 2026 · 13 min read

Email authentication for Mimecast: SPF, DKIM and DMARC

A Mimecast-specific guide to SPF, DKIM and DMARC: the exact regional includes, generating and publishing a DKIM key from the console, why return-path and From alignment behave differently behind a gateway, and how to reach p=reject without an email outage.

Read more
1 May 2026 · 13 min read

Email authentication for Postmark: SPF, DKIM and DMARC

A Postmark-specific guide to SPF, DKIM and DMARC: the exact spf.mtasv.net include, publishing the DKIM CNAME selectors, configuring a custom Return-Path for SPF alignment, and ramping safely from p=none to p=reject without breaking transactional mail.

Read more
30 April 2026 · 18 min read

Email authentication for Proofpoint: SPF, DKIM and DMARC

Proofpoint is a gateway, not an ESP, so it relays your mail from its own IPs and that quietly breaks SPF and DKIM alignment. This Proofpoint-specific guide gives the exact SPF mechanism for Essentials (a:dispatch-us.ppe-hosted.com) and the cluster include for Protection Server, the DKIM signing and selector workflow for both products, how the return path affects SPF alignment, and the staged path to p=reject with Proofpoint in front of Microsoft 365 or Google Workspace.

Read more
29 April 2026 · 12 min read

Email authentication for Proton Mail: SPF, DKIM and DMARC

A Proton Mail-specific guide to SPF, DKIM and DMARC on a custom domain: the exact _spf.protonmail.ch include, Proton's three rotating DKIM CNAME records, the return-path quirk that makes DKIM load-bearing for alignment, and a safe path to p=reject.

Read more
27 April 2026 · 11 min read

Email authentication for Salesforce: SPF, DKIM and DMARC

Salesforce is four senders, not one. Here are the exact SPF includes, how to generate and activate Salesforce DKIM CNAMEs, why bounce management breaks SPF alignment, and the staged path to p=reject across core, Marketing Cloud and Pardot.

Read more
26 April 2026 · 13 min read

Email authentication for SendGrid: SPF, DKIM and DMARC

A SendGrid-specific guide to SPF, DKIM and DMARC: the exact sendgrid.net include, Domain Authentication with the s1/s2 DKIM selectors, the custom return-path for SPF alignment, and the staged path to p=reject without breaking your mail.

Read more
25 April 2026 · 13 min read

Email authentication for SparkPost: SPF, DKIM and DMARC

A SparkPost-specific guide to SPF, DKIM and DMARC: the exact _spf.sparkpostmail.com include, the scph DKIM TXT record, the bounce-domain CNAME that makes SPF align, and how to reach p=reject without losing SparkPost mail.

Read more
24 April 2026 · 11 min read

Email authentication for Zendesk: SPF, DKIM and DMARC

Zendesk locks the Return-Path to its own domain, so SPF can never align and DKIM is the only mechanism that carries your DMARC pass. Here are the exact zendesk1 and zendesk2 CNAMEs, the mail.zendesk.com SPF include, the safe order of operations and how to reach p=reject without breaking support email.

Read more