Tagged “dmarc” (page 3)
135 articles, page 3 of 3
Email authentication for Amazon WorkMail: SPF, DKIM and DMARC
Amazon WorkMail sends through SES, so its defaults quietly fail DMARC alignment. Here is the exact SPF include, the three Easy DKIM CNAMEs, the custom MAIL FROM domain that fixes SPF alignment, and the staged path to p=reject without an outage.
Read more
Email authentication for Brevo: SPF, DKIM and DMARC
A Brevo-specific guide to SPF, DKIM and DMARC: the exact spf.brevo.com include, both DKIM CNAME selectors, why the return-path means DKIM (not SPF) carries DMARC on shared IPs, custom return-path with a dedicated IP, and the staged path from p=none to p=reject without breaking delivery.
Read more
Email authentication for Constant Contact: SPF, DKIM and DMARC
Constant Contact sends your campaigns from its own servers under your brand's From address, so by default SPF and DKIM both align to Constant Contact, not you, and DMARC fails. This Constant Contact-specific guide covers self-authentication, the real ccsend.com DKIM CNAMEs, when SPF and a branded return-path matter, and the safe staged path from p=none to p=reject without losing a campaign.
Read more
The SPF 10-lookup limit, explained
SPF caps how much DNS work a receiver may do when evaluating your record. Go over the 10-lookup limit, or the separate void-lookup limit, and SPF returns a permerror that quietly stops helping your DMARC result. Here is how includes consume the budget, why exceeding it breaks SPF, and how to get safely back under the line.
Read more
SPF ~all vs -all vs ?all
Soft fail, hard fail, neutral and pass-all: what each SPF qualifier on the all mechanism actually instructs receivers to do, how DMARC changes the picture, and which one to publish at each stage of your rollout.
Read more
Email authentication for Fastmail: SPF, DKIM and DMARC
A Fastmail-specific setup guide: the exact spf.messagingengine.com SPF include, the three fm1/fm2/fm3 DKIM CNAMEs, how return-path and DKIM alignment behave, and the safe path from p=none to p=reject.
Read more
What is BIMI and is it worth it?
BIMI puts your brand logo beside authenticated mail, but only after DMARC enforcement and, for the big providers, a paid certificate. Here is what it shows, what it costs, and an honest view of who actually benefits.
Read more
Email authentication for Freshdesk: SPF, DKIM and DMARC
A Freshdesk-specific setup guide: the exact SPF include, the fdkim1 and fdkim2 DKIM CNAMEs, why the Return-Path means SPF will not align, and how to reach DMARC enforcement on support email without breaking ticket replies.
Read more
What is DMARC and how does it work?
DMARC is the control that stops exact-domain spoofing. Here is what it is, how it builds on SPF and DKIM through alignment, what each policy value instructs receivers to do, and how to reach p=reject safely.
Read more
Email authentication for HubSpot: SPF, DKIM and DMARC
A HubSpot-specific guide to email authentication: the exact SPF include, HubSpot's two CNAME-based DKIM selectors, the custom bounce subdomain for return-path alignment, and how to take a HubSpot-sending domain from p=none to p=reject without breaking email.
Read more
Email authentication for Intercom: SPF, DKIM and DMARC
Intercom gives you both halves of DMARC: a DKIM CNAME and a custom return-path CNAME that makes SPF align. Here is the exact selector, the two records to publish, why you do not add an SPF include, and how to reach p=reject without breaking your onboarding, campaign or support email.
Read more
What is SPF and how does it work?
SPF lets you publish, in DNS, the list of servers allowed to send mail for your domain. Here is how the syntax works, what the all qualifier and each mechanism mean, what SPF actually authorises, the ten-lookup limit that catches everyone, and the spoofing gap that DMARC alignment closes.
Read more
Email authentication for Klaviyo: SPF, DKIM and DMARC
A Klaviyo-specific guide to SPF, DKIM and DMARC: the exact _spf.klaviyomail.com include, the kl/kl2 DKIM selectors, the dedicated sending domain CNAMEs, custom return-path alignment, and the safe path from p=none to p=reject without losing a campaign or flow.
Read more
Email authentication for Mailchimp: SPF, DKIM and DMARC
A Mailchimp-specific guide to SPF, DKIM and DMARC: the exact mcsv.net include, how to publish Mailchimp's DKIM CNAMEs, why default bounce addresses break SPF alignment, and how to reach p=reject without losing a campaign.
Read more
Email authentication for Mailgun: SPF, DKIM and DMARC
A complete, Mailgun-specific walkthrough: the exact SPF include, how to enable and publish DKIM with Mailgun's real selector, why the default return-path breaks SPF alignment, and how to reach DMARC enforcement when sending through Mailgun's subdomain model without an email outage.
Read more
Email authentication for Mailjet: SPF, DKIM and DMARC
A Mailjet-specific guide to SPF, DKIM and DMARC: the exact spf.mailjet.com include and why you can skip it, the mailjet._domainkey DKIM record, why the bnc3.mailjet.com return-path breaks SPF alignment, how to set a custom return-path, and the staged path to p=reject without losing mail.
Read more
Email authentication for Mimecast: SPF, DKIM and DMARC
A Mimecast-specific guide to SPF, DKIM and DMARC: the exact regional includes, generating and publishing a DKIM key from the console, why return-path and From alignment behave differently behind a gateway, and how to reach p=reject without an email outage.
Read more
Email authentication for Postmark: SPF, DKIM and DMARC
A Postmark-specific guide to SPF, DKIM and DMARC: the exact spf.mtasv.net include, publishing the DKIM CNAME selectors, configuring a custom Return-Path for SPF alignment, and ramping safely from p=none to p=reject without breaking transactional mail.
Read more
Email authentication for Proofpoint: SPF, DKIM and DMARC
Proofpoint is a gateway, not an ESP, so it relays your mail from its own IPs and that quietly breaks SPF and DKIM alignment. This Proofpoint-specific guide gives the exact SPF mechanism for Essentials (a:dispatch-us.ppe-hosted.com) and the cluster include for Protection Server, the DKIM signing and selector workflow for both products, how the return path affects SPF alignment, and the staged path to p=reject with Proofpoint in front of Microsoft 365 or Google Workspace.
Read more
Email authentication for Proton Mail: SPF, DKIM and DMARC
A Proton Mail-specific guide to SPF, DKIM and DMARC on a custom domain: the exact _spf.protonmail.ch include, Proton's three rotating DKIM CNAME records, the return-path quirk that makes DKIM load-bearing for alignment, and a safe path to p=reject.
Read more
Email authentication for Salesforce: SPF, DKIM and DMARC
Salesforce is four senders, not one. Here are the exact SPF includes, how to generate and activate Salesforce DKIM CNAMEs, why bounce management breaks SPF alignment, and the staged path to p=reject across core, Marketing Cloud and Pardot.
Read more
Email authentication for SendGrid: SPF, DKIM and DMARC
A SendGrid-specific guide to SPF, DKIM and DMARC: the exact sendgrid.net include, Domain Authentication with the s1/s2 DKIM selectors, the custom return-path for SPF alignment, and the staged path to p=reject without breaking your mail.
Read more
Email authentication for SparkPost: SPF, DKIM and DMARC
A SparkPost-specific guide to SPF, DKIM and DMARC: the exact _spf.sparkpostmail.com include, the scph DKIM TXT record, the bounce-domain CNAME that makes SPF align, and how to reach p=reject without losing SparkPost mail.
Read more
Email authentication for Zendesk: SPF, DKIM and DMARC
Zendesk locks the Return-Path to its own domain, so SPF can never align and DKIM is the only mechanism that carries your DMARC pass. Here are the exact zendesk1 and zendesk2 CNAMEs, the mail.zendesk.com SPF include, the safe order of operations and how to reach p=reject without breaking support email.
Read more
Email authentication for Zoho Mail: SPF, DKIM and DMARC
A Zoho Mail-specific guide to SPF, DKIM and DMARC: the exact Zoho SPF include, how to generate and publish DKIM selectors in the Admin Console, the return-path and alignment quirks that decide whether DMARC passes, and a safe sequence from p=none to p=reject.
Read more
Fix: BIMI logo not showing in Gmail
Gmail shows a grey initial instead of your BIMI logo and never says why. Here is every reason it fails, in the order Gmail checks them: DMARC not at enforcement, a missing VMC, an SVG that breaks the Tiny PS profile, a logo-to-certificate mismatch, and cached negative results, plus how to fix each.
Read more
Fix: DKIM fails after forwarding
Forwarders and mailing lists break DKIM by changing the message body and headers, not the connection. Here is exactly what fails, what survives, where ARC helps, how to spot forwarding failures in your DMARC reports, and how to reduce the impact without parking at p=none.
Read more
Fix: DKIM public key not found in DNS
The "DKIM public key not found in DNS" error is almost always a naming or publishing problem, not a broken key. Here is exactly which name receivers query, why it returns nothing, how CNAME and TXT publishing differ, and how to confirm the key resolves end to end.
Read more
Fix: DKIM signature did not verify
"DKIM signature did not verify" is at least six different problems wearing one error string: body hash mismatch, no key in DNS, malformed record, key mismatch after rotation, expired signature, or a key too short. Here is how to read the exact reason in the brackets and apply the one correct fix for each.
Read more
Fix: MTA-STS policy not found
"MTA-STS policy not found" is never one problem: it is a five-link chain (DNS TXT, HTTPS host, certificate, file path, file content) plus the MX-coverage trap, and it fails silently because senders fall back to opportunistic TLS rather than bounce. Walk the discovery the way a sending MTA does, with real dig, curl and openssl checks, and fix the first broken link.
Read more
Fix: multiple DMARC records
Two TXT records at _dmarc do not make DMARC stricter; they switch it off entirely, silently. Here is why RFC 7489 mandates that, the exact ways duplicates sneak into a zone, how to detect them and how to consolidate down to one correct record without losing your settings.
Read more
Fix: multiple SPF records
Two SPF records on one domain force a permanent PermError that silently strips a DMARC route. Here is why it happens, how receivers treat it, and how to merge two records into one compliant record without losing a sender or blowing the 10-lookup limit.
Read more
Fix: SPF TempError
An SPF TempError is a transient DNS failure, not a broken record. Here is what it means, why it differs from PermError, how Google, Yahoo and Microsoft treat it under SPF and DMARC, and the concrete steps that make your SPF resolution reliable.
Read more
Fix: SPF too many DNS lookups
SPF caps you at ten DNS-querying mechanisms, counted after every include expands into its provider's nested netblocks, which is why a record with five includes can spend fifteen lookups and PermError. Here is how to count the budget, prune the includes that overspend it, and flatten or consolidate back under the limit before enforcement makes the failure bite.
Read more
Free checkers vs paid DMARC platforms
Free DMARC checkers read the current state of your DNS in one lookup, and they do that job completely. Enforcement is different: getting a domain from p=none to p=reject without dropping legitimate mail is a multi-week process driven by the continuous aggregate-report stream, which no one-shot tool can ever surface. This guide draws the exact line between what free checkers do well, where they structurally stop, and what a managed platform adds, plus an honest account of who needs the paid side and who does not.
Read more
Header-From vs envelope-from: the two From addresses
Every email carries two different From addresses: the header-from (RFC5322.From) that humans see and the envelope-from (RFC5321.MailFrom) used for bounces. SPF checks one, DMARC checks the other, and the gap between them explains alignment, forwarding breakage and spoofing.
Read more
Hosted vs do-it-yourself DMARC
DIY DMARC looks free, but the real cost lives in senior time, the risk of breaking your own mail on the way to enforcement, and the monitoring tail nobody keeps up. Here is how to price hosted versus do-it-yourself honestly, and decide which your domain actually needs.
Read more
Relaxed vs strict DMARC alignment
DMARC does not check whether SPF or DKIM passed, it checks alignment. The aspf and adkim tags decide how exact that match must be. Here is when strict alignment is worth it, when relaxed is right, and exactly how the choice reshapes subdomain sending.
Read more
RFC 7489: the DMARC standard explained
A close reading of RFC 7489, the document that defines DMARC: the From-header trust model, identifier alignment, the record tags, policy discovery and application, the two report types, and the clauses people consistently misread.
Read more