DMARC Engine
Home/Blog/Tagged “enforcement”
Blog

Tagged “enforcement”

24 articles

18 June 2026 · 11 min read

The Google and Yahoo sender rules, one year on

A year after Google and Yahoo made authentication mandatory for bulk senders, here is what changed, how mail failed, and where enforcement is heading.

Read more
1 June 2026 · 11 min read

How to reach DMARC p=reject without breaking email

The staged playbook to DMARC enforcement with no email outage: inventory senders, fix SPF and DKIM, ramp p=none to p=reject, and lock down subdomains.

Read more
20 June 2026 · 12 min read

ARC: Authenticated Received Chain explained

Forwarding and mailing lists break SPF and DKIM in transit, flipping a passing message to a DMARC failure. ARC, the Authenticated Received Chain, preserves the original authentication verdict across intermediaries with a signed, tamper-evident chain, so trusted forwarders can vouch for legitimate mail and you can reach p=reject without breaking list traffic.

Read more
19 June 2026 · 13 min read

How BIMI displays in Gmail and Apple Mail

Gmail and Apple Mail both reward an enforced DMARC domain with a verified logo, but each shows it differently and both demand a certificate. Here is what each provider displays, why a Verified Mark Certificate is non-negotiable, and how to test the whole BIMI chain before you rely on it.

Read more
17 June 2026 · 13 min read

Done-for-you DMARC enforcement: how the managed path to p=reject works

Reaching p=reject is not the hard part. Anyone can change one DNS record from p=none to p=reject in thirty seconds. The hard part is reaching p=reject without silently dropping legitimate mail: the invoice from.

Read more
15 June 2026 · 11 min read

Why p=none gives a false sense of security

A DMARC record at p=none watches your domain but blocks nothing. Here is how to tell whether you are actually protected, and the safe path to enforcement.

Read more
10 June 2026 · 12 min read

Ten common DMARC mistakes and how to avoid them

The configuration and rollout mistakes that most often break mail or leave domains exposed, from jumping straight to p=reject to ignoring report drift, and exactly how to avoid each one.

Read more
9 June 2026 · 11 min read

Protecting parked and no-mail domains

Domains that never send mail are the easiest to secure and the most commonly left wide open. Here is how to lock down parked, legacy and campaign domains with SPF -all, DMARC p=reject and a null MX so they cannot be spoofed, with zero deliverability risk.

Read more
8 June 2026 · 13 min read

DMARC for Google Workspace

A new Google Workspace domain ships with no DKIM signing, an SPF record you must add yourself, and no DMARC policy at all. This guide walks the exact order to fix that: get SPF right under the 10-lookup limit, switch on DKIM in the Admin console, then ratchet DMARC from monitoring to full reject without breaking a single legitimate message.

Read more
7 June 2026 · 12 min read

DMARC for Microsoft 365

A practical, ordered guide to email authentication on Microsoft 365: build a complete SPF record for Exchange Online, enable DKIM signing with Microsoft's two selector CNAMEs, and walk DMARC safely from p=none through quarantine to p=reject without breaking your mail.

Read more
6 June 2026 · 15 min read

The DMARC pct tag and sampling, explained

The DMARC pct tag samples how often your policy is applied to failing mail, pushing the remainder down one level. Here is why pct=0 is a downgrade trap, how receivers actually apply the sample, and how to ramp pct safely from p=none to a full p=reject.

Read more
5 June 2026 · 12 min read

p=none vs quarantine vs reject

The three DMARC policies compared: what p=none, p=quarantine and p=reject each tell receivers to do with failing mail, and how to progress between them safely without breaking your own email.

Read more
3 June 2026 · 12 min read

How invoice fraud begins with a spoofed domain

Invoice fraud usually starts with a forged sender address. Here is how exact-domain spoofing works, what DMARC at p=reject stops, and what it does not.

Read more
2 June 2026 · 12 min read

DMARC aggregate vs forensic reports

DMARC sends two kinds of feedback: aggregate (rua) reports and forensic (ruf) reports. They answer different questions and carry very different privacy risks. This guide explains exactly what each contains, why forensic reports have all but vanished, the data-protection considerations on both sides, and how to turn the aggregate data into a safe path from p=none to p=reject.

Read more
1 June 2026 · 9 min read

Subdomain policy: the DMARC sp tag

An enforced root domain at p=reject protects exactly one address and can leave every subdomain spoofable. Here is what the DMARC sp tag does, the inheritance trap that catches teams mid-migration, and how to close the gap safely without bouncing legitimate subdomain mail.

Read more
30 May 2026 · 12 min read

Email transport security: STARTTLS, MTA-STS, DANE

DMARC proves who sent a message, but it does nothing to protect that message while it crosses the internet. Here is how opportunistic STARTTLS, MTA-STS, DANE and TLS-RPT work together to keep inbound mail encrypted in transit, why STARTTLS alone is trivially downgraded, and the safe order to deploy enforcement without bouncing legitimate mail.

Read more
25 May 2026 · 11 min read

Lookalike and cousin domains

Attackers register confusable domains that authenticate perfectly and slip past your defences, because your DMARC policy protects only the exact name it is published under. Here is how homoglyph and cousin domains work, the precise reason a p=reject policy cannot touch them, and the layered plan that actually defends your brand.

Read more
23 May 2026 · 12 min read

PCI DSS 4.0, cyber-insurance and email authentication

PCI DSS 4.0 Requirement 5.4.1 and cyber-insurance questionnaires now treat anti-phishing as a measurable control. Here is exactly how that intersects with DMARC, SPF and DKIM, what counts as evidence, and how to reach enforcement without breaking your own mail.

Read more
22 May 2026 · 11 min read

Phishing and business email compromise

Business email compromise rarely uses malware: it borrows trust by impersonating people you already deal with. Here is how phishing and BEC work, where the money goes, and the layered defences, with DMARC at enforcement as the load-bearing wall.

Read more
13 May 2026 · 11 min read

What is BIMI and is it worth it?

BIMI puts your brand logo beside authenticated mail, but only after DMARC enforcement and, for the big providers, a paid certificate. Here is what it shows, what it costs, and an honest view of who actually benefits.

Read more
10 May 2026 · 11 min read

What is DMARC and how does it work?

DMARC is the control that stops exact-domain spoofing. Here is what it is, how it builds on SPF and DKIM through alignment, what each policy value instructs receivers to do, and how to reach p=reject safely.

Read more
9 May 2026 · 12 min read

What is MTA-STS and how does it work?

MTA-STS forces encrypted, authenticated delivery of your inbound mail. Learn how the _mta-sts DNS record and the HTTPS-hosted policy file work together, the difference between testing and enforce mode, and exactly how it stops TLS downgrade and interception attacks.

Read more
7 May 2026 · 12 min read

What is TLS-RPT?

TLS-RPT (SMTP TLS Reporting) is a single safe-to-publish DNS record that gives you a daily, machine-readable summary of how other mail servers negotiated encryption with your inbound MX hosts. Learn what the record and its JSON reports contain, how to decode each failure type, and the exact publish-then-enforce workflow that pairs it with MTA-STS without risking an email outage.

Read more
4 April 2026 · 12 min read

Hosted vs do-it-yourself DMARC

DIY DMARC looks free, but the real cost lives in senior time, the risk of breaking your own mail on the way to enforcement, and the monitoring tail nobody keeps up. Here is how to price hosted versus do-it-yourself honestly, and decide which your domain actually needs.

Read more