DMARC Engine
Home/Blog/Tagged “spam”
Blog

Tagged “spam”

10 articles

18 June 2026 · 11 min read

The Google and Yahoo sender rules, one year on

A year after Google and Yahoo made authentication mandatory for bulk senders, here is what changed, how mail failed, and where enforcement is heading.

Read more
20 June 2026 · 12 min read

ARC: Authenticated Received Chain explained

Forwarding and mailing lists break SPF and DKIM in transit, flipping a passing message to a DMARC failure. ARC, the Authenticated Received Chain, preserves the original authentication verdict across intermediaries with a signed, tamper-evident chain, so trusted forwarders can vouch for legitimate mail and you can reach p=reject without breaking list traffic.

Read more
17 June 2026 · 13 min read

Done-for-you DMARC enforcement: how the managed path to p=reject works

Reaching p=reject is not the hard part. Anyone can change one DNS record from p=none to p=reject in thirty seconds. The hard part is reaching p=reject without silently dropping legitimate mail: the invoice from.

Read more
15 June 2026 · 11 min read

Why p=none gives a false sense of security

A DMARC record at p=none watches your domain but blocks nothing. Here is how to tell whether you are actually protected, and the safe path to enforcement.

Read more
12 June 2026 · 12 min read

SPF PermError: when your SPF silently stops working

SPF breaks quietly. Cross the 10 DNS-lookup limit and your record returns PermError, fails open, and stops protecting your domain. Here is how to count, fix and flatten it safely.

Read more
11 June 2026 · 15 min read

The five DNS records that protect your email

Email was designed in an era of trust. The original protocol, SMTP, lets any server on the internet claim to send mail as anyone.

Read more
10 June 2026 · 12 min read

Ten common DMARC mistakes and how to avoid them

The configuration and rollout mistakes that most often break mail or leave domains exposed, from jumping straight to p=reject to ignoring report drift, and exactly how to avoid each one.

Read more
8 June 2026 · 13 min read

DMARC for Google Workspace

A new Google Workspace domain ships with no DKIM signing, an SPF record you must add yourself, and no DMARC policy at all. This guide walks the exact order to fix that: get SPF right under the 10-lookup limit, switch on DKIM in the Admin console, then ratchet DMARC from monitoring to full reject without breaking a single legitimate message.

Read more
5 June 2026 · 11 min read

Bounce handling and the return-path

The envelope return-path is where bounces come back to and the domain SPF authenticates. Here is how a custom return-path on your own subdomain fixes SPF alignment under DMARC, and what really happens to a bounce.

Read more
3 June 2026 · 11 min read

What DMARC reports do and do not tell you

Passing DMARC is permission to be judged on your merits, not a guaranteed seat in the inbox. Here is how to read aggregate reports for exactly what they measure, identity and authentication, without mistaking a perfect pass rate for good deliverability or panicking at failures that do not matter.

Read more