Blog
Insights on email authentication, deliverability and security.
190 articles, page 1 of 4
The Google and Yahoo sender rules, one year on
A year after Google and Yahoo made authentication mandatory for bulk senders, here is what changed, how mail failed, and where enforcement is heading.
Read more
How to reach DMARC p=reject without breaking email
The staged playbook to DMARC enforcement with no email outage: inventory senders, fix SPF and DKIM, ramp p=none to p=reject, and lock down subdomains.
Read more
Troubleshooting DMARC Failure Due to Overly Restrictive SPF Records
Overly restrictive SPF records can cause DMARC failure, affecting email deliverability, learn how to troubleshoot and fix the issue
Read more
Navigating DMARC Alignment with Variable IP Pools in Cloud Email Services
Cloud email services' variable IP pools can cause DMARC alignment issues, affecting email delivery, a common problem for customers using services like Amazon Web Services
Read more
DMARC Alignment Pitfalls with Load Balancer IP Rotation
Load balancer IP rotation can cause DMARC alignment issues, impacting email deliverability, proper management is key to maintaining alignment
Read more
Mitigating False Positives in DMARC Reporting
False positives in DMARC reporting can lead to legitimate emails being rejected, damaging email deliverability. Optimising DMARC records is key to prevention
Read more
DMARC Alignment for Domains with Mixed IPv4 and IPv6 Mail Infrastructure
Achieving DMARC alignment is challenging in dual-stacked environments, this article provides solutions for domains with mixed IPv4 and IPv6 mail infrastructure
Read more
Troubleshooting DMARC Alignment Issues with Load Balancers and CDN Providers
Load balancers can complicate DMARC alignment, learn how to configure them correctly to improve email deliverability. DMARC Engine experts share their experience
Read more
DMARC Alignment Pitfalls with Multi-Tenant ESPs
DMARC alignment challenges arise with multi-tenant ESPs, causing email deliverability issues, a common problem when using shared sending infrastructure
Read more
Optimising DMARC for Domains with High Volume Third-Party Senders
Optimise DMARC for domains with multiple third-party senders, avoiding false positives and phishing attacks
Read more
Troubleshooting DMARC Alignment Issues with Third-Party Senders
Achieving DMARC alignment with third-party senders is crucial for email authenticity, but often proves challenging, requiring careful configuration of SPF and DKIM records
Read more
DMARC and Email Client Configuration
DMARC prevents email spoofing, learn how to configure email clients like Mozilla Thunderbird and Microsoft Outlook for optimal security. Understand the basics of DMARC and its importance in email security
Read more
DMARC, SPF, and DKIM for Multi-Brand Companies
Multi-brand companies can improve email deliverability with DMARC, SPF, DKIM, preventing spam and phishing, and protecting their reputation. Proper implementation is crucial for seamless communication across brands
Read more
DMARC and Third-Party Service Onboarding: A Step-by-Step Guide to Secure Delegation
DMARC prevents email spoofing and phishing attacks by verifying email authenticity, enabling secure third-party service onboarding. This guide provides a step-by-step approach to secure delegation
Read more
DMARC and Dynamic DNS: Authentication Challenges for Home Workers and Small Offices
DMARC is crucial for email authentication, working with SPF and DKIM to verify email authenticity, but poses challenges for home workers and small offices using Dynamic DNS. DMARC helps organisations like Barclays prevent cybercriminals from sending fake emails
Read more
DMARC and Subdomain Delegation for Franchises and Multi-Tenant Systems
DMARC helps organisations secure email authentication, particularly for franchises and multi-tenant systems. It ensures only authorised emails are sent from their domain
Read more
DMARC Compliance for Merger and Acquisition Scenarios
DMARC compliance is crucial in merger and acquisition scenarios to prevent email delivery issues and protect brand reputation. Proper DMARC setup ensures email authenticity and deliverability
Read more
DMARC and Email Migration: A Step-by-Step Guide to Preserving Deliverability
Email migration can impact deliverability, DMARC helps prevent spoofing by verifying email authenticity
Read more
The complete guide to email authentication
A definitive cornerstone guide to SPF, DKIM, DMARC, MTA-STS and BIMI: what each does, how alignment ties them together, and the exact order to deploy them from zero to full protection.
Read more
The DMARC enforcement playbook: from p=none to p=reject
A complete, step-by-step playbook for safely reaching p=reject without breaking legitimate mail: monitoring, reading reports, fixing every source, ramping pct, and avoiding the classic failure modes.
Read more
The complete guide to SPF
A definitive reference to Sender Policy Framework: mechanisms, qualifiers, the 10-lookup and 2-void limits, permerror vs temperror, flattening, ~all vs -all, and SPF alignment for DMARC.
Read more
The complete guide to DKIM
A definitive, standards-accurate guide to DKIM: how signing works, selectors, key length, canonicalisation, the t=y flag, safe key rotation and DKIM alignment for DMARC.
Read more
The complete guide to BIMI and VMC
A definitive guide to BIMI and VMC: the enforced-DMARC prerequisite, SVG Tiny PS logo rules, VMC vs CMC, which inboxes show logos, costs, and a full deployment checklist.
Read more
The complete guide to email deliverability
A definitive guide to email deliverability: authentication as the foundation, sender reputation, the Gmail/Yahoo/Microsoft bulk-sender rules, list hygiene, warmup and where DMARC fits.
Read more
Stopping email fraud: BEC, phishing and domain spoofing
A definitive guide to how exact-domain spoofing, look-alike domains, display-name fraud and BEC actually work, exactly what DMARC stops, and how to build a layered defence.
Read more
Understanding DMARC reports: aggregate (RUA) and forensic (RUF)
A definitive field-by-field guide to DMARC aggregate (RUA) and forensic (RUF) reports: how to read the XML, tell a spoofer from a misconfigured legitimate sender, and turn the data into a safe path to enforcement.
Read more
ARC: Authenticated Received Chain explained
Forwarding and mailing lists break SPF and DKIM in transit, flipping a passing message to a DMARC failure. ARC, the Authenticated Received Chain, preserves the original authentication verdict across intermediaries with a signed, tamper-evident chain, so trusted forwarders can vouch for legitimate mail and you can reach p=reject without breaking list traffic.
Read more
How BIMI displays in Gmail and Apple Mail
Gmail and Apple Mail both reward an enforced DMARC domain with a verified logo, but each shows it differently and both demand a certificate. Here is what each provider displays, why a Verified Mark Certificate is non-negotiable, and how to test the whole BIMI chain before you rely on it.
Read more
Preparing a BIMI logo: SVG Tiny PS
BIMI only accepts one restricted image dialect: SVG Tiny PS. Here is what that profile requires, the squareness and sizing rules that catch people out, how to host the file over HTTPS, and the validation failures that come up again and again.
Read more
How to add DMARC, SPF and DKIM records on Azure DNS
An Azure DNS-specific walkthrough of publishing TXT and CNAME records for DMARC, SPF and DKIM, covering record sets, the @ apex, TXT chunking, the CLI add-record trap, Alias records and why delegation must be set at the registrar.
Read more
BIMI VMC vs CMC certificates
The two BIMI mark certificates compared: what a Verified Mark Certificate and a Common Mark Certificate are, who issues them, what they really cost, and which mailbox providers accept which.
Read more
How to add DMARC, SPF and DKIM records on Cloudflare
A precise, Cloudflare-specific walkthrough of publishing TXT and CNAME records for DMARC, SPF and DKIM in the Cloudflare DNS editor, with the real gotchas: root versus host name, the orange-cloud proxy, automatic TXT chunking, CNAME flattening at the apex, TTL on Auto, and Email Routing conflicts.
Read more
Done-for-you DMARC enforcement: how the managed path to p=reject works
Reaching p=reject is not the hard part. Anyone can change one DNS record from p=none to p=reject in thirty seconds. The hard part is reaching p=reject without silently dropping legitimate mail: the invoice from.
Read more
Display-name spoofing and why DMARC misses it
Friendly-from spoofing impersonates a person using a domain the attacker legitimately controls, so it passes DMARC every time by design. Here is why DMARC cannot catch it, where it shows up in BEC and CEO fraud, and the layered controls that actually mitigate it.
Read more
How to add DMARC, SPF and DKIM records on DigitalOcean
A DigitalOcean-specific walkthrough for publishing DMARC, SPF and DKIM as TXT and CNAME records in the DigitalOcean DNS editor, covering the root-vs-host hostname convention, the no-auto-chunking DKIM trap, apex CNAME rules and TTL.
Read more
Automatic SPF flattening: staying under ten lookups without thinking about it
SPF has a hard limit baked into the specification: a receiving server is allowed to perform at most ten DNS lookups while evaluating your record.
Read more
Why p=none gives a false sense of security
A DMARC record at p=none watches your domain but blocks nothing. Here is how to tell whether you are actually protected, and the safe path to enforcement.
Read more
DKIM alignment and forwarding
A valid DKIM signature is not the same as DKIM alignment. This guide explains how alignment is evaluated, why DKIM is the one signal that survives forwarding while SPF cannot, and exactly how relays and mailing lists affect it.
Read more
How to add DMARC, SPF and DKIM records on Gandi
A precise, Gandi-specific walkthrough for publishing DMARC, SPF and DKIM in the Gandi LiveDNS editor, covering the root vs host name convention, TXT quoting and chunking, CNAME trailing dots and TTL.
Read more
Hosted BIMI end to end: from logo to verified mark in the inbox
BIMI is the standard that puts your brand logo next to your messages in supporting mailboxes. It sounds like a design task, and the visible result certainly is a logo, but underneath it is a chain of dependencies.
Read more
1024-bit vs 2048-bit DKIM keys
2048-bit DKIM is now the baseline every major mailbox provider expects, but a 2048-bit public key will not fit in a single DNS TXT string. This guide covers the real security trade-offs, the 255-byte per-string DNS limit and how chunking works, the exact way each major DNS provider wants the value entered, and how to verify the published key actually parses before you rely on it.
Read more
How to add DMARC, SPF and DKIM records on GoDaddy
A precise, GoDaddy-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the GoDaddy DNS editor, covering root versus host names, TXT chunking, CNAME rules and TTL.
Read more
Turning raw DMARC XML into decisions: aggregate report analysis
A DMARC aggregate report is one of the most useful documents your domain will ever generate, and one of the least read. Publish a record with a rua= tag and, within a day or two, gzip-compressed XML files start.
Read more
How to rotate DKIM keys safely
DKIM signing keys decay in security the longer they live. This guide shows how to rotate them using selectors, with full overlap and verification, so legitimate mail never drops a signature or fails DMARC during the change.
Read more
How to add DMARC, SPF and DKIM records on Google Cloud DNS
A precise, Google Cloud DNS-specific walkthrough for publishing TXT and CNAME records for DMARC, SPF and DKIM, including the gotchas that silently break authentication: public versus private managed zones, console versus gcloud TXT quoting, trailing dots on CNAME targets, 255-byte chunking and a TTL strategy for a safe staged rollout to p=reject.
Read more
Email authentication explained for beginners
Email was designed in an era when everyone on the network trusted everyone else, so it shipped with no built-in way to prove who actually sent a message.
Read more
SPF PermError: when your SPF silently stops working
SPF breaks quietly. Cross the 10 DNS-lookup limit and your record returns PermError, fails open, and stops protecting your domain. Here is how to count, fix and flatten it safely.
Read more
DKIM selectors explained
A DKIM selector is the label that points a receiver at the right public key. Here is what selectors are, how to read them out of a message and DNS, and how multiple selectors let you rotate keys without an outage and let many senders sign one domain.
Read more