DMARC Engine
Home/Blog
Blog

Blog (page 2)

Insights on email authentication, deliverability and security.

218 articles, page 2 of 5

24 June 2026 · 12 min read

The complete guide to BIMI and VMC

A definitive guide to BIMI and VMC: the enforced-DMARC prerequisite, SVG Tiny PS logo rules, VMC vs CMC, which inboxes show logos, costs, and a full deployment checklist.

Read more
24 June 2026 · 14 min read

The complete guide to email deliverability

A definitive guide to email deliverability: authentication as the foundation, sender reputation, the Gmail/Yahoo/Microsoft bulk-sender rules, list hygiene, warmup and where DMARC fits.

Read more
24 June 2026 · 12 min read

Stopping email fraud: BEC, phishing and domain spoofing

A definitive guide to how exact-domain spoofing, look-alike domains, display-name fraud and BEC actually work, exactly what DMARC stops, and how to build a layered defence.

Read more
24 June 2026 · 13 min read

Understanding DMARC reports: aggregate (RUA) and forensic (RUF)

A definitive field-by-field guide to DMARC aggregate (RUA) and forensic (RUF) reports: how to read the XML, tell a spoofer from a misconfigured legitimate sender, and turn the data into a safe path to enforcement.

Read more
20 June 2026 · 12 min read

ARC: Authenticated Received Chain explained

Forwarding and mailing lists break SPF and DKIM in transit, flipping a passing message to a DMARC failure. ARC, the Authenticated Received Chain, preserves the original authentication verdict across intermediaries with a signed, tamper-evident chain, so trusted forwarders can vouch for legitimate mail and you can reach p=reject without breaking list traffic.

Read more
19 June 2026 · 13 min read

How BIMI displays in Gmail and Apple Mail

Gmail and Apple Mail both reward an enforced DMARC domain with a verified logo, but each shows it differently and both demand a certificate. Here is what each provider displays, why a Verified Mark Certificate is non-negotiable, and how to test the whole BIMI chain before you rely on it.

Read more
18 June 2026 · 14 min read

The Google and Yahoo sender rules, one year on

A year after Google and Yahoo made authentication mandatory for bulk senders, here is what changed, how mail failed, and where enforcement is heading.

Read more
18 June 2026 · 11 min read

Preparing a BIMI logo: SVG Tiny PS

BIMI only accepts one restricted image dialect: SVG Tiny PS. Here is what that profile requires, the squareness and sizing rules that catch people out, how to host the file over HTTPS, and the validation failures that come up again and again.

Read more
18 June 2026 · 13 min read

How to add DMARC, SPF and DKIM records on Azure DNS

An Azure DNS-specific walkthrough of publishing TXT and CNAME records for DMARC, SPF and DKIM, covering record sets, the @ apex, TXT chunking, the CLI add-record trap, Alias records and why delegation must be set at the registrar.

Read more
17 June 2026 · 11 min read

BIMI VMC vs CMC certificates

The two BIMI mark certificates compared: what a Verified Mark Certificate and a Common Mark Certificate are, who issues them, what they really cost, and which mailbox providers accept which.

Read more
17 June 2026 · 14 min read

How to add DMARC, SPF and DKIM records on Cloudflare

A precise, Cloudflare-specific walkthrough of publishing TXT and CNAME records for DMARC, SPF and DKIM in the Cloudflare DNS editor, with the real gotchas: root versus host name, the orange-cloud proxy, automatic TXT chunking, CNAME flattening at the apex, TTL on Auto, and Email Routing conflicts.

Read more
17 June 2026 · 13 min read

Done-for-you DMARC enforcement: how the managed path to p=reject works

Reaching p=reject is not the hard part. Anyone can change one DNS record from p=none to p=reject in thirty seconds. The hard part is reaching p=reject without silently dropping legitimate mail: the invoice from.

Read more
16 June 2026 · 11 min read

Display-name spoofing and why DMARC misses it

Friendly-from spoofing impersonates a person using a domain the attacker legitimately controls, so it passes DMARC every time by design. Here is why DMARC cannot catch it, where it shows up in BEC and CEO fraud, and the layered controls that actually mitigate it.

Read more
16 June 2026 · 16 min read

How to add DMARC, SPF and DKIM records on DigitalOcean

A DigitalOcean-specific walkthrough for publishing DMARC, SPF and DKIM as TXT and CNAME records in the DigitalOcean DNS editor, covering the root-vs-host hostname convention, the no-auto-chunking DKIM trap, apex CNAME rules and TTL.

Read more
16 June 2026 · 13 min read

Automatic SPF flattening: staying under ten lookups without thinking about it

SPF has a hard limit baked into the specification: a receiving server is allowed to perform at most ten DNS lookups while evaluating your record.

Read more
15 June 2026 · 11 min read

Why p=none gives a false sense of security

A DMARC record at p=none watches your domain but blocks nothing. Here is how to tell whether you are actually protected, and the safe path to enforcement.

Read more
15 June 2026 · 10 min read

DKIM alignment and forwarding

A valid DKIM signature is not the same as DKIM alignment. This guide explains how alignment is evaluated, why DKIM is the one signal that survives forwarding while SPF cannot, and exactly how relays and mailing lists affect it.

Read more
15 June 2026 · 17 min read

How to add DMARC, SPF and DKIM records on Gandi

A precise, Gandi-specific walkthrough for publishing DMARC, SPF and DKIM in the Gandi LiveDNS editor, covering the root vs host name convention, TXT quoting and chunking, CNAME trailing dots and TTL.

Read more
15 June 2026 · 13 min read

Hosted BIMI end to end: from logo to verified mark in the inbox

BIMI is the standard that puts your brand logo next to your messages in supporting mailboxes. It sounds like a design task, and the visible result certainly is a logo, but underneath it is a chain of dependencies.

Read more
14 June 2026 · 12 min read

1024-bit vs 2048-bit DKIM keys

2048-bit DKIM is now the baseline every major mailbox provider expects, but a 2048-bit public key will not fit in a single DNS TXT string. This guide covers the real security trade-offs, the 255-byte per-string DNS limit and how chunking works, the exact way each major DNS provider wants the value entered, and how to verify the published key actually parses before you rely on it.

Read more
14 June 2026 · 13 min read

How to add DMARC, SPF and DKIM records on GoDaddy

A precise, GoDaddy-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the GoDaddy DNS editor, covering root versus host names, TXT chunking, CNAME rules and TTL.

Read more
14 June 2026 · 14 min read

Turning raw DMARC XML into decisions: aggregate report analysis

A DMARC aggregate report is one of the most useful documents your domain will ever generate, and one of the least read. Publish a record with a rua= tag and, within a day or two, gzip-compressed XML files start.

Read more
13 June 2026 · 10 min read

How to rotate DKIM keys safely

DKIM signing keys decay in security the longer they live. This guide shows how to rotate them using selectors, with full overlap and verification, so legitimate mail never drops a signature or fails DMARC during the change.

Read more
13 June 2026 · 21 min read

How to add DMARC, SPF and DKIM records on Google Cloud DNS

A precise, Google Cloud DNS-specific walkthrough for publishing TXT and CNAME records for DMARC, SPF and DKIM, including the gotchas that silently break authentication: public versus private managed zones, console versus gcloud TXT quoting, trailing dots on CNAME targets, 255-byte chunking and a TTL strategy for a safe staged rollout to p=reject.

Read more
13 June 2026 · 15 min read

Email authentication explained for beginners

Email was designed in an era when everyone on the network trusted everyone else, so it shipped with no built-in way to prove who actually sent a message.

Read more
12 June 2026 · 12 min read

SPF PermError: when your SPF silently stops working

SPF breaks quietly. Cross the 10 DNS-lookup limit and your record returns PermError, fails open, and stops protecting your domain. Here is how to count, fix and flatten it safely.

Read more
12 June 2026 · 10 min read

DKIM selectors explained

A DKIM selector is the label that points a receiver at the right public key. Here is what selectors are, how to read them out of a message and DNS, and how multiple selectors let you rotate keys without an outage and let many senders sign one domain.

Read more
12 June 2026 · 13 min read

How to add DMARC, SPF and DKIM records on IONOS

A precise, IONOS-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the IONOS DNS editor, covering the root-versus-host gotcha, TXT chunking, CNAME flattening, TTL and a safe sequence to p=reject.

Read more
12 June 2026 · 14 min read

Why your domain can be spoofed, and how to stop it

If you own a domain and have never published a DMARC record, anyone on the internet can send email that appears to come from you.

Read more
11 June 2026 · 14 min read

DMARC alignment explained, with examples

A message can pass SPF and verify DKIM yet still fail DMARC. The reason is alignment. This guide explains SPF and DKIM alignment, relaxed versus strict mode, and the exact DMARC pass rule, with five worked examples of messages that pass and fail.

Read more
11 June 2026 · 14 min read

How to add DMARC, SPF and DKIM records on Namecheap

A precise, Namecheap-specific walkthrough for adding DMARC, SPF and DKIM records in the Advanced DNS editor, covering the host-field gotchas, TXT chunking, CNAME targets, TTL and the safe path from p=none to p=reject.

Read more
11 June 2026 · 15 min read

The five DNS records that protect your email

Email was designed in an era of trust. The original protocol, SMTP, lets any server on the internet claim to send mail as anyone.

Read more
10 June 2026 · 12 min read

Ten common DMARC mistakes and how to avoid them

The configuration and rollout mistakes that most often break mail or leave domains exposed, from jumping straight to p=reject to ignoring report drift, and exactly how to avoid each one.

Read more
10 June 2026 · 14 min read

How to add DMARC, SPF and DKIM records on OVH

A precise, OVH-specific walkthrough for adding SPF, DKIM and DMARC records in the OVH DNS zone editor, covering the apex naming rule, TXT chunking for long DKIM keys, CNAME trailing dots and TTL behaviour.

Read more
10 June 2026 · 14 min read

Why email forwarding breaks SPF and DKIM

Email almost never travels in a straight line from sender to recipient. It gets redirected by university and corporate aliases, fanned out by mailing lists, scrubbed by security gateways, and quietly relayed by.

Read more
9 June 2026 · 12 min read

Reading your first DMARC aggregate report

A field-by-field walkthrough of a DMARC aggregate (RUA) XML report: metadata, source IPs, disposition, SPF and DKIM results, alignment, and spotting spoofers.

Read more
9 June 2026 · 11 min read

Protecting parked and no-mail domains

Domains that never send mail are the easiest to secure and the most commonly left wide open. Here is how to lock down parked, legacy and campaign domains with SPF -all, DMARC p=reject and a null MX so they cannot be spoofed, with zero deliverability risk.

Read more
9 June 2026 · 15 min read

How to add DMARC, SPF and DKIM records on AWS Route 53

A precise, Route 53-specific walkthrough for publishing SPF, DKIM and DMARC: empty Record name versus host names, TXT quoting and 255-character chunking, why DKIM CNAMEs must never become Alias records, and TTL strategy for a safe staged path to p=reject.

Read more
9 June 2026 · 14 min read

Mailing lists, DMARC and ARC

Mailing lists are one of the few places where correct, well-behaved email authentication still breaks for reasons that are nobody's fault.

Read more
8 June 2026 · 13 min read

DMARC for Google Workspace

A new Google Workspace domain ships with no DKIM signing, an SPF record you must add yourself, and no DMARC policy at all. This guide walks the exact order to fix that: get SPF right under the 10-lookup limit, switch on DKIM in the Admin console, then ratchet DMARC from monitoring to full reject without breaking a single legitimate message.

Read more
8 June 2026 · 16 min read

How to add DMARC, SPF and DKIM records on Squarespace

A precise, Squarespace-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the Squarespace DNS editor, including the gotchas that actually break setups: the doubled-domain Host field, TXT chunking, CNAME-at-apex, SPF flattening and TTL.

Read more
8 June 2026 · 15 min read

Aliases, .forward files and DMARC

An alias looks like the most innocent thing in email. You point sales@yourcompany.com at three colleagues, you set up info@ to land in a shared mailbox, a member of staff configures their university address to drop.

Read more
7 June 2026 · 12 min read

DMARC for Microsoft 365

A practical, ordered guide to email authentication on Microsoft 365: build a complete SPF record for Exchange Online, enable DKIM signing with Microsoft's two selector CNAMEs, and walk DMARC safely from p=none through quarantine to p=reject without breaking your mail.

Read more
7 June 2026 · 14 min read

How to add DMARC, SPF and DKIM records on Wix

A precise, Wix-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the Wix DNS editor, covering the real gotchas: relative host names, long-TXT chunking, CNAME targets without a trailing dot, the one-SPF-record rule and TTL during testing.

Read more
7 June 2026 · 14 min read

Amazon SES at scale: deliverability and DMARC

Amazon SES is deceptively easy to start with and deceptively hard to run well at volume. Verifying a domain, adding three DNS records and firing your first message takes an afternoon.

Read more
6 June 2026 · 11 min read

Do you actually need BIMI?

An honest decision guide to BIMI: what it really requires, what a VMC costs, the CMC alternative, the SVG Tiny PS rules, and who should skip it.

Read more
6 June 2026 · 16 min read

The DMARC pct tag and sampling, explained

The pct tag was DMARC's sampling dial until RFC 9989 removed it. How legacy receivers still apply it, why pct=0 was a downgrade trap, and how to migrate off it safely.

Read more
6 June 2026 · 12 min read

The BIMI selector explained

The selector is the label in front of _bimi that tells a receiver which logo record to fetch. Here is how the default._bimi lookup and the BIMI-Selector header actually work, and the real cases where you would publish a non-default selector for seasonal, multi-brand or test logos.

Read more