Blog (page 4)
Insights on email authentication, deliverability and security.
190 articles, page 4 of 4
Email authentication for SaaS companies
SaaS companies send several distinct mail streams at once: transactional, product, marketing and customer-generated. This guide shows how to structure SPF, DKIM, DMARC, MTA-STS and BIMI by subdomain so a bad day on one stream never poisons your password resets, and how to reach p=reject across every domain without an outage.
Read more
Email authentication for Salesforce: SPF, DKIM and DMARC
Salesforce is four senders, not one. Here are the exact SPF includes, how to generate and activate Salesforce DKIM CNAMEs, why bounce management breaks SPF alignment, and the staged path to p=reject across core, Marketing Cloud and Pardot.
Read more
Email authentication for SendGrid: SPF, DKIM and DMARC
A SendGrid-specific guide to SPF, DKIM and DMARC: the exact sendgrid.net include, Domain Authentication with the s1/s2 DKIM selectors, the custom return-path for SPF alignment, and the staged path to p=reject without breaking your mail.
Read more
Email authentication for SparkPost: SPF, DKIM and DMARC
A SparkPost-specific guide to SPF, DKIM and DMARC: the exact _spf.sparkpostmail.com include, the scph DKIM TXT record, the bounce-domain CNAME that makes SPF align, and how to reach p=reject without losing SparkPost mail.
Read more
Email authentication for Zendesk: SPF, DKIM and DMARC
Zendesk locks the Return-Path to its own domain, so SPF can never align and DKIM is the only mechanism that carries your DMARC pass. Here are the exact zendesk1 and zendesk2 CNAMEs, the mail.zendesk.com SPF include, the safe order of operations and how to reach p=reject without breaking support email.
Read more
Email authentication for Zoho Mail: SPF, DKIM and DMARC
A Zoho Mail-specific guide to SPF, DKIM and DMARC: the exact Zoho SPF include, how to generate and publish DKIM selectors in the Admin Console, the return-path and alignment quirks that decide whether DMARC passes, and a safe sequence from p=none to p=reject.
Read more
Executive impersonation and CEO fraud
CEO fraud forges your leaders to authorise urgent payments. Enforced DMARC kills exact-domain spoofing outright, but leaves real gaps. Here is exactly what it stops, what it cannot, and the layers you need around it.
Read more
Feedback loops and complaint handling
A feedback loop (FBL) is how a mailbox provider tells you a user marked your mail as spam. Learn what FBLs are, how Yahoo, Microsoft and Gmail differ, how to enrol against your DKIM signing domain, how to read ARF reports, and how to keep your complaint rate under the 0.3% threshold.
Read more
Fix: BIMI logo not showing in Gmail
Gmail shows a grey initial instead of your BIMI logo and never says why. Here is every reason it fails, in the order Gmail checks them: DMARC not at enforcement, a missing VMC, an SVG that breaks the Tiny PS profile, a logo-to-certificate mismatch, and cached negative results, plus how to fix each.
Read more
Fix: DKIM fails after forwarding
Forwarders and mailing lists break DKIM by changing the message body and headers, not the connection. Here is exactly what fails, what survives, where ARC helps, how to spot forwarding failures in your DMARC reports, and how to reduce the impact without parking at p=none.
Read more
Fix: DKIM public key not found in DNS
The "DKIM public key not found in DNS" error is almost always a naming or publishing problem, not a broken key. Here is exactly which name receivers query, why it returns nothing, how CNAME and TXT publishing differ, and how to confirm the key resolves end to end.
Read more
Fix: DKIM signature did not verify
"DKIM signature did not verify" is at least six different problems wearing one error string: body hash mismatch, no key in DNS, malformed record, key mismatch after rotation, expired signature, or a key too short. Here is how to read the exact reason in the brackets and apply the one correct fix for each.
Read more
Fix: MTA-STS policy not found
"MTA-STS policy not found" is never one problem: it is a five-link chain (DNS TXT, HTTPS host, certificate, file path, file content) plus the MX-coverage trap, and it fails silently because senders fall back to opportunistic TLS rather than bounce. Walk the discovery the way a sending MTA does, with real dig, curl and openssl checks, and fix the first broken link.
Read more
Fix: multiple DMARC records
Two TXT records at _dmarc do not make DMARC stricter; they switch it off entirely, silently. Here is why RFC 7489 mandates that, the exact ways duplicates sneak into a zone, how to detect them and how to consolidate down to one correct record without losing your settings.
Read more
Fix: multiple SPF records
Two SPF records on one domain force a permanent PermError that silently strips a DMARC route. Here is why it happens, how receivers treat it, and how to merge two records into one compliant record without losing a sender or blowing the 10-lookup limit.
Read more
Fix: SPF TempError
An SPF TempError is a transient DNS failure, not a broken record. Here is what it means, why it differs from PermError, how Google, Yahoo and Microsoft treat it under SPF and DMARC, and the concrete steps that make your SPF resolution reliable.
Read more
Fix: SPF too many DNS lookups
SPF caps you at ten DNS-querying mechanisms, counted after every include expands into its provider's nested netblocks, which is why a record with five includes can spend fifteen lookups and PermError. Here is how to count the budget, prune the includes that overspend it, and flatten or consolidate back under the limit before enforcement makes the failure bite.
Read more
Free checkers vs paid DMARC platforms
Free DMARC checkers read the current state of your DNS in one lookup, and they do that job completely. Enforcement is different: getting a domain from p=none to p=reject without dropping legitimate mail is a multi-week process driven by the continuous aggregate-report stream, which no one-shot tool can ever surface. This guide draws the exact line between what free checkers do well, where they structurally stop, and what a managed platform adds, plus an honest account of who needs the paid side and who does not.
Read more
GDPR and DMARC reporting
DMARC reports can contain personal data: source IPs in aggregate reports, and recipients, subjects and message bodies in forensic reports. Here is which fields the UK and EU GDPR catch, why forensic (ruf) reporting is the real hazard most domains should drop, and the lawful basis, retention and transfer practices that keep aggregate (rua) collection compliant.
Read more
Getting a trademark for a BIMI VMC
A Verified Mark Certificate will not issue without a registered figurative trademark for your logo. Here is why that prerequisite exists, the real registration timeline and cost, and the CMC route for organisations that have no trademark.
Read more
Gift card scams over email
Gift card BEC is business email compromise stripped to its cheapest form: no payload, just a name, a deadline and an irreversible cash-out. Here is how these scams work, why they lean on look-alike domains and spoofed display names rather than forging your real domain, and exactly what DMARC, SPF, DKIM and human controls can and cannot do to reduce your exposure.
Read more
Using Google Postmaster Tools
Google Postmaster Tools shows you how Gmail scores your domain and IP reputation, what share of your mail authenticates, your TLS coverage, and how often Gmail users mark your messages as spam. Here is how to read each dashboard, the spam-rate and reputation thresholds that actually matter, and how to pair it with DMARC aggregate data to find and fix the source of any problem.
Read more
Header-From vs envelope-from: the two From addresses
Every email carries two different From addresses: the header-from (RFC5322.From) that humans see and the envelope-from (RFC5321.MailFrom) used for bounces. SPF checks one, DMARC checks the other, and the gap between them explains alignment, forwarding breakage and spoofing.
Read more
Homograph and IDN spoofing domains
Homograph and IDN attacks register domains built from confusable Unicode characters that render identically to yours, then authenticate mail from them. Here is why DMARC, SPF and DKIM cannot stop it, how the Punycode trick works, and how to detect, register and monitor the variants that actually matter.
Read more
Hosted vs do-it-yourself DMARC
DIY DMARC looks free, but the real cost lives in senior time, the risk of breaking your own mail on the way to enforcement, and the monitoring tail nobody keeps up. Here is how to price hosted versus do-it-yourself honestly, and decide which your domain actually needs.
Read more
Inbox placement testing
Inbox placement testing tells you where your mail lands (inbox, spam, a tab, or nowhere), which DMARC reports cannot. Here is how seed lists and panel tools actually work, where they mislead you, and how to cross-read their output with DMARC aggregate data so authentication faults and reputation faults stop looking identical.
Read more
IP warming for new sending IPs
A new sending IP starts with zero reputation, so a sudden volume spike reads as spam. Here is a sensible warm-up schedule, when a dedicated IP is even worth it, and how aligned SPF, DKIM and DMARC make the reputation you build stick to your domain instead of a leased IP.
Read more
List hygiene and deliverability
Authentication proves who you are; list hygiene proves you are wanted. Once DMARC enforcement welds reputation to your verified domain, dead addresses, bounces and spam-trap hits stop being diffuse problems and start hitting your signed identity directly. Here is how clean lists protect the reputation your SPF, DKIM and DMARC setup earns.
Read more
Using Microsoft SNDS and JMRP
Microsoft gives self-hosted senders two free feedback channels into Outlook.com filtering: SNDS for IP reputation, complaint bands and spam-trap hits, and JMRP for the individual junk complaints behind them. Here is how to enrol, read the data honestly, instrument your mail so complaints are traceable, and connect it all to your DMARC alignment so an Outlook deliverability dip becomes diagnosable instead of a mystery.
Read more
MTA-STS vs DANE: which transport security to use
MTA-STS and DANE both stop SMTP downgrade attacks, but they anchor trust in opposite places: the web PKI versus DNSSEC. Here is how their trust models, failure behaviour and deployment burden differ, and a concrete guide to choosing one or running both.
Read more
Payroll diversion fraud
Payroll diversion fraud redirects an employee's salary to a criminal's account with a single polite email asking to update bank details. Here is exactly how the direct-deposit redirect scam works over email, which of its four spoofing variants DMARC at enforcement actually stops, and the verification and process controls that close the gaps authentication cannot reach.
Read more
QR code phishing (quishing)
Quishing hides a phishing URL inside a QR code so it slips past the URL-aware parts of your mail stack, then teleports the victim onto an unmonitored phone. Here is exactly why filters miss it, where DMARC at p=reject stops the impersonation route and where authentication categorically cannot help, plus the layered technical and user defences that actually work.
Read more
Relaxed vs strict DMARC alignment
DMARC does not check whether SPF or DKIM passed, it checks alignment. The aspf and adkim tags decide how exact that match must be. Here is when strict alignment is worth it, when relaxed is right, and exactly how the choice reshapes subdomain sending.
Read more
RFC 6376: the DKIM standard explained
A line-by-line tour of the DKIM specification: how a message is signed and canonicalised, what every tag in the DKIM-Signature header means, how the public key record is published in DNS, and exactly what a verifier does on the way in.
Read more
RFC 7208: the SPF standard explained
The SPF specification in plain British English: the record format, every mechanism, the four qualifiers, the eight result codes, the 10-lookup and void-lookup limits, and the macro language. Real example records throughout, plus exactly why SPF speaks for the return-path and never the visible From.
Read more
RFC 7489: the DMARC standard explained
A close reading of RFC 7489, the document that defines DMARC: the From-header trust model, identifier alignment, the record tags, policy discovery and application, the two report types, and the clauses people consistently misread.
Read more
RFC 8461: the MTA-STS standard explained
A precise walk through RFC 8461: why server-to-server mail needed MTA-STS, the _mta-sts DNS signal, the HTTPS-hosted policy file, the none, testing and enforce modes, and exactly how a sending MTA fetches and applies a policy.
Read more
RFC 8617: the ARC standard explained
Forwarding breaks SPF alignment and DKIM signatures, so DMARC fails on mail you legitimately sent. ARC, defined in RFC 8617, lets a trusted intermediary vouch for the authentication verdict it saw before it touched the message. This is a hop-by-hop walk through the three ARC header fields, how sealing works, how chain validation runs, and what a final receiver actually does with an ARC result after forwarding.
Read more
SPF macros explained
SPF macros turn a record into a small evaluated language, substituting live transaction data like the connecting IP into DNS queries. Here is the %{...} syntax, the macro letters and modifiers, the real use cases that justify them, and the lookup-count and security trade-offs you take on when you publish one.
Read more
SPF vs Sender ID: a short history
Sender ID was a serious 2000s attempt to authenticate the visible From address, sharing SPF's syntax but checking a different identity. Here is why it faded, what it shared with SPF, and what to do when you find a stale spf2.0/ record in your DNS today.
Read more
A subdomain strategy for sending mail
Splitting transactional, marketing and corporate mail across dedicated subdomains isolates reputation and shrinks the DMARC enforcement problem into small, independently controllable streams. Here is how to design the split, the exact SPF, DKIM and DMARC records to publish, and how to migrate without an email outage.
Read more
Subdomain takeover and email
When a forgotten CNAME or lapsed NS record dangles, an attacker can claim the subdomain, publish their own SPF and DKIM, and send mail that passes SPF, DKIM and DMARC from a real subdomain of your domain. Here is why p=reject does not catch it, how it hides in your reports, and how to find and close dangling DNS before it is exploited.
Read more
Thread hijacking email attacks
Thread hijacking inserts a malicious reply into a real conversation you already trust. Here is how attackers obtain the thread, the two delivery techniques that decide whether authentication can stop it, and the layered defences that cover the gaps DMARC cannot.
Read more
Typosquatting and email fraud
Attackers register misspelt look-alike domains, authenticate them properly, and send mail that passes every check you have. Here is why your DMARC at p=reject cannot stop ASCII typosquatting, how it differs from homograph spoofing and display-name fraud, and the monitoring, defensive-registration and process layers that actually reduce the risk.
Read more
Vendor email compromise
A supplier breach turns into a fraudulent invoice from a genuine, fully authenticated address. Here is how vendor email compromise works, why DMARC passes it cleanly, and the layered controls that actually catch it.
Read more
BIMI VMC cost and certificate authorities
What a Verified Mark Certificate actually costs, which CAs issue them (DigiCert and Entrust), how trademark and entity validation works, and what to watch at renewal so your logo never silently disappears.
Read more