Blog (page 4)
Insights on email authentication, deliverability and security.
218 articles, page 4 of 5
Email authentication for schools and universities
A practical, stage-by-stage path to DMARC enforcement on a sprawling .edu or .ac.uk estate: discovery, fixing SPF under the ten-lookup limit, aligning DKIM across many departmental senders, ramping to p=reject, and the governance traps that stall most rollouts.
Read more
SPF flattening: what it is and when you need it
SPF flattening replaces lookup-based mechanisms with raw IP ranges to dodge the ten-lookup limit. It works, but a hand-flattened record silently goes stale. Here is what flattening really does, the trade-offs, why doing it by hand is risky, and how hosted flattening stays current automatically.
Read more
Email authentication for Fastmail: SPF, DKIM and DMARC
A Fastmail-specific setup guide: the exact spf.messagingengine.com SPF include, the three fm1/fm2/fm3 DKIM CNAMEs, how return-path and DKIM alignment behave, and the safe path from p=none to p=reject.
Read more
SPF records for common email providers
The correct, current SPF includes for Google Workspace, Microsoft 365, Mailchimp, SendGrid, Amazon SES and more, plus how to combine several providers in one record without breaking the 10-lookup limit.
Read more
Email authentication for financial services
For banks, insurers and fintechs, DMARC, SPF, DKIM, MTA-STS and BIMI are anti-fraud and brand-protection controls, not deliverability tweaks. How to meet regulatory expectations and reach p=reject across a multi-vendor estate without breaking OTP or statement mail.
Read more
What is BIMI and is it worth it?
BIMI puts your brand logo beside authenticated mail, but only after DMARC enforcement and, for the big providers, a paid certificate. Here is what it shows, what it costs, and an honest view of who actually benefits.
Read more
Email authentication for Freshdesk: SPF, DKIM and DMARC
A Freshdesk-specific setup guide: the exact SPF include, the fdkim1 and fdkim2 DKIM CNAMEs, why the Return-Path means SPF will not align, and how to reach DMARC enforcement on support email without breaking ticket replies.
Read more
DANE and TLSA records explained
DANE pins your mail server's certificate in DNSSEC-signed TLSA records so senders refuse to deliver over a downgraded or substituted TLS connection. Here is how TLSA records work, how DNSSEC anchors the trust, how DANE compares with MTA-STS, and which one fits your domain.
Read more
Email authentication for government
Public-sector domains are prime spoofing targets because the state's authority is the most valuable brand a fraudster can wear. Here is why government email is forged, the mandates pushing departments to p=reject, and the engineering realities of getting a sprawling government estate to enforcement without cutting off citizen mail.
Read more
What is DKIM and how does it work?
DKIM attaches a cryptographic signature to every message you send, letting receivers verify with a public key in DNS that the mail really came from your domain and was not altered. Learn how signing and verification work step by step, how to read the headers and DNS record, and why a DKIM signature survives forwarding that breaks SPF outright.
Read more
Email authentication for healthcare and HIPAA
HIPAA never names DMARC, but it asks for exactly what SPF, DKIM and DMARC deliver: protection of transmitted PHI, integrity, sender authentication and ongoing risk management. Here is how email authentication maps onto the HIPAA Security Rule, why DMARC reporting need not expose PHI, and the staged path to p=reject that does not break clinical email.
Read more
What is DMARC and how does it work?
DMARC is the control that stops exact-domain spoofing. Here is what it is, how it builds on SPF and DKIM through alignment, what each policy value instructs receivers to do, and how to reach p=reject safely.
Read more
Email authentication for HubSpot: SPF, DKIM and DMARC
A HubSpot-specific guide to email authentication: the exact SPF include, HubSpot's two CNAME-based DKIM selectors, the custom bounce subdomain for return-path alignment, and how to take a HubSpot-sending domain from p=none to p=reject without breaking email.
Read more
What is MTA-STS and how does it work?
MTA-STS forces encrypted, authenticated delivery of your inbound mail. Learn how the _mta-sts DNS record and the HTTPS-hosted policy file work together, the difference between testing and enforce mode, and exactly how it stops TLS downgrade and interception attacks.
Read more
Email authentication for Intercom: SPF, DKIM and DMARC
Intercom gives you both halves of DMARC: a DKIM CNAME and a custom return-path CNAME that makes SPF align. Here is the exact selector, the two records to publish, why you do not add an SPF include, and how to reach p=reject without breaking your onboarding, campaign or support email.
Read more
What is SPF and how does it work?
SPF lets you publish, in DNS, the list of servers allowed to send mail for your domain. Here is how the syntax works, what the all qualifier and each mechanism mean, what SPF actually authorises, the ten-lookup limit that catches everyone, and the spoofing gap that DMARC alignment closes.
Read more
Email authentication for Klaviyo: SPF, DKIM and DMARC
A Klaviyo-specific guide to SPF, DKIM and DMARC: the exact _spf.klaviyomail.com include, the kl/kl2 DKIM selectors, the dedicated sending domain CNAMEs, custom return-path alignment, and the safe path from p=none to p=reject without losing a campaign or flow.
Read more
What is TLS-RPT?
TLS-RPT (SMTP TLS Reporting) is a single safe-to-publish DNS record that gives you a daily, machine-readable summary of how other mail servers negotiated encryption with your inbound MX hosts. Learn what the record and its JSON reports contain, how to decode each failure type, and the exact publish-then-enforce workflow that pairs it with MTA-STS without risking an email outage.
Read more
Email authentication for law firms
How solicitors use SPF, DKIM and DMARC to stop their domain being spoofed, protect client money on completions, and meet their confidentiality duties, with a staged, no-outage path to p=reject.
Read more
Why legitimate email lands in spam
Real, useful email ends up in the junk folder when its signals look untrustworthy to mailbox providers. This guide breaks misfiled mail into its four root causes (authentication, reputation, content and complaints) and shows how to diagnose and fix each with concrete tools and steps, starting with the highest-leverage fix: authentication.
Read more
Email authentication for Mailchimp: SPF, DKIM and DMARC
A Mailchimp-specific guide to SPF, DKIM and DMARC: the exact mcsv.net include, how to publish Mailchimp's DKIM CNAMEs, why default bounce addresses break SPF alignment, and how to reach p=reject without losing a campaign.
Read more
Email authentication for Mailgun: SPF, DKIM and DMARC
A complete, Mailgun-specific walkthrough: the exact SPF include, how to enable and publish DKIM with Mailgun's real selector, why the default return-path breaks SPF alignment, and how to reach DMARC enforcement when sending through Mailgun's subdomain model without an email outage.
Read more
Email authentication for Mailjet: SPF, DKIM and DMARC
A Mailjet-specific guide to SPF, DKIM and DMARC: the exact spf.mailjet.com include and why you can skip it, the mailjet._domainkey DKIM record, why the bnc3.mailjet.com return-path breaks SPF alignment, how to set a custom return-path, and the staged path to p=reject without losing mail.
Read more
Email authentication for Mimecast: SPF, DKIM and DMARC
A Mimecast-specific guide to SPF, DKIM and DMARC: the exact regional includes, generating and publishing a DKIM key from the console, why return-path and From alignment behave differently behind a gateway, and how to reach p=reject without an email outage.
Read more
Email authentication for nonprofits
For charities, DMARC is donor trust and fundraising revenue expressed as DNS records: it stops attackers spoofing your appeals and lifts your own appeals out of the spam folder. Here is how to align every sender, ramp safely to p=reject, and put your logo in the inbox, including via a Common Mark Certificate when your charity logo is not a registered trademark.
Read more
Email authentication for Postmark: SPF, DKIM and DMARC
A Postmark-specific guide to SPF, DKIM and DMARC: the exact spf.mtasv.net include, publishing the DKIM CNAME selectors, configuring a custom Return-Path for SPF alignment, and ramping safely from p=none to p=reject without breaking transactional mail.
Read more
Email authentication for Proofpoint: SPF, DKIM and DMARC
Proofpoint is a gateway, not an ESP, so it relays your mail from its own IPs and that quietly breaks SPF and DKIM alignment. This Proofpoint-specific guide gives the exact SPF mechanism for Essentials (a:dispatch-us.ppe-hosted.com) and the cluster include for Protection Server, the DKIM signing and selector workflow for both products, how the return path affects SPF alignment, and the staged path to p=reject with Proofpoint in front of Microsoft 365 or Google Workspace.
Read more
Email authentication for Proton Mail: SPF, DKIM and DMARC
A Proton Mail-specific guide to SPF, DKIM and DMARC on a custom domain: the exact _spf.protonmail.ch include, Proton's three rotating DKIM CNAME records, the return-path quirk that makes DKIM load-bearing for alignment, and a safe path to p=reject.
Read more
Email authentication for SaaS companies
SaaS companies send several distinct mail streams at once: transactional, product, marketing and customer-generated. This guide shows how to structure SPF, DKIM, DMARC, MTA-STS and BIMI by subdomain so a bad day on one stream never poisons your password resets, and how to reach p=reject across every domain without an outage.
Read more
Email authentication for Salesforce: SPF, DKIM and DMARC
Salesforce is four senders, not one. Here are the exact SPF includes, how to generate and activate Salesforce DKIM CNAMEs, why bounce management breaks SPF alignment, and the staged path to p=reject across core, Marketing Cloud and Pardot.
Read more
Email authentication for SendGrid: SPF, DKIM and DMARC
A SendGrid-specific guide to SPF, DKIM and DMARC: the exact sendgrid.net include, Domain Authentication with the s1/s2 DKIM selectors, the custom return-path for SPF alignment, and the staged path to p=reject without breaking your mail.
Read more
Email authentication for SparkPost: SPF, DKIM and DMARC
A SparkPost-specific guide to SPF, DKIM and DMARC: the exact _spf.sparkpostmail.com include, the scph DKIM TXT record, the bounce-domain CNAME that makes SPF align, and how to reach p=reject without losing SparkPost mail.
Read more
Email authentication for Zendesk: SPF, DKIM and DMARC
Zendesk locks the Return-Path to its own domain, so SPF can never align and DKIM is the only mechanism that carries your DMARC pass. Here are the exact zendesk1 and zendesk2 CNAMEs, the mail.zendesk.com SPF include, the safe order of operations and how to reach p=reject without breaking support email.
Read more
Email authentication for Zoho Mail: SPF, DKIM and DMARC
A Zoho Mail-specific guide to SPF, DKIM and DMARC: the exact Zoho SPF include, how to generate and publish DKIM selectors in the Admin Console, the return-path and alignment quirks that decide whether DMARC passes, and a safe sequence from p=none to p=reject.
Read more
Executive impersonation and CEO fraud
CEO fraud forges your leaders to authorise urgent payments. Enforced DMARC kills exact-domain spoofing outright, but leaves real gaps. Here is exactly what it stops, what it cannot, and the layers you need around it.
Read more
Feedback loops and complaint handling
A feedback loop (FBL) is how a mailbox provider tells you a user marked your mail as spam. Learn what FBLs are, how Yahoo, Microsoft and Gmail differ, how to enrol against your DKIM signing domain, how to read ARF reports, and how to keep your complaint rate under the 0.3% threshold.
Read more
Fix: BIMI logo not showing in Gmail
Gmail shows a grey initial instead of your BIMI logo and never says why. Here is every reason it fails, in the order Gmail checks them: DMARC not at enforcement, a missing VMC, an SVG that breaks the Tiny PS profile, a logo-to-certificate mismatch, and cached negative results, plus how to fix each.
Read more
Fix: DKIM fails after forwarding
Forwarders and mailing lists break DKIM by changing the message body and headers, not the connection. Here is exactly what fails, what survives, where ARC helps, how to spot forwarding failures in your DMARC reports, and how to reduce the impact without parking at p=none.
Read more
Fix: DKIM public key not found in DNS
The "DKIM public key not found in DNS" error is almost always a naming or publishing problem, not a broken key. Here is exactly which name receivers query, why it returns nothing, how CNAME and TXT publishing differ, and how to confirm the key resolves end to end.
Read more
Fix: DKIM signature did not verify
"DKIM signature did not verify" is at least six different problems wearing one error string: body hash mismatch, no key in DNS, malformed record, key mismatch after rotation, expired signature, or a key too short. Here is how to read the exact reason in the brackets and apply the one correct fix for each.
Read more
Fix: MTA-STS policy not found
"MTA-STS policy not found" is never one problem: it is a five-link chain (DNS TXT, HTTPS host, certificate, file path, file content) plus the MX-coverage trap, and it fails silently because senders fall back to opportunistic TLS rather than bounce. Walk the discovery the way a sending MTA does, with real dig, curl and openssl checks, and fix the first broken link.
Read more
Fix: multiple DMARC records
Two TXT records at _dmarc do not make DMARC stricter; they switch it off entirely, silently. Here is why RFC 7489 mandates that, the exact ways duplicates sneak into a zone, how to detect them and how to consolidate down to one correct record without losing your settings.
Read more
Fix: multiple SPF records
Two SPF records on one domain force a permanent PermError that silently strips a DMARC route. Here is why it happens, how receivers treat it, and how to merge two records into one compliant record without losing a sender or blowing the 10-lookup limit.
Read more
Fix: SPF TempError
An SPF TempError is a transient DNS failure, not a broken record. Here is what it means, why it differs from PermError, how Google, Yahoo and Microsoft treat it under SPF and DMARC, and the concrete steps that make your SPF resolution reliable.
Read more
Fix: SPF too many DNS lookups
SPF caps you at ten DNS-querying mechanisms, counted after every include expands into its provider's nested netblocks, which is why a record with five includes can spend fifteen lookups and PermError. Here is how to count the budget, prune the includes that overspend it, and flatten or consolidate back under the limit before enforcement makes the failure bite.
Read more
Free checkers vs paid DMARC platforms
Free DMARC checkers read the current state of your DNS in one lookup, and they do that job completely. Enforcement is different: getting a domain from p=none to p=reject without dropping legitimate mail is a multi-week process driven by the continuous aggregate-report stream, which no one-shot tool can ever surface. This guide draws the exact line between what free checkers do well, where they structurally stop, and what a managed platform adds, plus an honest account of who needs the paid side and who does not.
Read more
GDPR and DMARC reporting
DMARC reports can contain personal data: source IPs in aggregate reports, and recipients, subjects and message bodies in forensic reports. Here is which fields the UK and EU GDPR catch, why forensic (ruf) reporting is the real hazard most domains should drop, and the lawful basis, retention and transfer practices that keep aggregate (rua) collection compliant.
Read more
Getting a trademark for a BIMI VMC
A Verified Mark Certificate will not issue without a registered figurative trademark for your logo. Here is why that prerequisite exists, the real registration timeline and cost, and the CMC route for organisations that have no trademark.
Read more