Field notes on email security.
What's changing in DMARC and deliverability, how operators are responding, and how to read your reports — written for the people who actually run email.
- 01msp5 min read
DMARC at Scale: A Playbook for MSPs Managing 50+ Client Domains
Running DMARC across 50, 100, or 1,000 client domains is a process, not a project. A repeatable per-client SOP, multi-tenant monitoring, and how to package it as recurring MSP revenue.
- 02deliverability4 min read
The 0.3% Spam Rate: How to Monitor and Stay Under Google's Threshold
Google requires bulk senders to keep their user-reported spam rate under 0.3% — and really under 0.1%. Where the number comes from, how to watch it in Postmaster Tools, and what to do when it climbs.
- 03dmarc5 min read
Forwarders & Mailing Lists: ARC, and Why Legitimate Mail Fails DMARC
Forwarding and mailing lists break SPF and sometimes DKIM, so your own mail can fail DMARC. What's happening, what ARC does about it, and why it's usually safe to enforce through.
- 04security4 min read
Lookalike Domains & BEC: Why DMARC on Your Real Domain Isn't the Whole Story
DMARC stops attackers forging your exact domain — not one that looks like it. How lookalike domains and display-name tricks drive business email compromise, and how to defend the gap.
- 05dmarc5 min read
Third-Party Senders: Getting DMARC Alignment Right for Mailchimp, SendGrid & HubSpot
Your ESP authenticates your mail — so why does DMARC fail? Because 'authenticated' and 'aligned to your domain' aren't the same. How to fix alignment for Mailchimp, SendGrid & HubSpot.
- 06compliance6 min read
DMARC for Healthcare: HIPAA, Email Security, and What Auditors Actually Check
HIPAA doesn't name DMARC, but auditors increasingly expect enforced email authentication for ePHI. How DMARC maps to the Security Rule, and how to roll it out in a clinic.
- 07deliverability5 min read
DMARC Passes but Email Still Lands in Spam
Passing SPF, DKIM and DMARC is the entry ticket to the inbox, not a guarantee. Why aligned mail still gets filtered, and how to find the real cause.
- 08dmarc5 min read
How to Set Up SPF, DKIM & DMARC for Microsoft 365
The exact SPF record, the two DKIM CNAMEs and the DMARC record Microsoft 365 needs, plus the Defender step that actually turns DKIM signing on.
- 09security6 min read
Anatomy of a Domain Spoofing Attack
A spoofed email is just a forged From: header. How the attack is staged, what the target sees, and exactly how it surfaces in your DMARC reports.
- 10dmarc6 min read
SPF, DKIM & DMARC Setup for Google Workspace
The exact SPF, DKIM and DMARC records Google Workspace needs, in the right order, plus the gotchas that quietly break authentication.
- 11dmarc6 min read
Subdomain DMARC: Why the sp= Tag Matters
Does p=reject cover your subdomains? Usually, but one tag can silently undo it. How policy inheritance works and how to lock down dormant subdomains.
- 12deliverability5 min read
Microsoft 365 Sender Requirements Enforced
Microsoft now requires SPF, DKIM and an aligned DMARC record for bulk mail to Outlook.com. Who's affected and how it compares to Google and Yahoo's rules.
- 13dmarc4 min read
Reading DMARC Aggregate Reports: the XML
Aggregate reports show who is sending as your domain. How to read the XML, what each field means, and how to tell spoofing from a broken forwarder.
- 14dmarc6 min read
DMARC Rollout Playbook: p=none to p=reject
Moving from p=none to p=reject is where most DMARC projects stall. A staged, evidence-driven path to enforcement that won't block legitimate mail.
- 15deliverability4 min read
Google & Yahoo Sender Requirements 2026
The 2026 Yahoo & Google bulk-sender rules — SPF, DKIM, DMARC alignment, one-click unsubscribe, and the 0.3% spam-rate limit — in one checklist to confirm you comply.