dmarc
9 posts
- 01dmarc5 min read
Forwarders & Mailing Lists: ARC, and Why Legitimate Mail Fails DMARC
Forwarding and mailing lists break SPF and sometimes DKIM, so your own mail can fail DMARC. What's happening, what ARC does about it, and why it's usually safe to enforce through.
- 02dmarc5 min read
Third-Party Senders: Getting DMARC Alignment Right for Mailchimp, SendGrid & HubSpot
Your ESP authenticates your mail — so why does DMARC fail? Because 'authenticated' and 'aligned to your domain' aren't the same. How to fix alignment for Mailchimp, SendGrid & HubSpot.
- 03compliance6 min read
DMARC for Healthcare: HIPAA, Email Security, and What Auditors Actually Check
HIPAA doesn't name DMARC, but auditors increasingly expect enforced email authentication for ePHI. How DMARC maps to the Security Rule, and how to roll it out in a clinic.
- 04deliverability5 min read
DMARC Passes but Email Still Lands in Spam
Passing SPF, DKIM and DMARC is the entry ticket to the inbox, not a guarantee. Why aligned mail still gets filtered, and how to find the real cause.
- 05dmarc5 min read
How to Set Up SPF, DKIM & DMARC for Microsoft 365
The exact SPF record, the two DKIM CNAMEs and the DMARC record Microsoft 365 needs, plus the Defender step that actually turns DKIM signing on.
- 06dmarc6 min read
SPF, DKIM & DMARC Setup for Google Workspace
The exact SPF, DKIM and DMARC records Google Workspace needs, in the right order, plus the gotchas that quietly break authentication.
- 07dmarc6 min read
Subdomain DMARC: Why the sp= Tag Matters
Does p=reject cover your subdomains? Usually, but one tag can silently undo it. How policy inheritance works and how to lock down dormant subdomains.
- 08dmarc4 min read
Reading DMARC Aggregate Reports: the XML
Aggregate reports show who is sending as your domain. How to read the XML, what each field means, and how to tell spoofing from a broken forwarder.
- 09dmarc6 min read
DMARC Rollout Playbook: p=none to p=reject
Moving from p=none to p=reject is where most DMARC projects stall. A staged, evidence-driven path to enforcement that won't block legitimate mail.