Skip to main content

Writing

Articles

Clear, honest writing on DMARC, email authentication, and getting to enforcement without breaking your mail.

Analysis

Three Common Misconfigurations in DMARC, BIMI, and SPF Records

Three domains we checked have DMARC, BIMI, or SPF records that are syntactically correct and functionally inert: a BIMI logo that cannot render, a DMARC tag the current spec removed, and an SPF record that authenticates nothing.

2 Sep 2026 · 9 min read

Research

Nearly One Third of p=none DMARC Records Contain Only Two Tags

Nearly one third of the p=none DMARC records we checked contained only the version and policy tags. That can satisfy the DMARC part of a mailbox-provider rule, but it asks for none of the reports that make p=none useful.

25 Aug 2026 · 6 min read

Reference

DMARC Alignment Explained: SPF, DKIM, Relaxed vs Strict, and Every Setting

SPF and DKIM each produce an authentication result and an alignment result, independently, and every tag in the DMARC record bends the outcome. The full authentication times alignment matrix, relaxed vs strict mode, plus a tag-by-tag reference for p, sp, adkim, aspf, pct, rua, ruf, fo and the SPF qualifier.

11 Aug 2026 · 13 min read

Insight

One Email, Three Identities: SPF, DKIM and DMARC Explained

A single email carries a visible From address, a hidden envelope sender, a DKIM signing domain and a sending IP, and nothing requires them to match. One constructed message, traced field by field, showing exactly how DMARC decides a pass from identities that can legitimately disagree.

10 Aug 2026 · 8 min read

Insight

What DMARC Actually Protects You From, and What It Does Not

DMARC verifies that a domain owner authorised an email. It does not verify that the email is safe. A precise look at exact-domain spoofing, lookalikes, display-name impersonation, compromised mailboxes, and why authentication is not the same as trust.

31 Jul 2026 · 8 min read