Writing
Articles
Clear, honest writing on DMARC, email authentication, and getting to enforcement without breaking your mail.
Three Common Misconfigurations in DMARC, BIMI, and SPF Records
Three domains we checked have DMARC, BIMI, or SPF records that are syntactically correct and functionally inert: a BIMI logo that cannot render, a DMARC tag the current spec removed, and an SPF record that authenticates nothing.
2 Sep 2026 · 9 min read
ResearchNearly One Third of p=none DMARC Records Contain Only Two Tags
Nearly one third of the p=none DMARC records we checked contained only the version and policy tags. That can satisfy the DMARC part of a mailbox-provider rule, but it asks for none of the reports that make p=none useful.
25 Aug 2026 · 6 min read
ReferenceDMARC Alignment Explained: SPF, DKIM, Relaxed vs Strict, and Every Setting
SPF and DKIM each produce an authentication result and an alignment result, independently, and every tag in the DMARC record bends the outcome. The full authentication times alignment matrix, relaxed vs strict mode, plus a tag-by-tag reference for p, sp, adkim, aspf, pct, rua, ruf, fo and the SPF qualifier.
11 Aug 2026 · 13 min read
InsightOne Email, Three Identities: SPF, DKIM and DMARC Explained
A single email carries a visible From address, a hidden envelope sender, a DKIM signing domain and a sending IP, and nothing requires them to match. One constructed message, traced field by field, showing exactly how DMARC decides a pass from identities that can legitimately disagree.
10 Aug 2026 · 8 min read
InsightWhat DMARC Actually Protects You From, and What It Does Not
DMARC verifies that a domain owner authorised an email. It does not verify that the email is safe. A precise look at exact-domain spoofing, lookalikes, display-name impersonation, compromised mailboxes, and why authentication is not the same as trust.
31 Jul 2026 · 8 min read