What Is DMARC?
How DMARC protects your domain from spoofing, and why every sender needs it.
SPF, DKIM & DMARC — How They Fit Together
The relationship between the three protocols and why you need all three.
The Enforcement Path
p=none → p=quarantine → p=reject. The safe rollout sequence, step by step.
Complete DMARC Implementation Checklist
Everything from inventorying your senders to publishing p=reject — with a phase-by-phase sequence and what to do at each step.
Why Your DMARC Reports Show Failures
The most common causes of DMARC failures and how to diagnose each one using aggregate reports.
How SPF Works
What an SPF record does, how receivers check it, and what happens when it fails.
SPF Record Syntax Reference
v=spf1, include:, ip4:, -all, ~all — every mechanism and qualifier explained with examples.
Fixing the 10-Lookup Limit
Why SPF fails with PermError at 10 DNS lookups and how SPF flattening solves it.
How DKIM Works
Public/private key signing, DNS records, and why DKIM survives email forwarding when SPF doesn't.
Setting Up DKIM for Common ESPs
Step-by-step for Google Workspace, Microsoft 365, SendGrid, Mailchimp, and Mailgun.
1024-bit vs 2048-bit DKIM Keys
Why 1024-bit keys are no longer recommended and how to rotate to a stronger key without downtime.
DMARC Alignment Explained
DMARC checks whether the authenticated domain matches the visible From address. Here's what that means in practice.
Reading DMARC Aggregate Reports
How to interpret the XML, what each field means, and what to act on first.
Common DMARC Mistakes
Starting at p=reject too soon, missing third-party senders, duplicate SPF records, and more.
DMARC for Non-Sending Domains
Domains that never send email are still a spoofing target. How to lock them down in minutes.
BIMI Setup Guide
Show your logo in Gmail and Apple Mail by pairing a DMARC enforcement policy with BIMI.
MTA-STS: Enforcing Encrypted Delivery
Require TLS for inbound mail to your domain. How MTA-STS policies work and how to publish one.