Blog
- Rolling out DMARC without breaking mail: none to reject
A practical timeline for moving from p=none to p=reject — what to check at each stage, and why skipping ahead is the most common way legitimate mail gets blocked.
- SPF's 10-lookup limit: the silent failure mode
SPF records that look fine can still fail outright once they exceed 10 DNS lookups — and nobody gets an error email when it happens.
- How to read a DMARC aggregate report
DMARC reports arrive as XML, not a dashboard. Here's what the fields actually mean and how to tell a pass from a real problem.