DMARC: Deciding What Happens When Email Authentication Fails

DMARC: Deciding What Happens When Email Authentication Fails

DMARC defines what happens when email authentication fails, turning SPF and DKIM results into clear policy decisions that protect domains from spoofing and abuse.

26/01/2026 · 5 min · 932 words
DKIM: Proving a Message Wasn’t Changed — Not Who Sent It

DKIM: Proving a Message Wasn’t Changed — Not Who Sent It

DKIM (DomainKeys Identified Mail) doesn’t verify who sent an email. It verifies that the message hasn’t been altered since it was signed, and that a domain takes responsibility for its contents. Understanding DKIM means understanding what it proves — and what it deliberately ignores.

26/01/2026 · 6 min · 1213 words
SPF: What It Really Proves — and Why It Fails So Often

SPF: What It Really Proves — and Why It Fails So Often

SPF doesn’t verify who sent an email — it only confirms that a server was allowed to deliver it. That distinction explains why SPF passes during phishing, fails during forwarding, and can’t be treated as a trust signal on its own.

26/01/2026 · 6 min · 1189 words
Spamhaus, Spam, and the Shape of Modern Email Filtering

Spamhaus, Spam, and the Shape of Modern Email Filtering

Spam didn’t disappear — it was pushed out of sight. Reputation systems like Spamhaus reshaped email abuse at internet scale, trading noisy volume for quieter, more dangerous attacks. This is the infrastructure that keeps email usable — and the compromises it relies on.

26/01/2026 · 8 min · 1540 words
SPF, DKIM, and DMARC: How Email Authentication Actually Works

SPF, DKIM, and DMARC: How Email Authentication Actually Works

Email authentication relies on SPF, DKIM, and DMARC — a set of interlocking systems — but most people misunderstand what they really do, and what they don’t protect.

25/01/2026 · 11 min · 2294 words