
How email spoofing works and which records stop it
SMTP lets anyone claim any From address. Follow a spoofed message through a receiver and see exactly where SPF, DKIM and DMARC stop it, and where not.
5 min read

SMTP lets anyone claim any From address. Follow a spoofed message through a receiver and see exactly where SPF, DKIM and DMARC stop it, and where not.
5 min read

A timed checklist to audit SPF, DKIM, DMARC and transport security on any domain, with the commands to run and what a passing answer looks like.
4 min read

Relaxed alignment accepts subdomains, strict demands an exact match. See how each mode evaluates real headers and when strict is worth the risk.
4 min read

Attackers love subdomains you never configured. How sp= and the new np= tag cover them, how policy discovery works, and when to publish per-subdomain records.
4 min read

The Authentication-Results header records the SPF, DKIM and DMARC verdicts a receiver reached. Decode each field and use it to debug failures fast.
5 min read