
Reviewing and revoking AI app connections to your mailbox
A runbook for the life of an AI app connected to your email: how OAuth grants work, a quarterly review, when to revoke, what revoking does, admin off switches.
5 min read

A runbook for the life of an AI app connected to your email: how OAuth grants work, a quarterly review, when to revoke, what revoking does, admin off switches.
5 min read

An attacker can send from any free mailbox with your CEO's name in the display field. Why authentication cannot stop it and what actually helps.
4 min read

QR codes hide malicious URLs inside images, out of reach of many link scanners. How quishing works, why it evades filters and what defenses help.
4 min read

An admin playbook for AI email agents: inherit user mailbox access, keep a workspace off switch, cut access on removal, scope by task, wall off sensitive mail.
4 min read

Unused domains are easy spoofing targets. Publish a null MX, a deny-all SPF record and a reject DMARC policy so nobody can send mail as them.
4 min read

Typo and homoglyph domains pass authentication for themselves. Monitor new registrations, register obvious variants and train people to check senders.
4 min read

Money-related email needs precise copy, consistent senders and records you can find later. Operational habits for fintech startups, from notices to phishing.
5 min read

Koltrix runs on its own servers on OVHcloud in Frankfurt. Where your mail, attachments and AI requests go, who else touches them, and what we don't have yet.
5 min read

A runbook for giving freelancers and agencies access to team email: own accounts, only the mailboxes they need, 2FA, an end date and a clean offboarding.
4 min read

A new hire's email setup takes under an hour with a checklist: address, 2FA, shared mailbox access, signature, aliases and the rules of the road.
4 min read

A support runbook for email requests to change an owner address, disable 2FA or transfer an account: why email alone is weak proof and how to verify safely.
4 min read

A selector-based DKIM rotation plan: publish the new key, switch signing, keep the old key long enough, then revoke it with an empty p= tag.
4 min read