
Offboarding a teammate from shared email safely
A runbook for removing a departing teammate from shared email: access, connected apps and AI tokens, owned threads, forwarding rules and their old address.
4 min read

A runbook for removing a departing teammate from shared email: access, connected apps and AI tokens, owned threads, forwarding rules and their old address.
4 min read

Before you move company email to a new vendor, ask where the data lives, who processes it, and how you get it back out. A question list, with our own answers.
4 min read

Which headers to sign, why signing From twice blocks header injection, and how the l= body length tag lets attackers append content to signed mail.
5 min read

An email API key is the power to send as your domain. Scope keys narrowly, store them safely, rotate them on a schedule and respond fast to leaks.
4 min read

A checklist for keeping sensitive email away from AI tools: identify confidential categories, separate mailboxes, control connections and set a team policy.
4 min read

Stale CNAMEs and forgotten includes can let someone else send or host content on your domain. How takeovers happen and how to audit DNS for them.
5 min read

A runbook for enabling 2FA across a team's email accounts: announcing it, choosing apps, storing recovery codes, handling lost phones and verifying everyone.
4 min read

Never trust a webhook until you verify its signature over the raw body. HMAC verification in Node, Python and Go, plus timestamp and replay checks.
5 min read

A week-by-week DMARC rollout: monitor with p=none, fix every legitimate source, move to quarantine, then reject, with clear exit criteria per stage.
4 min read

A hijacked mailbox or leaked SMTP credential can burn your domain reputation in hours. The signals to watch and the containment steps to rehearse.
4 min read

Map roles to shared mailboxes with a permission matrix, apply least access, keep billing and legal mail narrow, and set a review cadence as your team grows.
4 min read

SMTP lets anyone claim any From address. Follow a spoofed message through a receiver and see exactly where SPF, DKIM and DMARC stop it, and where not.
5 min read