
Locking down domains that never send email
Unused domains are easy spoofing targets. Publish a null MX, a deny-all SPF record and a reject DMARC policy so nobody can send mail as them.
4 min read

Unused domains are easy spoofing targets. Publish a null MX, a deny-all SPF record and a reject DMARC policy so nobody can send mail as them.
4 min read

Publishing a second SPF TXT record makes every check a permerror. How it happens, how to detect it with dig, and how to merge records safely.
4 min read

Three DNS records decide whether your email arrives. What each one actually does, what to publish, and the four mistakes that cause most of the support tickets.
4 min read

Running a workspace mailbox provider and a transactional sender on the same domain? Combine SPF, give each its own DKIM selector, and align DMARC.
5 min read

A reference table of the DNS records a domain that sends email should have: MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI, with syntax for each.
4 min read

Flattening replaces includes with IP ranges to dodge the lookup limit. Here is how it works, why it rots, and safer alternatives like subdomains.
5 min read

Softfail or hard fail? How receivers treat ~all and -all today, why DMARC changed the calculus, and which ending to pick for each kind of domain.
4 min read

Which SPF mechanisms count toward the 10-lookup limit, how to audit your record by hand, and the safe ways to trim includes before you hit permerror.
5 min read

Most email migrations break something nobody listed: a CRM, a form, a scanner. How to find every service that sends as your domain before you change DNS.
4 min read

A timed checklist to audit SPF, DKIM, DMARC and transport security on any domain, with the commands to run and what a passing answer looks like.
4 min read

Relaxed alignment accepts subdomains, strict demands an exact match. See how each mode evaluates real headers and when strict is worth the risk.
4 min read