Plain-language guides to DMARC and the standards around it — written to be accurate first and short second. No jargon walls, no scare tactics.
Five articles, in order. About twenty minutes end to end, after which your DMARC reports will read as information rather than XML.
The control layer: policy, alignment, and the reports that name everyone sending as your domain.
5 min 2The DNS record listing your authorized servers — its syntax, the 10-lookup limit, and where it falls short.
4 min 3Signatures that survive forwarding: selectors, keys, and why DKIM is DMARC's sturdier input.
3 min 4What each policy does, what sp and np mean, and the staged playbook for enforcing without losing real mail.
4 min 5Every tag explained, three copy-paste records (none, quarantine, reject), and the exact DNS steps to publish one.
3 minWhat the daily XML actually contains, and how to tell a forwarding gateway from someone spoofing you.
The XML files Google and Microsoft send you daily: what's inside, what isn't, and how to turn them into decisions.
3 minTwo red badges have three very different causes — forwarding, a vendor nobody aligned, or actual spoofing. How to tell them apart in a minute.
4 minHow to tell a spoofing VPS from a vendor nobody configured, using the evidence the IP itself carries.
6 minThreat feeds report IPs the blocklists themselves don’t list. What the annotation means, and why your own DKIM key outranks any reputation feed.
4 minThe gap between "SPF and DKIM pass" and "DMARC passes" is alignment, and it is where almost every rollout stalls. Then there's keeping it that way.
Why Mailchimp or SendGrid mail can pass SPF and DKIM yet fail DMARC — and the two settings that fix it.
3 minCampaigns pass SPF and DKIM but fail DMARC until you authenticate your domain. Setting up custom DKIM, step by step.
5 minThree records in your own DNS make mail sent through Zoho verifiably yours — exact values, step by step.
3 minWix doesn't host your email — your SPF and DKIM live with your provider. DMARC is the record you own, and here's how to publish it.
3 minWhy Email Campaigns no longer needs an SPF record — and how DKIM plus your own DMARC record is what actually protects you.
3 minHow forwarded mail and mailing lists survive strict DMARC — and why you don't need to publish anything for it.
3 minSPF edits, lost DKIM keys, softened policies — why authentication decays after rollout and how to catch it in a day.
4 minEverything above assumes the domain is yours. When it's a client's, the hard parts move: DNS access you don't own, thirty sender inventories, and a conversation about who pays for it.
What changes between one domain and thirty — DNS access, sender inventories, drift — and what's worth systematizing before domain four.
6 minThe repeatable per-client playbook: audit, publish, inventory senders, align, tighten — with exit criteria for every stage.
4 minPackaging, pricing, the ninety-second pitch that closes in one meeting, and the objections you'll actually hear.
5 minThree things worth doing rather than reading.
Paste a domain, see its published record, what each tag does, and what it leaves open. No sign-up.
Free toolA 0–100 score built from the authentication signals spam filters weigh — DMARC policy, SPF, DKIM and MX — with the gaps named. No sign-up.
Choosing a toolAn honest, current comparison with DMARCLY, EasyDMARC, dmarcian and PowerDMARC — including where they beat us.