Articles tagged Email Security

Our blog shares expert insights on email security, DMARC configuration, and deliverability optimization.

RFC 9989, 9990, and 9991 are published: what changed for DMARC
email-security ·

RFC 9989, 9990, and 9991 are published: what changed for DMARC

DMARC is now an IETF Standards Track protocol. RFC 9989, 9990, and 9991 replace RFC 7489 from 2015. Records still start with v=DMARC1, so most production deployments need nothing immediate. But the spec has real changes: new tags, the Public Suffix List is out, the p=reject guidance has flipped, and aggregate reports gained fields. Here is what changed and what to do about it.

DT
DMARCTrust
15 min read
Phishing vs spear phishing: what changes when attacks get targeted
email-security ·

Phishing vs spear phishing: what changes when attacks get targeted

Phishing is broad impersonation. Spear phishing is targeted impersonation built around a specific person, role, vendor, or business process. Learn the difference, how executive phishing fits in, and where DMARC helps.

DT
DMARCTrust
10 min read
What is angler phishing? Fake customer support scams explained
email-security ·

What is angler phishing? Fake customer support scams explained

Angler phishing is a social-media scam where fake support accounts target people who publicly ask brands for help. Learn how it works, how to verify support accounts, and how baiting and pharming differ.

DT
DMARCTrust
9 min read
MTA-STS not working? Fix the 7 errors senders report
email-security ·

MTA-STS not working? Fix the 7 errors senders report

MTA-STS breaks when DNS, HTTPS policy hosting, and MX TLS drift out of sync. This troubleshooting guide covers seven failures, the records to check first, and the commands that expose them.

DT
DMARCTrust
14 min read
From p=none to p=reject: how to enable DMARC enforcement in 2026
dmarc-setup ·

From p=none to p=reject: how to enable DMARC enforcement in 2026

Forums show the same anxiety pattern: 'I want p=reject, but I'm afraid I'll block legit mail.' The rollout is mostly about gates: inventory done, alignment fixed, SPF lookup limit avoided, and then staged enforcement.

DT
DMARCTrust
8 min read
VMC vs CMC certificates: BIMI cost and requirements (2026)
email-deliverability ·

VMC vs CMC certificates: BIMI cost and requirements (2026)

A practical buyer's guide to VMC and CMC certificates for BIMI in 2026. Covers trademark vs prior-use paths, current prices, authorized issuers, and the Gmail checkmark distinction.

DT
DMARCTrust
8 min read
Who is sending mail as us? The Shadow IT sender inventory problem
dmarc-monitoring ·

Who is sending mail as us? The Shadow IT sender inventory problem

The biggest practical blocker to moving beyond p=none isn't DNS syntax. It's discovering every legitimate sender. DMARC reports expose these "unknown senders" and Shadow IT that you didn't even know existed.

DT
DMARCTrust
4 min read

Need expert help with email deliverability?

Hire an email deliverability consultant who has shipped billions of emails. Free assessment, hands-on engagement, written quote before any work starts.