Guides
Last updated 28 Sep 2026
DMARC setup, start to finish
Every step from no record to p=reject, with the numbers I use to decide when each step is safe and what to do when a sender will not align.
Move to p=reject without losing mail
Six checks to run against your reports before you tighten DMARC, the one-word change for each step, and how to move back fast when a step catches real mail.
How to read a DMARC aggregate report
Open the XML, find the sources that matter, and tell forwarding apart from a misconfigured vendor. A field-by-field walkthrough of a real report.
SPF's 10-lookup limit and how to get under it
Why SPF caps DNS lookups at ten, what each mechanism costs, and the four ways to get back under the limit ranked by how much maintenance they leave you.
DMARC alignment, explained
Three domains are involved in every message and DMARC only cares that two match. Relaxed against strict, and why forwarding breaks SPF.
What is DMARC
What a DMARC record is, why you publish it at p=none first, and how p=reject stops forged mail that uses your exact domain.
SPF record syntax, term by term
Every SPF record term checked against RFC 7208: qualifiers, mechanisms, modifiers and macros, each with a valid example record and the lookup it costs.
Why a domain can only have one SPF record
Two v=spf1 records on the same name is a permerror, and permerror fails every sender in both. How to tell if you have two, and how to merge them into one.
How many includes one SPF record can hold
Nothing caps how many include: terms an SPF record holds. The 10 DNS lookups they spend between them is the cap, and your record does not show that number.
Hard bounce vs soft bounce: what each one is telling you
A hard bounce is a 5xx refusal, a soft bounce is a 4xx retry. Which codes mean the address is gone, which mean your authentication is broken, and how to tell.
How to check your domain reputation, receiver by receiver
There is no single domain reputation score. Gmail, Microsoft and the blocklists each keep their own. How to check each one, starting with Postmaster Tools.
Spamhaus delisting: find the list, fix the cause, ask once
Spamhaus runs five lists and each has its own removal path. Read the return code to see which one has you, fix the cause, then request removal once.
Barracuda delisting: check the IP, fix the cause, file once
Barracuda lists IPs, not domains, from spam traps and its own appliances. How to check the list, what the form asks, and why a second request is ignored.
SPF, DKIM and DMARC: three records, one decision
SPF lists your servers, DKIM signs your mail, and DMARC is the only one that tells a receiver what to do. How the three fit, and where alignment comes in.
Email spoofing: how a forged From works, and what stops it
The From address on an email is text the sender types. How spoofing works, why the reader can't tell, what DMARC at p=reject stops, and what it doesn't.
DKIM fail: find the cause before you change DNS
Fix DKIM failures using the email's headers. Check signing, selectors, DNS keys and changed messages, even when a DKIM checker says the record is valid.
NCSC Mail Check is retired: move your DMARC reports
Mail Check stopped DMARC reporting in March 2025 and closed in March 2026. Check your rua address, choose a free report reader and change that tag only.
Direct Send spoofing: block it in Microsoft 365, then fix DMARC
Attackers use Direct Send to mail Microsoft 365 users as their own domain. Turn on Reject Direct Send, add connectors, and move DMARC off p=none.
Emails going to spam: find the cause, receiver by receiver
Why your emails go to spam at Gmail, Outlook and Yahoo even when SPF, DKIM and DMARC pass. Check complaints, consent, reputation and content, in that order.
SPF softfail: what it means, and when to change ~all
spf=softfail means the sending server isn't in your SPF record and the record ends in ~all. What receivers do with it, what DMARC does, and which fix applies.
Elsewhere on the site
Bounce and error codes
The literal string from your log, and what to change.
SPF and DKIM by provider
The records each platform needs, and where alignment breaks.
Or check a domain right now with the free DMARC, SPF and DKIM lookups.
What these guides depend on
Every policy step in these guides depends on reading the aggregate reports. We parse them and mail you a weekly summary. Paid plans email you the day a new source first fails. The first domain is free.
Get the weekly digestFree for your first domain · No card · Per-source totals kept for life