Practical insights on email deliverability, security, and infrastructure — based on real findings from working with 450+ organizations.
Email Deliverability
January 16, 2026
Explanation of why Gmail blocks sending during CRM batch emails and what's actually causing it.
Email Security
January 13, 2026
How DMARC forensics exposed an API key leak, 2.3M unauthorized emails, and a $10K bill.
January 8, 2026
Attackers use backscatter emails to bypass filters, harming servers and delivering phishing content.
December 29, 2025
Microsoft 365 groups can deliver spoofed emails despite failing SPF, DKIM, and enforced DMARC policies.
December 25, 2025
Proper DMARC enforcement on the root domain protects non-existent subdomains without needing separate policies.
December 1, 2025
New domain emvdmarc[.]com receives DMARC reports from random organizations, creating unexpected security concerns.
November 12, 2025
Implementing DMARC p=reject stops spoofing but often clashes with business workflows and new systems.
Architectural flaws in SaaS platforms allow phishing campaigns through trusted email infrastructure.
November 6, 2025
Neglected DMARC reporting addresses can leak internal email infrastructure and sensitive organizational information.
October 17, 2025
Removal limits visibility into ESP/CRM health, making it harder to monitor email deliverability risks.
October 15, 2025
Including Mailchimp IPs in root SPF unnecessarily exposes domains to spoofing despite strict DMARC policies.
Google Postmaster v1 is ending, reducing visibility into domain/IP reputation for email deliverability.