Blog
News, tips and insights about email security.
BEC Calibration: Why $49,225 Is No Coincidence
The number that only makes sense on second glance $49,225. At first read, it looks like an odd invoice total or a project flat fee. That is exactly the point.
Read more
Microsoft 365 AiTM Phishing: Why Passing DMARC Doesn't Mean You're Safe
A green auth check – and still phishing SPF: Pass. DKIM: Pass. DMARC: Pass. For many IT admins, that combination means one thing: the email is legitimate.
Read more
Phishing via Dormant Mailchimp Accounts: How Offboarding Gaps Break DMARC Trust
The incident: a phishing email that passed every check An IT security team reports a phishing email to the abuse desk.
Read more
DMARC Enforcement Without Preparation: Why Jumping from p=none to p=reject Fails
The scenario: two admins, one domain, no plan An IT consultant gets a straightforward-sounding assignment: two M365 admins need to move their company domain's…
Read more
Phishing Volume Down 20% – Why the Risk Is Actually Growing
Fewer phishing emails, more damage – how does that add up? The headline sounds like good news: global phishing volume has dropped by roughly 20%.
Read more
ARC Is Being Retired: What It Means for Email Authentication and Mailing Lists
What Is ARC — and Why Did We Need It? Anyone running DMARC knows the forwarding problem. An email travels through a mailing list or a forwarding service, and…
Read more
ARC and Mailing List Noise: Why DMARC Breaks on Forwarding – and How RFC 8617 Fixes It
The Problem: DMARC Breaks on Mailing Lists You've set up DMARC properly. SPF and DKIM are aligned, your policy is p=reject .
Read more
Microsoft Tightens Email Authentication: DMARC Enforcement from May 2025 – What IT Admins Need to Know Now
Microsoft joins the enforcement club As of May 2025, Microsoft has introduced mandatory email authentication requirements for messages delivered to…
Read more
Sender Inventory as Production Infrastructure: Why Companies Must Register Every Email Sender
Email sending is production infrastructure — and it's still treated like a side project Imagine a developer deploying a new microservice without a ticket,…
Read more
CVE-2026-42897: Exchange Flaw Enables Email Spoofing via XSS – What DMARC Can and Cannot Do
A new Exchange vulnerability is being actively exploited Microsoft has confirmed a critical vulnerability in Exchange Server: CVE-2026-42897 allows attackers…
Read more