Also by us:LastSpamReporter

Stay ahead of email threats

Get our latest DMARC, SPF, and email-security guides in your inbox. No spam — unsubscribe anytime.

We only use your email to send blog updates. One click unsubscribes you.

The authenticated swarm

The authenticated swarm

One phishing operator, ninety days: 342 registered domains wearing 18,749 different faces, and 90% of it passed SPF, DKIM and DMARC. Authentication stopped being proof of good intent — here is what that looks like in real mail flow.
p=none: the DMARC policy that looks compliant and stops nothing

p=none: the DMARC policy that looks compliant and stops nothing

Everyone agrees a domain with no DMARC record is dangerous. We think the more dangerous domain is the one at p=none: it passes the paperwork, and it still lets every forgery through — including into its own inboxes. Here is why, in plain language, and how long you should stay there.
You armoured the door — and let in anyone who says the right name

You armoured the door — and let in anyone who says the right name

You published DMARC. Nobody can forge your domain — including to attack your own people internally. But almost none of that protects the mail that arrives in someone else's name: your suppliers, your accountant, your bank. Here is the blind spot in every email-security budget, and the three things that close it.
Your email passes DMARC — until something auto-forwards it

Your email passes DMARC — until something auto-forwards it

Your authentication tests clean, then a customer auto-forwards a message and it fails. That is not a bug, and it is not random. One half of your authentication cannot survive a new hop, and the other half survives only under a condition nobody tells you about.
What actually sends email as your domain?

What actually sends email as your domain?

Most small businesses cannot answer that question — and it is the one that decides whether their invoices arrive. Here is a way to find out, tool by tool, without hiring anyone.
The New DMARC Standard Is Here. Most Domains Need to Change Nothing.

The New DMARC Standard Is Here. Most Domains Need to Change Nothing.

DMARC was rewritten in May 2026, and you have probably received a few worried emails about it. Here is the honest list — one thing worth checking today, one worth adding, and five you can ignore.
72% of Quebec Organizations Don't Block Email Impersonation

72% of Quebec Organizations Don't Block Email Impersonation

We checked the public DNS records of 296 Quebec organizations across 9 sectors. Only 28% actually block someone from sending email in their name — and the reason why is not what we expected.
We Mapped Where Spoofed Email Actually Comes From

We Mapped Where Spoofed Email Actually Comes From

We published a live map of where forged email originates, updated hourly. The results are not what most people expect — and one of the two views should worry you.
DMARCbis is official: what the new DMARC means for your domain

DMARCbis is official: what the new DMARC means for your domain

DMARCbis was published in May 2026 as RFC 9989. Here's what changed — the new np tag, the DNS Tree Walk, the removal of pct — and whether you need to do anything.
Google tightens Gmail filters this month! November 2025

Google tightens Gmail filters this month! November 2025

Google tightens Gmail filters this month! November 2025
Introducing “Insights”: A New Way to Understand Your Delivery Performance

Introducing “Insights”: A New Way to Understand Your Delivery Performance

Introducing “Insights”: A New Way to Understand Your Delivery Performance
Risks Associated with Microsoft Direct Send

Risks Associated with Microsoft Direct Send

Risks Associated with Microsoft Direct Send
Your Digital Footprint: A Hidden Gateway to Hacking and Spam

Your Digital Footprint: A Hidden Gateway to Hacking and Spam

Your Digital Footprint: A Hidden Gateway to Hacking and Spam
Why DMARC Monitoring is important

Why DMARC Monitoring is important

Monitoring your email flow using DMARC Reporting is essential for maintaining domain security, protecting your reputation, and improving email deliverability.
Can Your Domain Be Spoofed? Most Can!

Can Your Domain Be Spoofed? Most Can!

To this day, most internet domain can be spoofed and we'll explain why
About DMARCGUY eMails compliance monitoring service

About DMARCGUY eMails compliance monitoring service

DMARCGUY has rigorously evaluated numerous DMARC monitoring tools and selected URIports, widely regarded as one of the top solutions on the market.
Microsoft's New Requirements for Bulk Senders, Effective May 5, 2025

Microsoft's New Requirements for Bulk Senders, Effective May 5, 2025

It has now become essential to properly configure your email system.
Would you hand a loaded gun to a stranger without asking what they’ll do with it?

Would you hand a loaded gun to a stranger without asking what they’ll do with it?

Contact an email security expert to lock down your DMARC and stop spoofing for good.
About this site & Why DMARC GUY

About this site & Why DMARC GUY

What led to the creation of DMARC GUY
NSA warns of North Korean hackers exploiting weak DMARC email policies

NSA warns of North Korean hackers exploiting weak DMARC email policies

NSA warns of North Korean hackers exploiting weak DMARC email policies
US Says North Korean Hackers Exploiting Weak DMARC Settings

US Says North Korean Hackers Exploiting Weak DMARC Settings

US Says North Korean Hackers Exploiting Weak DMARC Settings