
Stay ahead of email threats
Get our latest DMARC, SPF, and email-security guides in your inbox. No spam — unsubscribe anytime.
We only use your email to send blog updates. One click unsubscribes you.


p=none: the DMARC policy that looks compliant and stops nothing
Everyone agrees a domain with no DMARC record is dangerous. We think the more dangerous domain is the one at p=none: it passes the paperwork, and it still lets every forgery through — including into its own inboxes. Here is why, in plain language, and how long you should stay there.

You armoured the door — and let in anyone who says the right name
You published DMARC. Nobody can forge your domain — including to attack your own people internally. But almost none of that protects the mail that arrives in someone else's name: your suppliers, your accountant, your bank. Here is the blind spot in every email-security budget, and the three things that close it.

Your email passes DMARC — until something auto-forwards it
Your authentication tests clean, then a customer auto-forwards a message and it fails. That is not a bug, and it is not random. One half of your authentication cannot survive a new hop, and the other half survives only under a condition nobody tells you about.
















