Email Authentication

Building an email and brand defense that works: Webinar recap

May 13, 20265 min read

DMARC is a good start, but it’s not the finish line. Learn more about the multifaceted nature of cyber attacks and what you can do to protect your brand in this webinar recap.

Read more
DMARC

59% of North Central U.S. organizations exposed to email spoofing

May 8, 202613 min readJack Lilley

Red Sift analyzed 1,000 North Central domains and found only 41% have full DMARC enforcement. See the state-by-state breakdown and how to close the gap.

Read more
DMARC

64% of U.S. Heartland organizations exposed to email spoofing

Apr 28, 202611 min read

Red Sift analyzed 900 Heartland domains and found only 36% have full DMARC enforcement. See the state-by-state breakdown and how to close the gap.

Read more
DMARC

Most businesses still can't answer one simple question about their email

Apr 23, 20267 min read

Just 2.5% of domains enforce DMARC at p=reject. Red Sift and Bespin Labs (Patronum) break down why email authentication stalls, and how to fix it before regulators and attackers force the issue.

Read more
DMARC

Only 40% of the Southwest's top organizations block spoofed email

Apr 17, 20269 min read

Red Sift analyzed 500 Southwest domains and found only 40% have full DMARC enforcement. See the state-by-state breakdown and how to close the gap.

Read more
DMARC

How to secure your brand with DMARC against email threats: Webinar recap

Apr 15, 20268 min read

AI-powered phishing attacks have surged. Learn how DMARC enforcement protects your brand from exact domain spoofing in this webinar recap.

Read more
DMARC

Only 44% of the Mid-Atlantic's top organizations block spoofed email

Apr 7, 20269 min read

Red Sift analyzed 700 Mid-Atlantic domains and found only 44% have full DMARC enforcement. See the state-by-state breakdown and how to close the gap.

Read more
DNS

NIST DNS update: What this means for your organization

Mar 25, 20265 min read

NIST SP 800-81 Revision 3 reframes DNS as an active security layer for the first time since 2013. Here's what changed and why it matters for DMARC, SPF, and DKIM.

Read more
DMARC

65% of the U.S. Northeast's top organizations are vulnerable to phishing

Mar 18, 20268 min read

An analysis of 700 domains across seven Northeast U.S. states found that only 35% have reached full DMARC enforcement, with significant variation between states and industries.

Read more
DMARC

50% of Boston's top organizations lack full DMARC protection

Feb 16, 20265 min read

Red Sift analyzed 99 domains from Boston's largest organizations and found nearly half (49.5%) haven't reached DMARC enforcement, leaving them open to spoofing and BEC.

Read more
DMARC

43% of Washington D.C.'s top organizations vulnerable to phishing

Feb 16, 20265 min read

Red Sift analyzed 100 domains from Washington D.C.'s largest organizations and found 43% lack DMARC enforcement — right where US cybersecurity policy is made.

Read more
DMARC

Over a quarter of New York's top organizations still exposed to email spoofing

Feb 16, 20265 min read

Red Sift analyzed 99 domains from New York's largest organizations. While 72.7% have reached DMARC enforcement, 27 domains remain exposed to email spoofing.

Read more
Email Security

Microsoft backs DMARC as protection against Tycoon 2FA phishing surge

Jan 8, 20266 min read

Attackers are using Tycoon 2FA kits to send phishing emails from misconfigured servers. Microsoft now recommends strict DMARC enforcement as the primary defense.

Read more
DMARC

52% of US insurance brokers remain vulnerable to email spoofing

Jan 5, 20264 min read

52% of the top 50 US insurance brokers have no effective DMARC protection, leaving them vulnerable to spoofing and phishing in an industry built on client trust.

Read more
DMARC

What is DMARC and how does it work effectively?

Dec 10, 20258 min read

DMARC protects domains from unauthorized email by aligning SPF and DKIM results with the visible From address. This guide covers how it works and how to deploy it effectively.

Read more
DNS

4 free tools for quick email security testing

Dec 1, 20254 min readJack Lilley

Four free tools from Red Sift to audit your email authentication in minutes: Investigate for DMARC, SPF Checker, BIMI Checker, and Blacklist Checker.

Read more
Email Security

DMARC, DKIM, SPF & BIMI: 5-minute playbook for Security and Marketing

Dec 1, 20253 min read

A quick-reference playbook for security and marketing teams covering SPF, DKIM, DMARC, and BIMI — what each does, why all four matter, and how to implement them.

Read more
DMARC

Finding the right DMARC monitoring tool: A practical guide for security teams

Dec 1, 20255 min read

A practical guide for choosing the right DMARC monitoring tool based on your organization's maturity — from basic reporting needs to full enterprise enforcement.

Read more
DMARC

SPF, DKIM, and DMARC: the three protocols protecting your inbox (and why you need all of them)

Dec 1, 20255 min read

SPF and DKIM alone can't prevent spoofing because they check different headers. This guide explains how DMARC ties them together to close the gap.

Read more
DMARC

How to simplify DMARC, SPF, and DKIM management

Dec 1, 20253 min read

Managing email authentication is complex — SPF lookup limits, DKIM key rotation, configuration drift. This post shows how OnDMARC simplifies the path to full enforcement.

Read more
DMARC

Best enterprise DMARC solution: Red Sift OnDMARC

Nov 27, 20255 min read

Red Sift OnDMARC unifies DMARC, SPF, DKIM, BIMI, and MTA-STS management in one platform, with the fastest enforcement timeline and dynamic DNS optimization for enterprise environments.

Read more
DMARC

Top platforms for enterprise DMARC enforcement: Technical comparison for Security Leaders

Nov 24, 20254 min read

A technical comparison of 7 enterprise DMARC platforms, evaluating automation, API integration, and time-to-enforcement. Red Sift OnDMARC leads with 6-8 week enforcement.

Read more
DMARC

Over 40% of essential services companies remain vulnerable to phishing

Nov 18, 20256 min read

Red Sift's analysis of 840 companies in chemical, energy, and water sectors found 42% lack DMARC protection, leaving critical infrastructure exposed to email threats.

Read more
Email Security

41% of top Fintech companies are vulnerable to email phishing

Nov 4, 20255 min read

Only 26% of leading Fintechs enforce DMARC at p=reject, leaving the majority exposed to spoofing and phishing attacks in a heavily targeted industry.

Read more
DMARC

49% of Big Pharma Companies Are Vulnerable to Email Phishing

Sep 22, 20253 min readRahul Powar

Nearly half of major pharmaceutical companies have no DMARC protection. Here's what Red Sift's research found and what the sector needs to do.

Read more
DMARC

74% of Credit Unions Are Spoofable: Is Yours on the List?

Aug 26, 20253 min readStuart Rogers

Red Sift research found almost three quarters of US credit unions have no domain protection. Find out if your organisation made the list.

Read more
DMARC

La Poste announces new email authentication requirements for all senders

Aug 22, 20253 min readJack Lilley

La Poste (laposte.net) has today announced significant changes to its email authentication requirements that will take effect in September 2025. These new requirements will fundamentally change how emails are processed and delivered to La Poste email addresses. What’s changing? Starting in September, La Poste will implement strict email authentication protocols that will affect all senders….Continue Reading: La Poste announces new email authentication requirements for all senders

Read more
DMARC

La Poste annonce de nouvelles exigences d’authentification des e-mails pour tous les expéditeurs

Aug 22, 20254 min readJack Lilley

La Poste (laposte.net) a annoncé aujourd’hui des changements importants à ses exigences d’authentification des e-mails qui entreront en vigueur en septembre 2025. Ces nouvelles exigences changeront fondamentalement la façon dont les e-mails sont traités et livrés aux adresses e-mail de La Poste. Qu’est-ce qui change ? À partir de septembre, La Poste mettra en place…Continue Reading: La Poste annonce de nouvelles exigences d’authentification des e-mails pour tous les expéditeurs

Read more
DMARC

Use Your Microsoft Azure Commitment (MACC) with OnDMARC

Aug 21, 20253 min readFrancesca Rünger-Field

OnDMARC is eligible under MACC, so you can deploy DMARC enforcement against your existing Azure commitment — no new budget required.

Read more
DMARC

What Is Email Spoofing and How Do You Prevent It?

Aug 12, 20255 min readFaisal Misle

Email spoofing lets attackers impersonate your domain to deceive recipients. Here's how it works, why it's so effective, and how to stop it.

Read more
DMARC

SVGs with JavaScript are bypassing traditional email security: Learn how to stay secure 

Jul 16, 20253 min readJack Lilley

Executive summary: Hackers are hiding JavaScript inside SVG attachments that pass as harmless images, and slipping past Secure Email Gateways (SEGs). To stay secure, organizations need to enforce a DMARC policy of p=reject, easily implemented with Red Sift OnDMARC, to stop compromised SVGs before they reach the end user. Key takeaways: Scalable Vector Graphics (SVG)…Continue Reading: SVGs with JavaScript are bypassing traditional email security: Learn how to stay secure

Read more
DMARC

Over 50% of US Banks Remain Vulnerable to Phishing Attacks

Jul 9, 20255 min readStuart Rogers

New research shows the majority of US banks still lack DMARC enforcement, leaving customers exposed to impersonation. Here's what the data shows.

Read more
DMARC

73% of Healthcare Breaches Involve Domains Without DMARC

Jun 23, 20254 min readFaisal Misle

New data shows nearly three quarters of healthcare breaches involve organisations with no DMARC enforcement. Here's what that means for the sector.

Read more
DMARC

The Future of Email Security: What's Coming Next

Jun 12, 20255 min readJack Lilley

From AI-generated phishing to evolving authentication standards, here's how Red Sift sees email security developing — and how to stay ahead.

Read more
DMARC

Why DMARC Is Non-Negotiable for Aviation Security

Jun 10, 20253 min readJack Lilley

Aviation is a high-stakes target for email fraud. Here's why DMARC enforcement is critical for airlines, airports, and the wider supply chain.

Read more
DMARC

Why DMARC Should Top Your MSP Roadmap in 2025

Jun 5, 20254 min readJack Lilley

MSPs that don't offer DMARC are leaving clients exposed and revenue on the table. Here's why it belongs at the top of every security roadmap.

Read more
DMARC

New Zealand Mandates DMARC: What It Means for Your Org

May 27, 20254 min readJack Lilley

New Zealand joins the list of governments mandating DMARC enforcement. Here's what the policy requires and how to get compliant fast.

Read more
DMARC

DMARC ROI: The Business Case for Email Authentication

May 14, 20255 min readJack Lilley

DMARC delivers measurable ROI through reduced fraud, improved deliverability, and lower incident costs. Here's how to make the case internally.

Read more
DMARC

Microsoft's Update Drove a 400,000 Domain DMARC Surge

May 1, 20253 min readJack Lilley

Microsoft's high-volume sender requirements triggered a wave of DMARC adoption. Here's what drove it and what it means for email security.

Read more
DMARC

Stop Phishing via Microsoft Email Routing with Red Sift

Mar 26, 20252 min readFaisal Misle

Complex Microsoft 365 routing setups can break DMARC alignment. Red Sift OnDMARC handles it — here's how to protect your mail flow.

Read more
DMARC

The Mail Check Deadline Has Passed: Are You at Risk?

Mar 25, 20256 min readJack Lilley

NCSC's Mail Check service changed its free tier. If your organisation relied on it for DMARC monitoring, here's what to do now.

Read more
DMARC

60% of Healthcare Organisations Have No DMARC Protection

Mar 5, 20254 min readRed Sift

New research shows most healthcare organisations are dangerously exposed to email impersonation. Here's what the data says and what to do.

Read more
DMARC

Preparing for the Mail Check Deadline: A Practical Guide

Feb 26, 20254 min readJack Lilley

NCSC's Mail Check free tier is changing. A step-by-step guide to assessing your exposure and finding the right alternative before the deadline.

Read more
DMARC

2.3 million organizations embrace DMARC compliance

Feb 5, 20254 min readJack Lilley

Executive Summary: Over the past year, 2.3 million organizations have adopted DMARC, enhancing email security globally. This progress reflects a positive trend toward securing email ecosystems, with certain countries leading the charge.​ This article: Introduction It has been one year since Google and Yahoo implemented stricter requirements for bulk email senders. Eleven months ago, Red Sift…Continue Reading: 2.3 million organizations embrace DMARC compliance

Read more
DMARC

Mail Check Changes: What UK Organisations Need to Know

Jan 15, 20255 min readJack Lilley

NCSC's Mail Check service has been updated. A plain-English breakdown of what changed, what's gone, and what to use instead.

Read more
DMARC

BreakSPF: How to mitigate the attack

Nov 28, 20244 min readJack Lilley

Executive Summary: BreakSPF is an emerging threat that takes advantage of misconfigured SPF records, especially those with overly broad IP ranges. Attackers can exploit these vulnerabilities to send fraudulent emails that appear legitimate.Utilizing solutions like Red Sift OnDMARC can help organizations detect and correct these misconfigurations, enhancing their overall email security posture.​ This article: Introduction BreakSPF is…Continue Reading: BreakSPF: How to mitigate the attack

Read more
DMARC

Navigating G-Cloud 14 for DMARC Solutions

Nov 22, 20246 min readFrancesca Rünger-Field

Procuring DMARC through G-Cloud 14? This guide covers what to look for, how OnDMARC fits the framework, and how to get started.

Read more
DMARC

First look at DKIM2: The next generation of DKIM

Nov 5, 20244 min readFaisal Misle

In 2011, the original DomainKeys Identified Mail (DKIM1) standard was published. It outlined a method allowing a domain to sign emails, enabling recipients to verify that the email originated from an entity holding a private key that matches the public key published in the domain’s DNS records. Now in 2024, DKIM is ready for a…Continue Reading: First look at DKIM2: The next generation of DKIM

Read more
DMARC

Protecting U.S. Political Campaigns from Email Attacks

Oct 22, 20244 min readRed Sift

Political campaigns are high-value phishing targets. See how DMARC and email authentication protect against impersonation at scale.

Read more
DMARC

Getting Started with the OnDMARC API

Aug 12, 202410 min readNadim Lahoud

A practical guide to integrating OnDMARC via API. Automate DMARC reporting, policy management, and enforcement at scale.

Read more
DMARC

What's Next for DMARC: Key Takeaways from Our Webinar

Jul 25, 20243 min readFrancesca Rünger-Field

Red Sift and Inbox Monster explored the future of DMARC together. Here are the highlights — from inbox placement to enforcement trends.

Read more
DMARC

DNS and DMARC: Understanding the Relationship

Jun 25, 20244 min readRebecca Warren

DMARC lives in DNS — but the two are often managed separately, creating gaps. Here's how they interact and why aligned ownership matters.

Read more
DMARC

Why successful email marketing relies on domain authentication

Feb 1, 202412 min readFrancesca Rünger-Field

How to master the essentials of email security for optimal campaign reach and inbox placement Crafting the perfect email marketing campaign is hard work. And, nothing is more frustrating than a perfectly crafted campaign not performing because the emails were delivered to the the spam folder. In 2023, Validity found that one in every six…Continue Reading: Why successful email marketing relies on domain authentication

Read more
DMARC

2024: The year of DMARC as a business imperative

Jan 23, 20246 min readRahul Powar

I can say with confidence that the world does not need more security predictions for 2024. But as we head into the new year, it is important to have conversations about security strategy to inform our business priorities and our road maps. As I talk to our Red Sift customers, our partners, and the thought…Continue Reading: 2024: The year of DMARC as a business imperative

Read more
DMARC

Google and Yahoo announce new requirements for email delivery

Oct 24, 20235 min readFrancesca Rünger-Field

On October 3, 2023, Google and Yahoo announced a new set of requirements for email delivery that will become mandated by February 2024. For senders that send more than 5,000 emails a day to Gmail addresses, Google will require a set of authentication measures to be met in order to ensure secure email delivery to…Continue Reading: Google and Yahoo announce new requirements for email delivery

Read more
DMARC

Microsoft's New DMARC Policy Handling: What's Changed

Jul 26, 20233 min readFrancesca Rünger-Field

Microsoft updated how it processes DMARC policies for high-volume senders. Here's what changed, why it matters, and what to do next.

Read more
DMARC

What Is a Beg Bounty? Avoiding DMARC Vulnerability Payouts

Aug 9, 20226 min readFaisal Misle

Beg bounties exploit weak DMARC configs to extort payments. Learn what they are, how they target your domain, and how to shut them down.

Read more
DMARC

How DMARC Helps Healthcare Defend Against Ransomware

Feb 11, 20224 min readRed Sift

Most ransomware starts with a phishing email. DMARC stops attackers impersonating your domain — a frontline ransomware defence for healthcare.

Read more
DMARC

Data Privacy Day: Why DMARC Is a Privacy Issue Too

Jan 28, 20224 min readRed Sift

Email impersonation isn't just a security problem — it's a privacy one. Here's why DMARC belongs in every data protection conversation.

Read more
DMARC

19 DMARC Myths, Debunked by the Experts

Sep 22, 202111 min readBrian Westnedge

Confused by conflicting DMARC advice? We tackle 19 common myths — from 'p=none is fine' to 'DMARC breaks email' — with straight answers.

Read more
DMARC

DMARC Reporting for Office 365: What You Need

Sep 9, 20204 min readRed Sift

Office 365 doesn't surface DMARC aggregate reports natively. Learn how to get full visibility into who's sending on your domain.

Read more
DMARC

London's Restaurants Are Failing Basic Email Security

Feb 14, 20203 min readRed Sift

Red Sift tested DMARC adoption across London's top restaurants ahead of Valentine's Day. The results were not romantic.

Read more
DMARC

U.S. Universities Are Failing at DMARC Adoption

Nov 10, 20191 min readRed Sift

Threatpost research shows US universities lag badly on DMARC. Here's why higher education is a high-risk sector — and what good looks like.

Read more
DMARC

Mailsploit: Does It Break DMARC?

Dec 6, 20173 min readRed Sift

Mailsploit exploits email client rendering bugs to spoof senders — even with DMARC in place. Here's what actually protects you.

Read more
DMARC

Without DMARC, Email Is Cybersecurity's Weakest Link

Apr 13, 20178 min readRahul Powar

Most breaches start with email. Without DMARC, your domain is an open door for impersonation. Here's the case for making enforcement a baseline.

Read more