How to Generate a Compliant DMARC Record
A working walkthrough of composing a DMARC TXT record — every tag, the safe defaults, and the rollout path from p=none to p=reject without breaking client mail.
Archive
A working walkthrough of composing a DMARC TXT record — every tag, the safe defaults, and the rollout path from p=none to p=reject without breaking client mail.
A working analyst’s guide to reading raw email headers — Received chain, Authentication-Results, alignment, ARC, and the patterns that surface root cause fast.
A working DNS lookup discipline is the foundation of every MSP DMARC engagement — record types, resolver behavior, propagation, and the patterns that catch real issues.
How to run change control on _dmarc TXT records across an MSP portfolio — approval gates, rollback windows, ticket templates, audit trail.
Operational mechanics of handing a client’s DMARC setup back at engagement end — RUA cutover, documentation, what to keep monitoring vs cut hard.
What MSPs actually show clients in a Quarterly Business Review on DMARC — trend graphs, narrative, what to do when the report is “boring” (good).
How to write the DMARC service line into a Master Service Agreement and Statement of Work — scope boundaries, change control, liability, and exit clauses.
Complete DMARC rollout guide for Google Workspace — SPF, DKIM (1024 → 2048 bit), DMARC, relay routing, multi-domain tenants, BIMI prereqs.
Complete DMARC rollout guide for Microsoft 365 — SPF, DKIM in Defender for 365, DMARC, hybrid Exchange, GCC tenants, and the M365-specific gotchas.
Amazon SES requires domain identity verification plus DKIM config to satisfy DMARC. Here’s the AWS-specific setup.