Glossary
Email authentication
DMARC
Domain-based Message Authentication, Reporting and Conformance — ties SPF and DKIM to the From header a reader sees, tells receivers what to do when neither aligns, and asks them to report what they saw.
Defined in RFC 7489.
Where this appears
The lessons that use this term, and what each is for.
Email Authentication FundamentalsThe gap SPF and DKIM leave openDemonstrate a message that passes both SPF and DKIM and still deceives the recipient.Email Authentication FundamentalsThe policy record, tag by tagRead any DMARC record and state exactly what it asks receivers to do.Email Authentication FundamentalsHow a receiver evaluates DMARCWalk the evaluation in order and say at which step a given message passes or fails.Email Authentication FundamentalsThe staged path to enforcementWrite a rollout plan with a defensible go/no-go criterion at every stage.DKIM PractitionerGetting d= alignedTake a vendor from signing as themselves to signing as you, and verify it happened.DMARC PractitionerEvery tag, including the unused onesWrite a policy record in which every tag is there for a reason you can state.DMARC Practitionersp and npSet different policies for the apex, existing subdomains and non-existent ones.DMARC PractitionerWhat pct actually doesPredict the effect of a pct value, and say why it is a worse rollout tool than it looks.DMARC PractitionerThe two queriesName the record a receiver applies to any given From domain, and the order it looked.DMARC PractitionerDelegating the recordDelegate _dmarc to a processor, and say what you give up by doing it.DMARC PractitionerWhat a report does not containState the questions aggregate reports can answer and the ones they never will.DMARC PractitionerSending reports somewhere elseAuthorise an external report destination and confirm reports are arriving.DMARC Practitionerfo, and what each value asks forRequest the failure reports you want, and predict how few you will receive.DMARC PractitionerEvidence before policyState the criteria that make the next policy step safe, in numbers from your own reports.DMARC PractitionerWhich half of the estate firstChoose between enforcing the apex and enforcing subdomains first, and defend the order.DMARC PractitionerThe rollbackDefine in advance what would make you revert, and make reverting take minutes.DMARC PractitionerFour causes, one methodTake a failing message to one of four causes using only its headers.DMARC PractitionerDomains that send nothingPublish the complete set of records that makes a parked domain unusable for mail.DMARC PractitionerFifty domains, one policyRun a consistent policy across an estate without fifty independent records drifting apart.DMARC PractitionerDomains you inheritBring an acquired domain under policy in an order that cannot break its mail.DMARC PractitionerWhat changes without youName the things that alter your DMARC outcome while your record stays identical.DMARC PractitionerWhat to alert onDefine alerts that fire on the changes that matter and stay quiet the rest of the time.Advanced Email TrustWhat BIMI requiresList every prerequisite in order, and say which one stops most domains.Advanced Email TrustReading live recordsRead a BIMI record, fetch what it points at, and judge whether it will render.Advanced Email TrustWhat authentication does not buySeparate the delivery problems authentication fixes from the ones it cannot touch.Advanced Email TrustThe bulk-sender requirementsState what the large mailbox providers require of bulk senders, and who counts as one.Advanced Email TrustThe order to adopt inSequence the advanced controls so each one rests on something already working.Email Security PractitionerFifteen minutes of public DNSEstablish a domain’s entire published mail posture without any access to it.Email Security PractitionerRanking by consequenceOrder findings by what each one actually permits, not by how easy it is to describe.Email Security PractitionerThe write-up that gets acted onWrite a finding that produces a change rather than a ticket nobody closes.Email Security PractitionerSequencing an estateOrder an estate of domains so early work makes later work smaller.Email Security PractitionerThe work that is not yoursIdentify every party whose action the programme depends on, before you commit to a date.Email Security PractitionerWhat it actually costsGive an honest estimate of effort and money for an authentication programme.Email Security PractitionerA spoofing campaignWork an active spoofing campaign in the order that ends it fastest.Email Security PractitionerAn outage you causedRecover from a policy change that stopped legitimate mail, and find out what you missed.Email Security PractitionerExplaining it to people who do not run DNSDescribe the exposure and the fix without analogies that will be quoted back at you wrongly.Email Security PractitionerFraud that authenticates perfectlyExplain why the most costly email fraud passes every check you have deployed.Email Security PractitionerQuestions this is the wrong answer toRecognise the problems people will bring to you that authentication cannot address.Email Security PractitionerA worked estateTake a fictional estate from cold audit to enforcement, making every decision explicitly.Email Security PractitionerWhat steady state involvesDefine the recurring work that keeps a finished programme finished.Domain Trust ArchitectureA definition worth usingDefine domain trust in a way that does not depend on any product or vendor.Domain Trust ArchitectureThe four surfacesPlace any control on one of four surfaces, and say which surface a given attack targets.Domain Trust ArchitectureWhere each control sitsMap every control you have learned onto the surface it defends.Domain Trust ArchitectureThe dependency graphDraw what depends on what, and identify the controls that cannot be deployed yet.Domain Trust ArchitectureWhat must come firstSequence a programme so each step rests on something already working.Domain Trust ArchitectureWhat to do with no budgetList the controls that cost nothing but attention, and deploy them in an afternoon.Domain Trust ArchitectureA method you can run by handAssess any estate against every surface using public data and a fixed sequence.Domain Trust ArchitectureWhat a score cannot sayUse a posture score without letting it stand in for the assessment.Domain Trust ArchitectureImpact against effort, honestlyRank remediation without pretending either axis is more precise than it is.Domain Trust ArchitectureThe ones worth skippingDefend a decision not to deploy a control, in writing.Domain Trust ArchitectureMaking the caseArgue for the work without scare tactics, and act usefully when the answer is no.Domain Security PractitionerThe briefRead an estate description and list what you still have to find out.Domain Security PractitionerPosture, domain by domainProduce the assessment table for a mixed estate and rank every finding.Domain Security PractitionerThe first thirty daysChoose the work that ships in a month with no budget and no dependencies.Domain Security PractitionerNinety days, and a yearSequence the funded work around the constraints you cannot remove.Domain Security PractitionerOwners and criteriaAssign every item to a party and give each step a condition for proceeding.Domain Security PractitionerThe listWrite the not-doing section for a specific estate, with triggers.Domain Security PractitionerDefending it afterwardsAnswer for an omission after an incident, when the omission was deliberate.Domain Security PractitionerThe shape of the reportStructure the document so the highest-value items are the ones acted on.Domain Security PractitionerThe conversationPresent the findings so the free work starts this week and the rest is scheduled.Domain Security PractitionerA year laterDescribe what a successful programme looks like twelve months on, and how you would know.