Email Security and Authentication
SPF, DKIM, DMARC and alignment — in deployment order.
Courses
Why spoofing works, what SPF, DKIM and DMARC each assert, and how to reach enforcement without blocking your own mail.
Operating SPF on a real estate: exact lookup accounting, macros, flattening against dynamic SPF, multi-domain architecture, third-party senders, and a diagnostic method that names the failure.
Operating DKIM: what a signature covers, why it breaks in transit, key records and their tags, selector and rotation strategy, vendor signing, and reading a verification failure down to its cause.
Operating DMARC: every tag including the ones nobody sets, how a receiver finds your policy, reporting at scale, staged enforcement with a rollback, and a triage method for failures.
What sits on top of authentication: MTA-STS and DANE for transport, TLS-RPT for evidence, BIMI for the inbox, and the deliverability signals no DNS record can buy.
The capstone: auditing a domain cold, sequencing a programme across an estate, running the three incidents you will actually meet, and saying honestly what none of it stops.