SPF record syntax explained
Every SPF mechanism and qualifier, with examples, and how to stay under the 10-lookup limit.
Background reading for the checks. Every guide links to the tool that tests what it explains.
Every SPF mechanism and qualifier, with examples, and how to stay under the 10-lookup limit.
A staged setup plan from monitoring to full enforcement, with report review checkpoints at each stage.
How to rotate DKIM keys safely, without breaking mail already in flight, using selector overlap.
How MTA-STS enforces encrypted mail delivery and TLS-RPT gives you visibility into failures, and why they pair together.
A plain-language walkthrough of record types, TTLs and authoritative versus resolver answers.
Every BIMI requirement explained: DMARC enforcement, the SVG logo format, and when a Verified Mark Certificate matters.
What an MX record actually does, how priority and fallback work, and what happens when a domain has none.
A practical, ordered checklist covering SPF, DKIM, DMARC, BIMI, MTA-STS and TLS-RPT.
What every DNS record type actually does, read from real lookups, and the mistakes each one invites.
Why a DNS change is not visible everywhere at once, what actually sets the wait, and how to plan a cutover around it.
Why SPF stops working past ten DNS lookups, how to count yours, and the four fixes in order of least regret.
Every tag RFC 9989 defines, with defaults and worked examples, and the tags the 2026 revision removed.
Selectors are not discoverable from DNS. Three reliable ways to find yours, and what each major platform uses.
Read headers the way a mail server does: the Received chain bottom-up, the authentication verdict, and what a forgery looks like.
What Google, Yahoo and Microsoft each require from senders, where they differ, and the order to fix things in.
The current MX records for both platforms, where your own values come from, and how to cut over without losing mail.
Why the PTR record for your server is not in your own DNS, who can publish it, and what mail receivers actually check.
Why SPF and DKIM can pass while DMARC fails, what alignment actually requires, and how to identify and fix each class of failure from an aggregate report.
What expiry actually does to visitors and API clients, how to check the whole chain, and how to renew, automate and monitor it.
What each security header actually does, which ones are obsolete, and how to deploy CSP and HSTS without breaking the site.
What a chain and a loop are, what each 3xx status really means, and how to collapse the usual four hops into one.
What CAA actually prevents, the exact record values for the common authorities, and how to publish one without blocking your own renewal.
What signing a zone actually proves, how the chain of trust is built, and how to turn DNSSEC on and off without an outage.
What LCP, INP and CLS measure, the current thresholds, why field and lab data disagree, and the fixes for each.
What a blocklist listing actually means, how to read the return code, how to fix the cause, and how delisting works at each major operator.
Everything that decides inbox placement once SPF, DKIM and DMARC are already correct: reputation, reverse DNS, warm-up, list hygiene, complaints, unsubscribe, TLS and the monitoring loop.
How RDAP replaced WHOIS, what an RDAP response contains, which EPP status codes matter, and how to find who really runs a domain.
What an autonomous system is, how to look up the network behind an IP address, and how far the public data can honestly take you.
What open, closed and filtered actually mean, how to test from the outside, and which ports are worth worrying about.