
Domain without email: the Null MX configuration
An explicit DNS zone for a website without email or a defensive domain: Null MX, strict SPF, DMARC reject, no DKIM selector, and an appropriate CAA policy.
Domain-based Message Authentication implementation and policy configuration.
29 articles

An explicit DNS zone for a website without email or a defensive domain: Null MX, strict SPF, DMARC reject, no DKIM selector, and an appropriate CAA policy.

Hornetsecurity 365 Total Protection is the cloud SEG for SMBs and MSPs (ex-Vade, now Proofpoint). Complete guide: architecture, mx01.hornetsecurity.com MX, spf.hornetsecurity.com SPF include, DKIM by CNAME, gateway vs API and a comparison with Proofpoint/Barracuda/Mimecast.

Barracuda Email Gateway Defense is the cloud SEG for SMBs and MSPs (200,000+ customers). Complete guide: architecture, *.ess.barracudanetworks.com MX, SPF/DKIM/DMARC, DNS detection, the distinction with the ESG appliance (CVE-2023-2868) and a comparison with Mimecast/Proofpoint/Defender.

The IETF is reclassifying ARC (RFC 8617) as "Historic." But deprecated on paper does not mean dead in practice: Apple, Google and Microsoft still require it. Here is what really changes and what you should do.

The email deliverability score is not a black box. It rests on five measurable pillars: authentication, reputation, transport security, BIMI and engagement. This guide breaks them down and gives the thresholds to aim for.

Cloudflare now covers 4 email layers: free Email Routing, transactional Email Service (public beta April 2026), anti-phishing Email Security (formerly Area 1), and DMARC Management. Complete guide covering architecture, DNS, Proofpoint/Mimecast comparison, and pricing.

Cisco Secure Email Cloud Gateway (CES) is Cisco's primary SaaS offering in 2026, the successor to the legacy ESA appliances inherited from Ironport. Complete guide: CES onboarding, iphmx.com MX records by region (NA/EU/APJ), SPF/DKIM/DMARC, migration from ESA to CES, 2024-2025 Gartner Magic Quadrant exit, zero-day CVE-2025-20393, comparison with Proofpoint, Mimecast, Defender and Abnormal.

Abnormal Security is an API-native ICES platform that detects BEC, VEC, and Account Takeover attacks using behavioral AI, with no MX change required. Complete guide: Attune 1.0 architecture, Proofpoint/Mimecast/Defender comparison, limitations, and DNS record audit.

Proofpoint is the enterprise SEG benchmark, used by 87 of the Fortune 100. Complete guide: Nexus AI architecture, TAP, SPF/DKIM/DMARC configuration, the 2024 EchoSpoofing incident and a comparison with Mimecast, Microsoft Defender and Abnormal Security.

Mimecast is a cloud email gateway (SEG) that intercepts all traffic via MX redirection. Full guide: architecture, SPF/DKIM/DMARC setup, Proofpoint/Abnormal Security comparison, and DNS audit.

One in five emails never reaches the inbox. This guide shows you how to test your email deliverability before sending and fix every issue.

DMARCbis replaces RFC 7489, drops the PSL in favor of the DNS Tree Walk, adds three tags and splits reporting into three documents. This guide covers everything: how it works, migration, compliance.

91% of cyberattacks start with an email. Learn how to spot the warning signs, verify a suspicious link, and protect your inbox with the right protocols.

Are your emails consistently landing in spam? This guide analyzes the 5 main causes and gives you a concrete action plan to restore optimal deliverability.

From .dvag (10,562 domains) to .ferrari, .zara, and .google: discover why 494 global companies have invested in their own .brand TLD.

Add the CaptainDNS MCP server to ChatGPT and use 3 widgets to troubleshoot DMARC/DNS and analyze email headers without leaving the conversation.

Putting your logo in the inbox: what you actually need to configure in DNS for BIMI, and how to choose between VMC and CMC.

Gmail and Yahoo require a one-click unsubscribe via RFC 8058-compliant List-Unsubscribe headers. Here's the expected format, the server-side POST, and the compliance checklist.

Your logo changed but inboxes still display the old one? It is not only a DNS issue: mailbox providers cache BIMI assets. Discover how the cache layers work and how to plan a smooth BIMI migration.

Starting in November 2025, Google enforces new security requirements for bulk senders: full SPF/DKIM/DMARC authentication, TLS encryption and strict unsubscribe management.

AI-automated phishing emails average a click-through rate of roughly 54%. At scale, automation can make these campaigns up to ×50 more profitable. Both figures come from the Microsoft Digital Defense Report 2025 (MDDR 2025).