
Domain without email: the Null MX configuration
An explicit DNS zone for a website without email or a defensive domain: Null MX, strict SPF, DMARC reject, no DKIM selector, and an appropriate CAA policy.
Email protocols, configuration, and best practices for reliable messaging.
62 articles

An explicit DNS zone for a website without email or a defensive domain: Null MX, strict SPF, DMARC reject, no DKIM selector, and an appropriate CAA policy.

Gmail's program for U.S. political committees does not promise the inbox. It formalizes a known rule: identity opens the door, reputation decides what follows.

The IETF is reclassifying ARC (RFC 8617) as "Historic." But deprecated on paper does not mean dead in practice: Apple, Google and Microsoft still require it. Here is what really changes and what you should do.

The email deliverability score is not a black box. It rests on five measurable pillars: authentication, reputation, transport security, BIMI and engagement. This guide breaks them down and gives the thresholds to aim for.

Complete guide to obtaining and deploying a VMC or CMC certificate: CA comparison, pricing, prerequisites and hosting.

Every email carries an invisible logbook. This guide teaches you how to extract it, read it field by field, and diagnose deliverability or security issues.

Your email gateway blocks 99% of threats. But the 1% that gets through is what matters. Here are the 10 header indicators that most filters ignore.

One in five emails never reaches the inbox. This guide shows you how to test your email deliverability before sending and fix every issue.

DMARCbis replaces RFC 7489, drops the PSL in favor of the DNS Tree Walk, adds three tags and splits reporting into three documents. This guide covers everything: how it works, migration, compliance.

BIMI isn't just for large enterprises. This guide covers the 3 deployment tiers (free, CMC, VMC), the DNS prerequisites, and 5 steps for small and mid-sized businesses.

An SVG file can contain JavaScript, phishing links and tracking pixels. Learn how the SVG Tiny-PS profile neutralizes these threats to secure BIMI logos.

Microsoft is retiring Basic authentication for SMTP AUTH on Exchange Online. Revised timeline, 550 5.7.30 error, OAuth alternatives, HVE, Graph API, and step-by-step migration checklist.

Port 25 is blocked by most cloud providers and ISPs to fight outbound spam. Here's how to diagnose the block and restore your sending capability.

SSL, TLS, STARTTLS, Implicit TLS, DANE, MTA-STS: email encryption in transit relies on mechanisms that are often confused. This guide clarifies each protocol, explains their vulnerabilities, and shows how to configure robust TLS encryption on Postfix, Exim and Exchange.

Port 25, 465, 587, or 2525? Each SMTP port has a specific role. This guide breaks down how each port works, its encryption method, the relevant RFCs, and helps you pick the right port for your use case.

Your DNS records are perfect, but emails aren't getting through? The problem might be at the transport layer. This guide shows you how to test SMTP connectivity for each MX server, step by step.

Hands-on tutorial to set up TLS-RPT (SMTP TLS Reporting) on Microsoft 365, Google Workspace, and OVHcloud. DNS record, verification, and troubleshooting included.

Step-by-step tutorial to deploy MTA-STS on Microsoft 365, Google Workspace, and Cloudflare. MX patterns, policy file, hosting, and validation included.

Detailed comparison of the 3 main email blocklists: detection methods, false positive rates, delisting procedures, and impact on Gmail, Outlook, and Yahoo deliverability.

Are your emails consistently landing in spam? This guide analyzes the 5 main causes and gives you a concrete action plan to restore optimal deliverability.

Is your IP on a blacklist and your emails getting rejected? This guide details the delisting procedures for each major blacklist, including processing times and best practices to avoid getting listed again.

A detailed technical guide for developers: DNS configuration (SPF, 2048-bit DKIM), Web API v3, SMTP Relay, dedicated vs shared IP, limits and webhooks.

Putting your logo in the inbox: what you actually need to configure in DNS for BIMI, and how to choose between VMC and CMC.

Gmail and Yahoo require a one-click unsubscribe via RFC 8058-compliant List-Unsubscribe headers. Here's the expected format, the server-side POST, and the compliance checklist.

Starting January 2026, Gmail will no longer continuously fetch messages from external mailboxes via POP ("Check mail from other accounts"). Impacts, timeline, and alternatives for Gmail and Google Workspace users and admins.
How we wired CaptainDNS to AIs through MCP: architecture, HTTP+SSE transport, JSON-RPC, 424 errors, timeouts, and what we learned along the way.

Your logo changed but inboxes still display the old one? It is not only a DNS issue: mailbox providers cache BIMI assets. Discover how the cache layers work and how to plan a smooth BIMI migration.

Starting in November 2025, Google enforces new security requirements for bulk senders: full SPF/DKIM/DMARC authentication, TLS encryption and strict unsubscribe management.