DKIM deep dive: signing, selectors and how verification works

This post is part of the Email Security Foundations series. What DKIM actually does DKIM stands for DomainKeys Identified Mail. Where SPF checks where a message came from, DKIM proves that the message hasn’t been changed while it was in transit. When you send an email, your mail server adds a cryptographic signature to the … Read more

SPF mistakes, troubleshooting, and validation

This post is part of the Email Security Foundations series. The mistakes that break SPF quietly SPF usually does not fail in loud or obvious ways. Mail does not bounce with a helpful error message. It just gets filtered, delayed, or rejected somewhere else. You only find out when someone eventually asks, “Did you get … Read more

SPF deep dive – how it works and how to configure it

This post is part of the Email Security Foundations series. What SPF actually does SPF, Sender Policy Framework, is simply a way to publish a list in DNS of which servers are allowed to send email for your domain. When a receiving mail server gets a message claiming to be from yourdomain.com, it looks up … Read more

SPF, DKIM, DMARC, DANE, MTA-STS and BIMI explained

This post is part of the Email Security Foundations series. The goal of the series is simple. Explain SPF, DKIM, DMARC, DANE, MTA‑STS, and BIMI in a way that actually helps Microsoft 365 admins run safer email. Before we go deep, here is the map In post #01 we looked at why email authentication still … Read more

Email Security Foundations #01: Why email is still the most dangerous attack surface

This post kicks off the Email Security Foundations series here on MSDigest.net. It’s a practical, no‑nonsense walkthrough of SPF, DKIM, DMARC, DANE, MTA‑STS, and BIMI written specifically for Microsoft 365 admins who want email to stop being the weakest link. Email spoofing remains one of the most effective attacks on the internet, largely because most … Read more