DKIM: key rotation, third-party senders and troubleshooting

This post is part of the Email Security Foundations series. Rotating DKIM keys Key rotation is good practice. If a private key is ever compromised, rotating limits how long an attacker can use it. Exchange Online makes this easy. How to connect to Exchange Online using PowerShell to rotate the DKIM Keys. After rotation Exchange … Read more

DKIM deep dive: signing, selectors and how verification works

This post is part of the Email Security Foundations series. What DKIM actually does DKIM stands for DomainKeys Identified Mail. Where SPF checks where a message came from, DKIM proves that the message hasn’t been changed while it was in transit. When you send an email, your mail server adds a cryptographic signature to the … Read more

Is Your On-Premise Exchange Server Ready for March 22nd 2026?

If you run an on-premises Exchange Server or any Windows-based SMTP relay that sends mail to or receives mail from Exchange Online, then you might have a hard deadline coming up: March 22, 2026. Miss it, and you can risk breaking your mail flow, if the Root Certificates used by Exchange is not updated. What … Read more

SPF, DKIM, DMARC, DANE, MTA-STS and BIMI explained

This post is part of the Email Security Foundations series. The goal of the series is simple. Explain SPF, DKIM, DMARC, DANE, MTA‑STS, and BIMI in a way that actually helps Microsoft 365 admins run safer email. Before we go deep, here is the map In post #01 we looked at why email authentication still … Read more

Email Security Foundations #01: Why email is still the most dangerous attack surface

This post kicks off the Email Security Foundations series here on MSDigest.net. It’s a practical, no‑nonsense walkthrough of SPF, DKIM, DMARC, DANE, MTA‑STS, and BIMI written specifically for Microsoft 365 admins who want email to stop being the weakest link. Email spoofing remains one of the most effective attacks on the internet, largely because most … Read more