Tech SPF Macros: Overcoming the 10 DNS Lookup Limit If your domain relies heavily on third-party services to send emails on its behalf, you could encounter the DNS lookup limit outlined in section 4.6.4 of RFC7208, resulting in an SPF permerror. Without a correct DKIM configuration, emails may not pass DMARC checks, potentially leading to blocking or
Tech DKIM Ed25519-SHA256 adoption In this blog, we will delve into the significance of these RFCs, their recommendations, and the current state of email providers' support for Ed25519-SHA256.
Tech The Ultimate SPF / DKIM / DMARC Best Practices 2023 Reduce spoofing and phishing, build and maintain a solid reputation, and increase email deliverability with SPF, DKIM, and DMARC.
Tech The end of Expect-CT With the release of the latest Google Chrome browser (105) at the end of August 2022, the Expect-CT header has officially been deprecated and will be removed in version 107.
Tech Eight years of Sender Policy Framework (SPF) Sender Policy Framework (SPF) is used to authenticate senders of email. Receiving servers use SPF to verify if the message source IP is authorized to send on behalf of the HELO or MAIL FROM domain. History The first draft [https://datatracker.ietf.org/doc/html/draft-schlitt-spf-classic-00] of the Sender Policy
Tech Hosted MTA-STS by URIports Publish an MTA-STS policy by adding just two CNAME records to your domain's DNS. URIports will publish an RFC-compliant MTA-STS policy using the latest best practices and periodically validate your policy and email setup.
Tech Introduction to SPF, DKIM, and DMARC For those of you that are new to the email security subject, you've probably heard about SPF, DKIM, and DMARC. But what are they, and how do they relate to each other? Like regular postal mail, someone could send you a letter in an envelope and forge the sender's name
Reporting API v1 is here! A new version of the Reporting API [https://web.dev/reporting-api/] has been released that hopefully will get supported across more browsers. The legacy Reporting API (v0) is currently only supported by Chrome and Edge browsers. If you have already implemented the Reporting API v0, you can migrate to the
Guides DMARC External Destinations verification The aggregate (rua) and failure (ruf) report destinations can be specified within the domain's DMARC policy. And while it is possible to specify a destination on a different organizational domain, the receiving domain must expressly indicate that reports for other domains are welcome. The absence of this record will prevent
Tech Why use URIports for your DMARC monitoring? DMARC, SPF, and DKIM have been around for more than eight years now. Every day, more domains adopt this mechanism to increase email deliverability and protect against email spoofing and phishing attacks. The "R" in DMARC stands for Reporting, and it is one of the great features of DMARC. Email
Guides Single Sign-On (SSO) URIports supports Single Sign-On (SSO) using OpenID Connect (OIDC) for Mountain and Himalaya subscriptions. SSO speeds up access to your account by allowing you to log in with your existing company or Identity-As-A-Service (IDaaS) credentials, meaning fewer passwords to keep track of and easy user management. We've written quick guides
Guides SSO OIDC Quick guide Okta Below are screenshots to illustrate the steps required to connect URIports to Okta for the purpose of enabling Single Sign-On through OpenID Connect (OIDC). 6. Paste the Redirect URI from URIports here 7. Select which users should have access to URIports 9. Copy the Client ID and save this value
Guides SSO OIDC Quick guide Azure Active Directory (Entra ID) Below are screenshots to illustrate the steps required to connect URIports to Azure Active Directory (Entra ID) for the purpose of enabling Single Sign-On through OpenID Connect (OIDC). 4. Select which users should have access to URIports 5. Paste the Redirect URI from URIports here 7. Copy the Client ID
Guides SSO OIDC Quick guide OneLogin Below are screenshots to illustrate the steps required to connect URIports to OneLogin for the purpose of enabling Single Sign-On through OpenID Connect (OIDC). 5. Paste the Redirect URI from URIports here 10. Copy the Client ID and save this value in URIports 12. Copy the Client Secret and save
Guides SSO OIDC Quick guide SalesForce Below are screenshots to illustrate the steps required to connect URIports to SalesForce for the purpose of enabling Single Sign-On through OpenID Connect (OIDC). 8. Paste the Redirect URI from URIports here 13. Copy the Consumer Key and save this value in URIports as Client ID 14. Reveal the Consumer
Guides SSO OIDC Quick guide Ping Identity Below are screenshots to illustrate the steps required to connect URIports to Ping Identity for the purpose of enabling Single Sign-On through OpenID Connect (OIDC). 8. Paste the Redirect URI from URIports here 16. Copy the ISSUER and save this value in URIports as the Application URL 17. Copy the
Guides SSO OIDC Quick guide Google Workspace Below are screenshots to illustrate the steps required to connect URIports to Google Workspace (formerly known as G Suite) for the purpose of enabling Single Sign-On through OpenID Connect (OIDC). The Google Workspace Application URL is https://accounts.google.com. Go to the Google Cloud Platform [https://console.cloud.google.
Guides Instant DMARC reports Why wait 24 hours? Instant DMARC reports allow you to view your SPF and DKIM performance in seconds.
Tech Microsoft is finally sending DMARC aggregate reports (...poorly) Microsoft has started sending DMARC aggregate reports, but unfortunately they don't know how to format a proper email.
Guides DMARC aggregate reports explained DMARC reports are a powerful tool for detecting issues with your DKIM and SPF setup. Let me guide you through the most common DMARC report types and dive into the details of some of ours to help you better understand your own.
Tech Why you need Network Error Logging (NEL) By adding a NEL response header to your website, you’ll receive reports from your visitors’ browsers, allowing you to accurately measure performance characteristics that will help you improve your website.
Tech Setting up OpenPGP Web Key Directory (WKD) If you use OpenPGP to secure your email communication, you should consider publishing your public key using Web Key Directory. It's easier than you think.
Application Support DMARC failure reports and GDPR Unlike aggregate reports, DMARC failure reports contain personal data like email subject, sender address, recipient address, and sometimes even the original message body. What does this mean for GDPR compliance?
Application Support The Beginner's Guide to DMARC with URIports As soon as SPF, DKIM, and DMARC policies are set up, reports will start to appear in your URIports account. I'm going to explain the different report elements, what they mean, and what to do with them.
Tech DMARC reports IETF RFC compliance After analyzing millions of DMARC reports, I came to the disappointing conclusion that only a fraction of them comply with the DMARC IETF RFC guidelines. Most of them lack mandatory elements or hold incorrect element values.