📚 Articles

Working notes on email deliverability, DNS, and the standards that decide whether your mail reaches the inbox. New pieces as the corners of the spec demand them.

🦁

BIMI: how to set it up, and why you probably shouldn't bother yet

What it actually takes to get your logo into the inbox with BIMI, and an honest look at why, right now, it's mostly vanity rather than a deliverability win.

Featured 25 Jun 2026
13 min read
🚚 Migration

Migrate to M365 or Google Workspace without a weekend outage

The MX record takes thirty seconds to change. The caches holding the old one take hours. How to prepare the TTLs, the accepted domains and the Autodiscover record so the cutover is boring.

27 Aug 202619 min
🔎 Email Headers

Email header forensics: how to read a spoof

A supplier emails new banking details and it reads right. How to read Authentication-Results, the Received chain and Return-Path, and find where it came from.

20 Aug 202616 min
🌐 DNS

RFC 10001 makes IPv6 a requirement for authoritative DNS

RFC 10001 says every zone MUST be served by at least two IPv6-reachable nameservers as well as two IPv4 ones. What that means for your domain, why it reaches your mail before it reaches your website, and how to check yours in a minute.

13 Aug 202613 min
📮 Deliverability

Self-hosting email in 2026: the deliverability checklist nobody warns you about

Self-hosting email in 2026 isn't impossible, it's a gauntlet with a fixed set of gates. PTR and FCrDNS, the IPv6 trap, and the checklist in the order to work through it.

6 Aug 202610 min
↩️ Deliverability

How to read an SMTP bounce, not the tea leaves

A bounce says exactly what happened, if you read the number instead of the sentence. The 4.x.x and 5.7.x codes per provider, what each one really means, when to retry.

30 Jul 202614 min
📡 DNS

Is public Wi-Fi DNS safe? No, and the usual defences don't fix it

A public resolver, encrypted DNS and DNSSEC all fail on a hotel gateway that forges answers. What actually protects you on someone else's network, and what to check before you sign in.

27 Jul 202614 min
🔍 Outlook

How to check Autodiscover, and the four ways it breaks

Outlook stops at the first endpoint that hands back a payload, right or wrong. How to check your Autodiscover record and read Outlook's own log.

23 Jul 202611 min
🚫 Deliverability

Your domain's on a blocklist. Which ones actually matter?

A blacklist checker lit up red and you're panicking. Most of those listings never touch your mail. Here's which blocklists actually gate delivery, and how to get delisted.

16 Jul 202618 min
🪟 Deliverability

Why Microsoft 365 and Outlook are blocking your mail in 2026

Microsoft blocked your mail with 550 5.7.515 or 5.4.1 and the bounce reads like Klingon. Decode the 2025 Outlook and M365 codes and fix the right thing.

9 Jul 202617 min
📭 Deliverability

Everything "passes" and the mail still lands in spam. Why?

SPF, DKIM and DMARC all pass, Gmail Postmaster shows 0% spam, and your mail still lands in Junk. Here's why authentication is not placement, and what actually moves the needle.

2 Jul 20267 min
🔑 DKIM

Google Workspace DKIM 2048-bit: the zero-downtime myth

The honest way to move Google Workspace DKIM from 1024-bit to 2048-bit. Why the slick two-selector swap you read about doesn't work here, and how to make the unavoidable signing gap harmless.

30 Jun 20266 min
🔑 DKIM

Microsoft 365 DKIM 2048-bit: why you run it twice

Rotate-DkimSigningConfig upgrades only the selector that is not currently signing, so moving Microsoft 365 from 1024-bit to 2048-bit takes two runs four days apart. What the second run is for, and how to tell which selector is live.

30 Jun 20269 min
🧰 MXToolbox

A friendly MXToolbox alternative for email deliverability checks

An honest, friendly comparison: when MXToolbox is the right tool, and when TamingDNS gives you faster, plain-English email deliverability checks for free.

30 Jun 202610 min
🛡️ DMARC

DMARC from p=none to p=reject, without breaking real mail

The safe path from a do-nothing DMARC record to full enforcement. Read the reports first, fix every legitimate sender, and ratchet the policy in stages instead of one risky jump.

23 Jun 20265 min
🔒 MTA-STS

From no MTA-STS to enforce, without blackholing your own mail

A staged plan for going from no SMTP TLS policy to enforce mode. Reporting first, the pitfalls that bite in the middle, and real scenarios for M365 and mixed-MX setups.

18 Jun 20265 min
🔐 DNSSEC

What on earth is DNSSEC, and should your business care?

A plain-English explainer of what DNSSEC actually does, where it genuinely helps your domain and business, and where it doesn't, without the cryptography lecture.

11 Jun 20265 min