📚 Articles
Working notes on email deliverability, DNS, and the standards that decide whether your mail reaches the inbox. New pieces as the corners of the spec demand them.
BIMI: how to set it up, and why you probably shouldn't bother yet
What it actually takes to get your logo into the inbox with BIMI, and an honest look at why, right now, it's mostly vanity rather than a deliverability win.
Migrate to M365 or Google Workspace without a weekend outage
The MX record takes thirty seconds to change. The caches holding the old one take hours. How to prepare the TTLs, the accepted domains and the Autodiscover record so the cutover is boring.
Email header forensics: how to read a spoof
A supplier emails new banking details and it reads right. How to read Authentication-Results, the Received chain and Return-Path, and find where it came from.
RFC 10001 makes IPv6 a requirement for authoritative DNS
RFC 10001 says every zone MUST be served by at least two IPv6-reachable nameservers as well as two IPv4 ones. What that means for your domain, why it reaches your mail before it reaches your website, and how to check yours in a minute.
Self-hosting email in 2026: the deliverability checklist nobody warns you about
Self-hosting email in 2026 isn't impossible, it's a gauntlet with a fixed set of gates. PTR and FCrDNS, the IPv6 trap, and the checklist in the order to work through it.
How to read an SMTP bounce, not the tea leaves
A bounce says exactly what happened, if you read the number instead of the sentence. The 4.x.x and 5.7.x codes per provider, what each one really means, when to retry.
Is public Wi-Fi DNS safe? No, and the usual defences don't fix it
A public resolver, encrypted DNS and DNSSEC all fail on a hotel gateway that forges answers. What actually protects you on someone else's network, and what to check before you sign in.
How to check Autodiscover, and the four ways it breaks
Outlook stops at the first endpoint that hands back a payload, right or wrong. How to check your Autodiscover record and read Outlook's own log.
Your domain's on a blocklist. Which ones actually matter?
A blacklist checker lit up red and you're panicking. Most of those listings never touch your mail. Here's which blocklists actually gate delivery, and how to get delisted.
Why Microsoft 365 and Outlook are blocking your mail in 2026
Microsoft blocked your mail with 550 5.7.515 or 5.4.1 and the bounce reads like Klingon. Decode the 2025 Outlook and M365 codes and fix the right thing.
Everything "passes" and the mail still lands in spam. Why?
SPF, DKIM and DMARC all pass, Gmail Postmaster shows 0% spam, and your mail still lands in Junk. Here's why authentication is not placement, and what actually moves the needle.
Google Workspace DKIM 2048-bit: the zero-downtime myth
The honest way to move Google Workspace DKIM from 1024-bit to 2048-bit. Why the slick two-selector swap you read about doesn't work here, and how to make the unavoidable signing gap harmless.
Microsoft 365 DKIM 2048-bit: why you run it twice
Rotate-DkimSigningConfig upgrades only the selector that is not currently signing, so moving Microsoft 365 from 1024-bit to 2048-bit takes two runs four days apart. What the second run is for, and how to tell which selector is live.
A friendly MXToolbox alternative for email deliverability checks
An honest, friendly comparison: when MXToolbox is the right tool, and when TamingDNS gives you faster, plain-English email deliverability checks for free.
DMARC from p=none to p=reject, without breaking real mail
The safe path from a do-nothing DMARC record to full enforcement. Read the reports first, fix every legitimate sender, and ratchet the policy in stages instead of one risky jump.
From no MTA-STS to enforce, without blackholing your own mail
A staged plan for going from no SMTP TLS policy to enforce mode. Reporting first, the pitfalls that bite in the middle, and real scenarios for M365 and mixed-MX setups.
What on earth is DNSSEC, and should your business care?
A plain-English explainer of what DNSSEC actually does, where it genuinely helps your domain and business, and where it doesn't, without the cryptography lecture.