SPF, DKIM and DMARC in practice

Key takeaways SPF and DKIM each validate a domain, but neither looks at the address your recipient actually sees. DMARC exists to connect them to that address, and that connection is called alignment. The DMARC specification was rewritten in May 2026. RFC 9989 replaces RFC 7489, and DMARC is now an IETF Standards Track protocol […]

Read More

Microsoft 365 accounts hijacked through relayed sign-ins to reach payroll email

Key takeaways An active phishing campaign is taking over Microsoft 365 accounts by relaying the genuine sign-in page, so multi-factor authentication is completed correctly and the resulting session is stolen anyway. Hundreds of organisations were targeted by email in July across healthcare, education, manufacturing, government and professional services in the United States, Canada and Europe. […]

Read More

How to Spot a Phishing Email in 30 Seconds

Key takeaways: Most phishing emails can be spotted in under a minute with a few quick checks. The strongest signals are the real sender address, hidden link destinations, and pressure to act fast. Hover over links to see where they really go, and never open unexpected attachments. Polished writing no longer proves an email is […]

Read More