Discussion about this post

User's avatar
The Shadow Catalog's avatar

The two-sender explanation is the hinge because DMARC closes an alignment gap, not every impersonation path. When a reject policy is honored, it can stop an unauthorized sender from borrowing the exact visible From domain; it does not make a lookalike domain or a compromised legitimate mailbox honest. That boundary is worth keeping in the user-facing explanation.

Nelson Lopes's avatar

Last year, I alerted the IT department of a company I was collaborating with about a serious gap in their email protection. To show them how important it was to fix it, I sent an email impersonating their new CEO, with a note that the CEO would not be happy to see that the email had gone through. The first reaction was “How did you do that?”, as if it weren't something we've been doing since we were kids. Regardless of the reaction and all the explanations, a year later the protection was still not configured...

You and I, as managers, know how demanding our roles are, but faced with a demonstration like that, it's incomprehensible that it wasn't immediately prioritized.

Excellent article! Even though the three are already configured in my environments, I still learned a lot from reading it 👍

2 more comments...

No posts

Ready for more?