2026 Update: Enforcement has tightened considerably since this post first went written. Starting in November 2025, Google began ramping up enforcement on non-compliant bulk mail, and failing messages can now see temporary or permanent SMTP rejections rather than just being routed to spam. Microsoft has also joined Google and Yahoo, enforcing its own SPF, DKIM, and DMARC requirements for Outlook.com, Hotmail.com, and Live.com senders since May 5, 2025. And the DMARC standard itself has changed: in May 2026, the IETF officially published DMARCbis, an update to the DMARC specification that adds a few new record tags and retires a few old ones. We've updated the guidance below to reflect all of this.
Brad Wyro
Recent Posts
Deploying DMARC to Adhere to Google's Strengthened Email Authentication Requirements
By Brad Wyro posted in Email Authentication, Anti-Spoofing
New Security & Administration Features for MDaemon Email Server
By Brad Wyro posted in MDaemon Email Server, Product Updates
With every new version of MDaemon, we've added new security and administration features to facilitate better collaboration and to protect businesses from the latest email-borne threats.
We're excited to announce the release of SecurityGateway 10, with some exciting new features and enhancements. Read on to learn more!
Businesses concerned about the shortfalls of DMARC with forwarded messages and mailing lists will benefit from new email authentication features added to MDaemon Email Server version 24. Discover how ARC (Authenticated Received Chain) enhances email security and solves authentication issues.
Protect Accounts from Hackers: 9 Tips for Stronger Passwords
By Brad Wyro posted in Cybersecurity, Email Security Best Practices, Email Best Practices, Passwords
Passwords have been the primary mechanism for online security for years, but many people continue to use poor habits when creating passwords, and this trend appears to be getting worse as the average online user has to keep track of up to 100 accounts.
How to Block Executable Files in SecurityGateway™ for Email
By Brad Wyro posted in Attachments, Email Security, Anti-Virus
Malware only needs one click to do considerable damage to your business. That click is still most often triggered the same way it always has been: a hyperlink to a spoofed login page, a Word or Excel file carrying a malicious macro, unpatched software, or a plain old file attachment paired with a convincing social engineering pitch (“invoice attached,” “please review,” “your delivery couldn't be completed”).
Protect Yourself from IRS Tax Filing Phishing Scams
By Brad Wyro posted in Phishing, Email Security Best Practices, tax scams
The April 15 tax filing deadline is approaching. Learn how to safeguard yourself from IRS tax filing phishing scams that can compromise your personal information and financial security.
For most businesses, email is the key driver of efficient communication. Even after a business closes for the day, email continues to flow. This is why it is crucial for administrators to be able to monitor the mail server status and queues on-demand, even on the go.
Stay One Step Ahead: Anti-Phishing Best Practices for Your Business
By Brad Wyro posted in Email Security, Phishing, Email Security Best Practices, Email Best Practices
Protect your business from phishing attacks with these essential best practices. Stay one step ahead of cybercriminals and safeguard your sensitive data.
Microsoft Outlook (Version 2401 Build 16.0.17231.20194) includes an issue that prevents Outlook from retrieving data from ActiveSync servers. As of February 29, 2024, Microsoft has fixed the issue in Outlook Desktop version 2402 Build 17328.20068 and higher. To install the update, launch Microsoft Outlook and select File | Office Account | Update Options | Update Now.

