Sender Policy Framework
35
MENTIONS
16
EPISODES
14
PODCASTS
Search complete. 35 mentions across 16 episodes found for "Sender Policy Framework".
Sep 18, 2026
SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability
J
0:37Johannes UllrichHOST
What happened here was, first of all, a somewhat targeted email arriving.
J
0:41Johannes UllrichHOST
Luckily, the email was detected by anti-malware and also would have, uh, been blocked by, well, your usual DKIM and SPF, uh, precautions which, uh, the sender domain had enabled properly.
J
0:56Johannes UllrichHOST
But where it got interesting was when Jan actually analyzed the malware itself.
J
1:02Johannes UllrichHOST
There are two components to the malware that are playing together.
Q&A special: AI's relation to the nuclear bomb, the solution to spam email and one impossible question
A
20:44Alex HudsonHOST
It depends on your three things.
A
20:45Alex HudsonHOST
So SPF, DKIM, and DMARC.
A
20:47Alex HudsonHOST
So Center Policy Frameworks, which essentially, are you allowed to send mail? Domain Keys, Identified Mail, that's DKIM.
A
20:52Alex HudsonHOST
So Cryptographic Signature, which proves you're real.
Email Automation Infrastructure, Deliverability, Reputation, Compliance by Santa Clarita Artificial Intelligence
C
0:46Connor MacIvorHOST
The first questions are who is actually sending the message? What reputation does the sender have and why is the recipient supposed to receive it? Your email may appear to come from your name, but it may actually travel through HubSpot or MailChimp, GoHighLevel, Constant Contact, BombBomb, Salesforce, a brokerage CRM, or some other provider.
C
1:08Connor MacIvorHOST
Google, Yahoo, and Outlook and other email providers evaluate that sending domain, the sending IP address, SPF, DKIM, and DMARC, bounce rates, spam complaints, engagement, and unsubscribed behavior.
C
1:23Connor MacIvorHOST
You can have a legitimate business and a really good offer yet still land in spam because the provider or shared sending environment has a poor reputation.
C
1:33Connor MacIvorHOST
You can also damage your own reputation with an old, purchased, scraped or unverified list.
C
1:39Connor MacIvorHOST
Before I send anything, I inspect the sending domain.
C
1:42Connor MacIvorHOST
Is your primary domain a marketing subdomain or the brokerage's domain? Is the infrastructure shared or dedicated? Who controls the authentication records? Who sees the complaint data? Who owns the reputation if you leave the brokerage? SPF identifies authorized sending servers.
C
2:00Connor MacIvorHOST
DKIM digitally signs messages.
C
2:02Connor MacIvorHOST
DMARC tells receiving providers how to handle authentication failures and helps align the visible.
Your Newsletter Might Be Going to Spam and Here's Why | LB Blair | Send & Grow 2.0 Ep. 4
L
8:47Lori Beth BlairGUEST
We had a lot of amazing internal and external support articles.
L
8:52Lori Beth BlairGUEST
I just started reading the RFCs around SPF and DKIM and learning more and more.
L
8:56Lori Beth BlairGUEST
And then eventually I got picked up by another ESP and then promoted to deliverability.
L
9:02Lori Beth BlairGUEST
It honestly kind of finds you.
Domains: Your Most Important Digital Property
B
9:47Bryan C. MillsHOST
Finally, a TXT record is a notes field attached to your domain that other systems can read.
B
9:54Bryan C. MillsHOST
It's become the workhorse of verification, and the email authentication records from the five forces, SPF and DMARC, are among them, and they live there.
B
10:04Bryan C. MillsHOST
Episode 11 writes those records.
B
10:06Bryan C. MillsHOST
Today, you just need to recognize where they live.
Mikrotik and Cisco Active Exploits - The 443 Podcast - Episode 387
C
30:26Corey NachreinerHOST
Adding a little to the trying to figure out what's real or not, one of the ways about the way they phished coming through a known and validated provider meant that these phishing emails completely passed DKIM.
C
30:38Corey NachreinerHOST
You know, their DMARC and SPF, they had all the right markings because this Brevo connection was a legitimate one.
C
30:47Corey NachreinerHOST
So, you know, that just makes it harder to find certain types of advanced phish when they're actually taking, uh, control of your own infrastructure through really an identity issue, a credential issue, but one that was exposed through SSO.
C
31:02Corey NachreinerHOST
So def- I'm, I'm glad that even our original analyst would notice this was a phish email so long ago.
KYC: KILL YOUR CUSTOMER | THE BITCOIN BRIEF 90
Q
49:49QHOST
Uh, Bitbox, uh, and Trezor both confirmed the breach around about the same time, at 8:00 PM that evening.
Q
49:56QHOST
Now because the attackers gained access to Braavo, which is like the, the marketing tool that lives in the background, uh, they were able to send legitimate emails that passed all of the typical email checks like SPF and DKIM, um, that your email provider normally runs to confirm that a, an email message came from the domain that it claims to be from.
Q
50:18QHOST
And they did indeed come from that domain because they had access to the, to the backend where these companies were, you know, they had all of the, the email related credentials.
Q
50:27QHOST
So the weak point was the company, Braavo, that the wallet m- makers trusted to send their email.
Subject Line Blank E13 - The EU AI Act: What Will Happen to Your AI in 2027?
M
10:31Marcos BravoHOST
The inbox cares about whether you sound like a human worth hearing from.
M
10:35Marcos BravoHOST
Nail your authentication, SPF, DKIM, DMARC, keep your spam complaints rate under Google's zero point three percent ceiling, and test your sending in a safe environment first before you ever hit a real EU inbox.
M
10:52Marcos BravoHOST
Mail trap, anyone? Before you leave, I want you to take four things.
M
10:56Marcos BravoHOST
These are not predictions.
I Built a Mail Server From Scratch and Spent Most of My Time on Four DNS Records
A
7:25Artificial IntelligenceNARRATOR
I would leave it where it already is, because putting your authoritative DNS on the same single server as your mail means one outage takes out both.
A
7:33Artificial IntelligenceNARRATOR
Five records: type name value Y your server IP the forward half of reverse DNS MX, priority ten, where inbound mail goes TXT SPF TXT or DKIM public key DKIM text mark the last three are where the real work is, and they get their own sections below.
A
7:51Artificial IntelligenceNARRATOR
One note on Cloudflare if you use it, the A record must be DNS only, gray cloud, not proxied.
A
7:57Artificial IntelligenceNARRATOR
Proxying it breaks mail entirely, because the world would resolve to Cloudflare's IPs rather than yours, and your PTR would no longer match anything.
A
9:05Artificial IntelligenceNARRATOR
Now the actual work starts.
A
9:06Artificial IntelligenceNARRATOR
The scoreboard, mail-tester.com gives you a throwaway address, you send a message to it, and it grades what arrives out of ten.
A
9:14Artificial IntelligenceNARRATOR
It is the fastest feedback loop in this discipline, and it checks roughly: Does your IP have a PTR record, and does that name resolve back to the same IP? Does the domain publish SPF, and does your sending IP pass it? Is the message DKIM signed, and does the signature verify? Does the domain publish DMARC, and does SPF or DKIM align with the from header? Is your IP on any blocklist? What does SpamAssassin think of the content? The trap is that these look like six independent items and they are not.
A
9:45Artificial IntelligenceNARRATOR
Four of them are the same fact stated four times, and if you treat them separately you will fix them one at a time forever.
The Job Nobody Applied For
B
8:44Bryan C. MillsHOST
Email now requires proof of identity.
B
8:47Bryan C. MillsHOST
The major mailbox providers, Google and Microsoft among them, now expect senders to authenticate their email using published standards with intimidating names and, well, their acronyms, SPF, DKIM, and DMARC.
B
9:01Bryan C. MillsHOST
In plain terms, these are records you publish alongside your domain that let receiving servers confirm a message really came from you.
B
9:09Bryan C. MillsHOST
Without them, legitimate mail, your invoices, your receipts, your newsletters, lands in spam, and or it vanishes entirely.
6 more episodes mention Sender Policy Framework.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.