Skip to main content
Sender Policy Framework

Sender Policy Framework

Search complete. 35 mentions across 16 episodes found for "Sender Policy Framework".

Sep 18, 2026

Johannes UllrichHOST
0:37
What happened here was, first of all, a somewhat targeted email arriving.
Johannes UllrichHOST
0:41
Luckily, the email was detected by anti-malware and also would have, uh, been blocked by, well, your usual DKIM and SPF, uh, precautions which, uh, the sender domain had enabled properly.
Johannes UllrichHOST
0:56
But where it got interesting was when Jan actually analyzed the malware itself.
Johannes UllrichHOST
1:02
There are two components to the malware that are playing together.
Alex HudsonHOST
20:44
It depends on your three things.
Alex HudsonHOST
20:45
So SPF, DKIM, and DMARC.
Alex HudsonHOST
20:47
So Center Policy Frameworks, which essentially, are you allowed to send mail? Domain Keys, Identified Mail, that's DKIM.
Alex HudsonHOST
20:52
So Cryptographic Signature, which proves you're real.
Connor MacIvorHOST
0:46
The first questions are who is actually sending the message? What reputation does the sender have and why is the recipient supposed to receive it? Your email may appear to come from your name, but it may actually travel through HubSpot or MailChimp, GoHighLevel, Constant Contact, BombBomb, Salesforce, a brokerage CRM, or some other provider.
Connor MacIvorHOST
1:08
Google, Yahoo, and Outlook and other email providers evaluate that sending domain, the sending IP address, SPF, DKIM, and DMARC, bounce rates, spam complaints, engagement, and unsubscribed behavior.
Connor MacIvorHOST
1:23
You can have a legitimate business and a really good offer yet still land in spam because the provider or shared sending environment has a poor reputation.
Connor MacIvorHOST
1:33
You can also damage your own reputation with an old, purchased, scraped or unverified list.
Connor MacIvorHOST
1:39
Before I send anything, I inspect the sending domain.
Connor MacIvorHOST
1:42
Is your primary domain a marketing subdomain or the brokerage's domain? Is the infrastructure shared or dedicated? Who controls the authentication records? Who sees the complaint data? Who owns the reputation if you leave the brokerage? SPF identifies authorized sending servers.
Connor MacIvorHOST
2:00
DKIM digitally signs messages.
Connor MacIvorHOST
2:02
DMARC tells receiving providers how to handle authentication failures and helps align the visible.
Lori Beth BlairGUEST
8:47
We had a lot of amazing internal and external support articles.
Lori Beth BlairGUEST
8:52
I just started reading the RFCs around SPF and DKIM and learning more and more.
Lori Beth BlairGUEST
8:56
And then eventually I got picked up by another ESP and then promoted to deliverability.
Lori Beth BlairGUEST
9:02
It honestly kind of finds you.
Bryan C. MillsHOST
9:47
Finally, a TXT record is a notes field attached to your domain that other systems can read.
Bryan C. MillsHOST
9:54
It's become the workhorse of verification, and the email authentication records from the five forces, SPF and DMARC, are among them, and they live there.
Bryan C. MillsHOST
10:04
Episode 11 writes those records.
Bryan C. MillsHOST
10:06
Today, you just need to recognize where they live.
Corey NachreinerHOST
30:26
Adding a little to the trying to figure out what's real or not, one of the ways about the way they phished coming through a known and validated provider meant that these phishing emails completely passed DKIM.
Corey NachreinerHOST
30:38
You know, their DMARC and SPF, they had all the right markings because this Brevo connection was a legitimate one.
Corey NachreinerHOST
30:47
So, you know, that just makes it harder to find certain types of advanced phish when they're actually taking, uh, control of your own infrastructure through really an identity issue, a credential issue, but one that was exposed through SSO.
Corey NachreinerHOST
31:02
So def- I'm, I'm glad that even our original analyst would notice this was a phish email so long ago.
QHOST
49:49
Uh, Bitbox, uh, and Trezor both confirmed the breach around about the same time, at 8:00 PM that evening.
QHOST
49:56
Now because the attackers gained access to Braavo, which is like the, the marketing tool that lives in the background, uh, they were able to send legitimate emails that passed all of the typical email checks like SPF and DKIM, um, that your email provider normally runs to confirm that a, an email message came from the domain that it claims to be from.
QHOST
50:18
And they did indeed come from that domain because they had access to the, to the backend where these companies were, you know, they had all of the, the email related credentials.
QHOST
50:27
So the weak point was the company, Braavo, that the wallet m- makers trusted to send their email.
Marcos BravoHOST
10:31
The inbox cares about whether you sound like a human worth hearing from.
Marcos BravoHOST
10:35
Nail your authentication, SPF, DKIM, DMARC, keep your spam complaints rate under Google's zero point three percent ceiling, and test your sending in a safe environment first before you ever hit a real EU inbox.
Marcos BravoHOST
10:52
Mail trap, anyone? Before you leave, I want you to take four things.
Marcos BravoHOST
10:56
These are not predictions.
Artificial IntelligenceNARRATOR
7:25
I would leave it where it already is, because putting your authoritative DNS on the same single server as your mail means one outage takes out both.
Artificial IntelligenceNARRATOR
7:33
Five records: type name value Y your server IP the forward half of reverse DNS MX, priority ten, where inbound mail goes TXT SPF TXT or DKIM public key DKIM text mark the last three are where the real work is, and they get their own sections below.
Artificial IntelligenceNARRATOR
7:51
One note on Cloudflare if you use it, the A record must be DNS only, gray cloud, not proxied.
Artificial IntelligenceNARRATOR
7:57
Proxying it breaks mail entirely, because the world would resolve to Cloudflare's IPs rather than yours, and your PTR would no longer match anything.
Artificial IntelligenceNARRATOR
9:05
Now the actual work starts.
Artificial IntelligenceNARRATOR
9:06
The scoreboard, mail-tester.com gives you a throwaway address, you send a message to it, and it grades what arrives out of ten.
Artificial IntelligenceNARRATOR
9:14
It is the fastest feedback loop in this discipline, and it checks roughly: Does your IP have a PTR record, and does that name resolve back to the same IP? Does the domain publish SPF, and does your sending IP pass it? Is the message DKIM signed, and does the signature verify? Does the domain publish DMARC, and does SPF or DKIM align with the from header? Is your IP on any blocklist? What does SpamAssassin think of the content? The trap is that these look like six independent items and they are not.
Artificial IntelligenceNARRATOR
9:45
Four of them are the same fact stated four times, and if you treat them separately you will fix them one at a time forever.
Bryan C. MillsHOST
8:44
Email now requires proof of identity.
Bryan C. MillsHOST
8:47
The major mailbox providers, Google and Microsoft among them, now expect senders to authenticate their email using published standards with intimidating names and, well, their acronyms, SPF, DKIM, and DMARC.
Bryan C. MillsHOST
9:01
In plain terms, these are records you publish alongside your domain that let receiving servers confirm a message really came from you.
Bryan C. MillsHOST
9:09
Without them, legitimate mail, your invoices, your receipts, your newsletters, lands in spam, and or it vanishes entirely.

6 more episodes mention Sender Policy Framework.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.