Freddie Leeman
freddieleeman.bsky.social
Freddie Leeman
@freddieleeman.bsky.social
Code cruncher by day, smart home alchemist by night, fiercely guarding the realms of privacy and security.
You might want to read up on asymmetric cryptography. The DNS record contains the public key, not the private key used for signing DKIM. learndmarc.com
Learn and test SPF, DKIM and DMARC
Visualize, analyze and improve your email authentication setup
learnDMARC.com
August 14, 2025 at 3:57 AM
This is one of the most inaccurate and confusing DMARC infographics I’ve seen. It appears to be created either by someone unfamiliar with the standard or by a flawed AI tool.
July 17, 2025 at 5:24 AM
Started my day with a smile... Thanks. To work around the limit, use subdomains or SPF macros: www.uriports.com/blog/spf-mac...
SPF Macros: Overcoming the 10 DNS Lookup Limit
If your domain relies heavily on third-party services to send emails on its behalf, you could encounter the DNS lookup limit outlined in section 4.6.4 of RFC7208, resulting in an SPF permerror. Withou...
www.uriports.com
July 17, 2025 at 5:19 AM
Shameless plug: check out my URIports.com — it analyzes and aggregates your reports, notifies you only when something needs attention, and starts at just $12/year!
An advanced unified tool to monitor DMARC, Content Security Policy, Network Error Logging, TLS-RPT, and more.
URIports. Real-time reporting for websites and email
URIports.com
July 15, 2025 at 7:32 PM
I tried the same with SFP and DMIK — shockingly, still no luck. These protocols are *so* picky about spelling!
July 15, 2025 at 7:30 PM
Sure there is: dmarcvendors.com. If you are looking for a SAAS, have a look at mine: uriports.com
DMARC Vendors and Solutions
2025 List of DMARC Vendors and DMARC Solutions
dmarcvendors.com
July 7, 2025 at 9:51 AM
RFC 7489 does not mention "forensic reports" anywhere. Section 7.3 refers to "failure reports," which can be used for forensic analysis. To avoid confusion—especially among those new to email authentication—we should use the correct terminology.
June 22, 2025 at 10:07 PM
Failure reports are incorrectly referred to as "Forensic Reports,". Additionally, the explanation of "Relaxed Alignment" could be improved as it means that subdomains are ignored for alignment purposes, and as long as the Organizational Domain matches, the identifier will pass alignment.
June 16, 2025 at 9:37 AM
DMARC: Instructs receiving mail servers (MTAs) on how to handle messages when *BOTH* SPF and DKIM checks fail, and provides detailed reports. Additionally, DMARC checks alignment between the domain used for authentication and the domain in the RFC5322.From header. 👉 learnDMARC.com
Learn and test SPF, DKIM and DMARC
Visualize, analyze and improve your email authentication setup
learnDMARC.com
May 16, 2025 at 1:38 PM
This isn't a DMARC monitoring tool; it simply validates the email authentication of a message you send to it. In contrast, a DMARC monitoring service provides insight into all email traffic claiming to come from your domain.
May 10, 2025 at 4:29 AM
Here’s mine: uriports.com/dmarc — feature-rich, privacy-first, and easy to use. Affordable too: starting at just $12 per year, with a free 30-day trial and no payment details needed.
An advanced unified tool to monitor DMARC, Content Security Policy, Network Error Logging, TLS-RPT, and more.
URIports. Real-time reporting for websites and email
uriports.com
May 7, 2025 at 12:59 PM
There’s even an AI-narrated podcast at the top of the post for those who prefer listening over reading.
April 25, 2025 at 9:33 AM
I've created a few resources that might help: LearnDMARC.com visualizes the authentication process between servers, and this blog post uses an easy-to-understand analogy to explain SPF, DKIM, and DMARC: www.uriports.com/blog/introdu....
Learn and test SPF, DKIM and DMARC
Visualize, analyze and improve your email authentication setup
LearnDMARC.com
April 25, 2025 at 9:33 AM
MTA-STS-POLICY Check incorrectly identifies the policy as being in testing mode, even though it is set to enforce. Consider adding an explanation that the site’s inability to detect DKIM doesn’t necessarily mean DKIM isn’t configured or working correctly. Do you check for all common selectors?
April 4, 2025 at 9:42 AM
Have you tried my learndmarc.com ?
Learn and test SPF, DKIM and DMARC
Visualize, analyze and improve your email authentication setup
learnDMARC.com
March 26, 2025 at 6:08 AM
Even if a domain is not used for email, enabling DMARC helps prevent spoofing. It is also essential to configure SPF, DKIM, and DMARC for parked domains. www.m3aawg.org/sites/defaul...
March 16, 2025 at 10:00 AM
No DMARC policy and a SoftFail SPF policy? Here is a link to email authentication best practices: www.uriports.com/blog/spf-dki...
SPF, DKIM, and DMARC Best Practices
Reduce spoofing and phishing, build and maintain a solid reputation, and increase email deliverability with SPF, DKIM, and DMARC.
www.uriports.com
March 6, 2025 at 10:23 AM
The DKIM signature is typically added by the sending MTA, so it does not require manual intervention.
February 26, 2025 at 5:00 PM