Guides

Spotting Phishing Behind a Valid SPF Record
A phishing message can pass an SPF check and still be designed to steal credentials, redirect payments, or install malware. SPF confirms that an approved…
Understanding High Forwarding Rates in DMARC Reports
A high percentage of forwarded messages in DMARC aggregate reports usually means that many recipients receive your mail through another server before it…
How to Set Up Automated Alerts for Lookalike Domains
A newly registered domain that resembles your business name can support phishing, fake login pages, invoice fraud, or deceptive email campaigns. Attackers may…
Enrich Threat Intelligence With Domain Trust Data
Using the platform’s API to enrich threat intelligence feeds with domain trust data can give security teams more context than an isolated domain name or IP…
Automating Weekly Monitoring for Brand-Impersonating Domains
A convincing impersonation domain can be registered in minutes and used to send phishing emails, host a fake login page, or redirect customers to malware.…
Turning Domain Reputation Into Incident Priorities
Security teams often receive more alerts than they can investigate immediately. Domain reputation data helps reduce that pressure by showing which identities,…
What High DMARC Failures From One IP Can Reveal
A high volume of DMARC failures from a single IP address is a meaningful signal, but it is not proof of a phishing campaign by itself. The address may belong…
Finding Lookalike Domains With Fuzzy Matching
A legitimate brand can be copied long before anyone notices. Attackers register domains that resemble a company’s name, product, or service, then use them for…
Why You Shouldn't Rely Solely on SPF to Block Phishing Emails
SPF is an important email authentication control, but it was never designed to determine whether a message is trustworthy. It verifies whether a sending server…
How to Check Whether a Sender IP Is Blocklisted
An email sender’s IP address can lose trust for several reasons, including spam complaints, compromised accounts, malware, poor list hygiene, or an incorrectly…