Guides

High Trust Score, Missing DMARC: A Gap That Still Demands Attention
In boardrooms from Sydney to Perth, security teams increasingly rely on domain reputation scores as a quick filter for incoming mail. A clean number on the…
A Practical Weekly Trust Score Review for Your Email Allow List
Email domains fly onto allow lists when suppliers, banks, and government agencies are first onboarded. Months later, the same entry might shield a hijacked…
DMARC p=reject policy that still lets mail slip past - what it means
A DMARC policy of p=reject is widely treated as the finish line for email authentication across Australian organisations, from Sydney financial firms to…
How DMARC alignment exposes spoofed marketing emails
A marketing email can look polished, use a familiar logo and contain a valid unsubscribe link, yet still be fraudulent. The visible sender address is easy to…
Why Misspelled TLDs Help Phishers Look Legitimate
A domain ending in .cm can look almost identical to a familiar .com address when it appears in a rushed email, mobile notification or shortened link. The…
How to Automate Domain Trust Checks for Every Email in Your SIEM Pipeline
Email remains a major attack path for Australian organisations, from supplier invoice fraud in Melbourne to credential theft aimed at customers in Sydney and…
What Sudden SPF PermError Spikes Reveal About Email Infrastructure
A sudden flood of SPF PermError responses rarely arrives without warning. It usually signals that something deeper has shifted in the way a domain negotiates…
Validating suspicious email headers using Trusted Sender Score
Every week, thousands of Australians receive emails that pretend to be from their bank, a courier company, or a government agency. Some land in inboxes in…
Why a New WHOIS Record and Low Trust Score Deserve Attention
A domain with a recently created WHOIS record and a poor trust score should be treated cautiously, especially when it appears in an unexpected email. This…
Reading DMARC reports with multiple DKIM signatures
When you open a DMARC aggregate report and see two or three different DKIM signatures attached to messages that look identical, the first reaction is often…