Guides
Reading DMARC reports to uncover hidden third-party sendersMost Australian organisations rely on a stack of cloud tools to communicate with customers, from marketing platforms to invoicing systems. Each one can send…Why a Valid DMARC Record May Still Leave a Domain ExposedA domain can publish a perfectly valid DMARC record and still be useful to an attacker conducting email spoofing. The record may exist, pass syntax checks and…Catch-All SPF and DMARC strategies for subdomain spoofing defenceSubdomain spoofing has become a favourite tactic of scammers sending fake ATO overdue notices, false CBA statements, and impersonations of smaller Australian…Why Rotating DKIM Keys Too Often Can Weaken Email AuthenticationEmail security is a constant balancing act for Australian businesses, especially as phishing scams targeting local tradies, accountants, and small retailers…Tracking email senders with a history of frequently rotating IPsAustralian organisations have spent recent years dealing with a steady rise in business email compromise, and the Australian Cyber Security Centre regularly…Why Malicious Domains Change SPF Records Before a Phishing CampaignPhishing remains the number one cyber crime reported to the Australian Cyber Security Centre, with thousands of incidents logged every year across Sydney,…Automating Recurring Bulk Domain Checks for Alumni and Former StaffWhen an employee hands in their badge and walks out of the Sydney head office for the final time, most IT teams in Australia tick the account off the…Query Firewall Blocklist IP Trust Scores with an APIA firewall blocklist is useful for stopping suspicious traffic, but an IP address alone does not explain the wider risk. An address may be linked to phishing,…Detecting Phishing Campaigns Behind Fresh, Authenticated DomainsA phishing operation can register a new domain, configure DKIM and DMARC correctly, and still use the domain to impersonate a bank, government agency,…What SPF Passes but DKIM and DMARC Failures RevealAn email can pass SPF and still present a serious trust problem. SPF confirms that the sending server is authorised to send for a domain, but it does not prove…