Ruvalin

Guides

Understand, check, fix

Guides written to be used: the exact values to publish, the commands to verify them, and what each protection does not do. None of them is a translation.

DMARC

DMARC: the complete guide

DMARC is a DNS record published at _dmarc.your-domain.com that tells receiving servers what to do with messages claiming to come from you that pass neither SPF nor DKIM. Three policies exist: p=none observes, p=quarantine files as junk, p=reject has the message refused. Only p=reject stops impersonation.

  • p=none, quarantine or reject: which to choose

    The three DMARC policies, what they actually do to a message, and why staying at p=none amounts to having installed nothing. With the decision rule, and what pct= and sp= really do.

    Updated

  • Moving DMARC to reject without breaking your mail

    The rollout to p=reject, stage by stage, over two to three weeks. How to read the reports, align every legitimate sender, and how to tell when it is safe to tighten.

    Updated

  • What DMARC does not stop

    DMARC blocks exact spoofing of your domain and nothing else. Cousin domains, misleading display names and compromised mailboxes all go straight through. What that means in practice.

    Updated

SPF

  • SPF: the ten DNS lookup limit

    Past ten DNS queries, an SPF record returns permerror and stops protecting the domain, with nothing visibly breaking. How to count, how to get back under the limit, and why flattening is a trap.

    Updated

Email fraud

Business email compromise: how it works and how to stop it

Business email compromise gets a company to pay into an account a fraudster controls, by impersonating over email a director or a supplier whose bank details have supposedly changed. In France it accounted for 13.5% of assistance requests from companies in 2025, up 93% year on year.

With your provider

Missing a word? Open the glossary

CallBook