10 min read
Microsoft Extended Service Terms and Renewal Cost Risk
A missed Microsoft 365 renewal can now increase your licensing cost by roughly 23%. That change took effect on May 4, 2026, when Microsoft removed...
2 min read
Keri LaRue : Updated on May 19, 2026
Email authentication standards have moved from “nice to have” to “mandatory.” Microsoft, Google, and Yahoo now require SPF, DKIM, and DMARC for bulk senders, and enforcement is tightening.
Misconfigurations no longer just hurt deliverability. They can lead to message rejection and increase exposure to domain spoofing.
In Part 2 of our podcast series, we go beyond the basics and talk through why DNS is the control plane for trust and how SPF/DKIM missteps can leave organizations exposed.
That makes DNS, SPF, and DKIM non-negotiable for IT leaders responsible for protecting brand trust and ensuring reliable communication.
Every authentication control for email lives in DNS. If your records aren’t accurate, secure, and maintained, your organization loses control over who can send in your name.
Priorities for IT leaders:
SPF defines which mail servers are authorized to send on behalf of your domain. It’s simple in principle, but many organizations break it by stacking multiple SPF records or exceeding the 10-lookup limit.
Best practices:
These issues are more common than most teams expect, especially as new services get added over time. Even small mistakes in SPF, DKIM, or DNS records can lead to authentication failures or unexpected delivery problems.
Run a quick scan below to validate your domain's configuration.
If your results highlight errors or inconsistencies, those should be addressed before building more advanced controls like DMARC enforcement or transport-layer protections.
DKIM signs outbound email so receiving servers can verify it wasn’t altered in transit. Microsoft 365 supports DKIM natively, but most tenants leave the default setup incomplete.
Key actions:
SPF and DKIM don’t stop all phishing. But without them, your domain can be freely impersonated, and your legitimate mail may not reach the inbox. Together with DNS, they form the foundation for DMARC, which adds reporting and enforcement. That’s where visibility and control really begin.
Part 3 of this series covers how to implement DMARC for full protection.
10 min read
A missed Microsoft 365 renewal can now increase your licensing cost by roughly 23%. That change took effect on May 4, 2026, when Microsoft removed...
10 min read
Microsoft’s March 2026 updates signal a shift in how AI operates inside Microsoft 365. Until now, Copilot has focused on individual tasks. Drafting...
10 min read
Many E5 customers are still paying for third-party endpoint privilege tools, maintaining legacy certificate servers on aging domain controllers, and...
1 min read
Attackers don’t just target users anymore. They exploit the gaps in the infrastructure that moves email across the internet. Encryption in transit...
1 min read
Email remains one of the most common ways attackers gain access to organizations. DNS, SPF, DKIM, and DMARC serve as identity checks that verify...
1 min read
Token theft and phishing attacks in Microsoft 365 are rapidly increasing, with over half of surveyed organizations experiencing a breach in the past...