Skip to main content

p=monthly; the newsletter

The month in email authentication, and what to do about it

One email a month. I read the RFCs and drafts, the mailbox provider announcements, the vendor posts and the research, then tell you in five minutes whether anything needs to change in your DNS or your email stack.

What's in an issue

The big story
The month's most important change, and what to do about it this month. October: who actually reads the DMARC reports their record asks for.
Protocol watch
The RFCs and drafts that moved, and whether any of it is deployable yet. October: DKIM2's busiest month, and the RFC 9989 tree walk reaching DMARC libraries.
From the field
Bypasses, outages and provider changes that hit real domains, each with the check to run. October: an empty envelope sender that gets past Microsoft 365's Direct Send control.
One record at a time
One command to run against your own domain. October: a one-line dig that tells you your DKIM key length.

Every item ends with what to do about it, even when the answer is “nothing, yet.”

From the October issue

Every issue closes with one check to run against your own domain. October's tells you how long your DKIM key is:

dig +short TXT selector1._domainkey.yourdomain.com | tr -d '" ' | grep -o 'p=[^;]*' | awk '{print length($0)-2}'

Swap in a selector you use (the s= tag in any DKIM-Signature header you send). The number is the length of your public key: 392 is a 2048-bit RSA key, 216 is 1024-bit, 44 is Ed25519. Anything else under 216 is an RSA key below 1024 bits and should be replaced. Our DKIM checker does the same read without a terminal.

Past issues

  1. Everyone publishes. Fewer are listening. Issue 1 · October 2026

What you sign up for

  • One email a month, with a one-click unsubscribe in every issue.
  • We use your address to send p=monthly and never sell or share it. Privacy policy.
  • Reply to any issue: it lands in my inbox, and I read every reply.