Transactional mail can pass SPF and DKIM and still fail DMARC when neither aligns with the visible From domain, a dev.to Node.js guide shows. Because forwarding breaks SPF, the author treats aligned DKIM as the path to protect.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence50
GitHub's SPF record uses all 10 DNS lookups RFC 7208 allows once the includes inside its vendors' records are counted. One more mail vendor would make SPF return PermError and leave GitHub's mail to pass DMARC on DKIM alone.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives45
- Confidence55
Publishers onboarding custom domains should confine wildcard DNS to routing and verify three mail records per tenant, a dev.to guide argues. That costs extra writes and waiting, and it gives every customer its own rollback boundary and audit trail.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
The request came from an unauthorized account on a real government domain, and Revolut acted on it. The company calls the number of affected customers limited, and it declined to say how many or name the agency.
Perspective Coverage
5 publishers
- Builder
- Builder 23%
- Operator
- Operator 55%
- Investor
- Investor 22%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence66
Publishing p=none starts an XML report feed and enforces nothing. A practitioner sequence for getting a domain to p=reject turns on an owned sender inventory, aligned DKIM and a written condition for each step.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives20
- Confidence55
A dev.to walkthrough stores the provider's DNS zone ID as replaceable cache and checks the returned domain before every mutation. The cutover only closes when an independent DNS read matches the approved MX set.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+10
- Incentives20
- Confidence38
A dev.to post on healthtech workspace joining argues that DNS TXT challenges and mailbox confirmations prove different things, and the Go example it ships bounds DNS freshness at 24 hours while leaving the mailbox proof undated.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives20
- Confidence50
A dev.to walkthrough of per-tenant subdomains on a gaming platform gives the TTL drop, the target change and the TTL restore separate deadlines, preconditions and audit evidence, so a worker that restarts can prove what it already applied.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap0
- Incentives18
- Confidence45
RFC 9989 removed the pct tag on 19 May 2026, and a record still carrying pct=25 describes a staged rollout that conforming receivers no longer honour. The replacement, t=y, gives one testing step and no percentages.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+18
- Incentives22
- Confidence58
In four codebases a dev.to author found bounce handlers that read 5.x.x and stopped, so a receiver's verdict on the sending domain got written down as a dead mailbox. The RFC 3463 subject digit separates the two.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+12
- Incentives40
- Confidence57
The DNS and header half of deliverability is a pure function of your own configuration, so a scheduled job can assert it; inbox placement is a measurement you put on a dashboard with a date on it.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence55
A dev.to walkthrough splits outbound mail by risk profile. Whether that split changes anything for receivers comes down to one tag: sp= on the organizational domain. Subdomains still need their own SPF and DKIM either way.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+12
- Incentives60
- Confidence55
A dev.to runbook for property-management DNS ties every record to a property ID, plans each delete against an expected current value, and calls the job done only once resolver checks agree.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap−5
- Incentives18
- Confidence55
A dev.to walkthrough of FastAPI onboarding separates two proofs that codebases keep merging, one testing whether a person can read mail at a domain and the other whether anyone can write to its zone. Negative caching explains why the first check fails.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+8
- Incentives22
- Confidence55
A dev.to walkthrough traces a newsletter whose SPF and DKIM both pass for example.net while the visible From reads editorial.example. The evidence that settles it sits in the receiver's Authentication-Results header.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+8
- Incentives25
- Confidence55
A dev.to design post writes an attempt row before every provider call and keeps accepted apart from delivered across six states, paying extra latency where the API publishes no idempotent-send contract.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap−5
- Incentives18
- Confidence58
The request arrived from what looked like a government agency's domain, cleared all three email authentication checks, and Revolut's compliance team processed it. Notifications to affected customers began on September 11.
Reality
- Evidence35
- Adoption30
- Hype gap+25
- Incentives60
- Confidence45
A dev.to onboarding design keeps the SPF, DKIM and DMARC values you generated in one row and the answers a resolver returned in another. Its comparator is a single stripped string match, so an SPF value the customer appended to lands in drifted.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives20
- Confidence60
The decision to automate tenant subdomains turns on whether you can test intent, confirm the authoritative answer and reverse a record, and a dev.to field guide keeps a checklist for anything below that bar.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap0
- Incentives20
- Confidence55
Microsoft Security Research reported over a million emails pairing fake ServiceNow invoices with forged forward threads. No malware ran, so the investigation lives in mail headers and accounting records.
Reality
- Evidence45
- Adoption30
- Hype gap−10
- Incentives65
- Confidence55
Earlier coverage
- Direct Send carried 29,785 spoofed internal emails past the mail gateway in two months
Security · September 11, 2026 · 1 publisher
- A lapsed Carnival promo domain routed authenticated booking mail into a cloaked malware network
Build · September 10, 2026 · 1 publisher
- Trezor's spoofed alert reused the language of the $112.7m Coldcard exploit
Invest · September 10, 2026 · 1 publisher
- Cloudflare's send_email binding reaches only verified addresses until onboarding finishes
Build · September 7, 2026 · 1 publisher
- IPQS scores a ten-year domain 95 with no malicious artifact in its own report
Build · August 29, 2026 · 1 publisher
- SPF and DMARC records that pass every free checker and stop nothing
Build · August 24, 2026 · 1 publisher
- Buy transactional email on recovery controls, not send price
Build · August 20, 2026 · 1 publisher
- 1,400 npm maintainer domains, 18 flags, and one word doing too much work
Build · August 18, 2026 · 1 publisher
- Ransomware's price point is $10m to $1bn in revenue, and it is not moving
Security · August 18, 2026 · 1 publisher
- Judge transactional email on retries and DKIM alignment, not open rates
Build · August 17, 2026 · 1 publisher
- Email and Slack disagree on what a conversation is, and the join key is the envelope
Build · August 15, 2026 · 1 publisher