Help
Short articles about the things Sojka flags. Each one says what the finding means, what it costs you if you leave it, and exactly what to change — including the parts that are not a DNS record.
Nothing here needs an account. If a colleague looks after your DNS, send them the link.
New to all of this? Read Why DMARC is worth having before anything goes wrong, then What DMARC alignment means, then From p=none to p=reject without breaking your own mail — in that order they cover the why, the mechanism, and the path.
Understand
- Why DMARC is worth having before anything goes wrong — Anyone can put your domain in the From header of an email. DMARC is how receivers learn what to do about it - and how you learn it is happening.
- What DMARC alignment means — Passing SPF or DKIM is not the same as passing DMARC. What alignment adds, and why it decides whether your mail survives.
- Why a well-kept sending domain collects fewer spam reports — Receivers keep a running score on your domain. Good hygiene - authentication on every sender, an enforced policy, clean lists - lowers complaints and compounds into reputation.
- What a DMARC report actually contains — The XML receivers mail you, decoded: who reports, what a row means, and why the reporting address is the most consequential part of your record.
- Why strangers appear in your DMARC reports — Unknown servers carrying mail that passes your DMARC are usually recipients forwarding it. How forwarding looks in reports, and when an unknown sender actually matters.
- DKIM is not a digital signature — DKIM is your server vouching for the domain, not a person signing a message - and DMARC says nothing about encryption. What each layer actually proves.
Fix
- Your mail is not DKIM-aligned — Mail that passes DMARC on SPF alone fails the moment it is forwarded. How to sign with your own domain, per platform.
- Your mail is not SPF-aligned — What SPF alignment is, when it is worth fixing, and why DKIM is usually the better place to spend the effort.
- Mail using your domain that is not yours — A sender that never authenticated as you cannot be aligned - there is no key it could use. What stops it is the policy, and here is why.
- You are on a blocklist. Now what? — Find the listing, fix the cause before delisting, then follow each list's own process. Which lists matter, which expire on their own, and what never to do.
- The SPF 10-lookup limit: the record that breaks by growing — Every include costs DNS lookups, the budget is ten, and going over turns your SPF into a permanent error. How records get there and how to walk them back.
- Why Gmail, Seznam and Outlook now refuse unauthenticated mail — The big receivers stopped treating authentication as optional. What the sender requirements actually demand, and the shortest path to meeting them.
Decide & act
- From p=none to p=reject without breaking your own mail — p=none observes, quarantine and reject protect. The staged path - verify every real sender, tighten a slice at a time, watch the reports - so nothing of yours breaks.
- The domain that sends no mail still needs DMARC — Parked and defensive domains are the easiest to spoof precisely because nobody watches them. The three records that lock one down, with the reasoning.
- Email authentication for a domain you just bought — A fresh domain has no reputation and no bad habits - the one moment authentication is easy. The day-one checklist, for sending and parked domains both.
- BIMI: the logo in the inbox, and what it really requires — The inbox logo is a reward for finished DMARC work: enforcement first, then the record, then - for most receivers - a verified mark certificate.
Not finding it?
Write to support@sojka.email. If Sojka told you something you could not act on, that is a gap in this page, not in you.