← All courses
Email Authentication Fundamentals
How SPF, DKIM, and DMARC actually work, why spoofing is trivial without them, and how to read the reports they produce.
How Email Delivery Actually WorksThe envelope, the header, and why spoofing is trivial by default.SPF — What It Checks and How It FailsThe DNS record, the 10-lookup limit, and the one thing SPF alone doesn't protect.DKIM — Signing and VerificationCryptographic signatures, selectors, and what the signing domain does (and doesn't) prove.DMARC — Policy, Alignment, and EnforcementHow DMARC ties SPF/DKIM to the visible From: header, and why p=none isn't protection.Reading a DMARC Aggregate ReportWhat's actually inside the XML your rua= address receives, and how to read it.BIMI — Brand Logos in the InboxWhy a verified brand logo requires DMARC enforcement first, not the other way around.
Ready for the quiz?
12 questions, 80% to pass. You'll give your name and email once, right before you start it – that's the only thing this course ever asks for, and it's only used to issue your certificate.
Take the final quiz