
Featured Insights
How Does a DMARC Check Work? A Step-by-Step Guide to DMARC Validation
A DMARC check looks at a message that has already gone through SPF and DKIM, and asks one more question: does the domain that passed either of those ...
Filter by Tag
How Does a DKIM Check Work? A Step-by-Step Guide to DKIM Verification
A DKIM check confirms two things about a message: 1) that a system holding the sending domain's private key signed it, and 2) that the signed parts...
How Does an SPF Check Work?
When a message arrives, the receiving mail server checks the sending domain's SPF record before it does almost anything else with the message. It...
Top ISO 27001 Internal Audit Providers (2026): A Buyer's Guide
Truvo Cyber is a Canadian cybersecurity firm that performs independent ISO 27001 internal audits for companies preparing for a certification audit or...
SPF, DKIM and DMARC: How the Three Email Authentication Records Work Together
SPF, DKIM and DMARC work as a team to stop attackers from sending email that looks like it comes from a domain they do not control. SPF checks...
What Is DNSSEC? Signed DNS, CAA Records and What They Protect
DNSSEC (the DNS Security Extensions) signs DNS records so a validating resolver can prove an answer came from the zone owner and was not altered; it...
What Is DKIM? How Email Signing Works Under RFC 6376
DKIM (DomainKeys Identified Mail) lets a domain sign its outgoing mail with a private key and publish the matching public key in DNS, so a receiving...
What Is BIMI? Brand Logos in the Inbox, DMARC Enforcement and MTA-STS
BIMI (Brand Indicators for Message Identification) is a DNS TXT record, published at default._bimi.yourdomain.com, that lets participating mailbox...
What Is an SPF Record? Format, Syntax and the 10-Lookup Limit Explained
An SPF record is a DNS TXT record, published at a domain and starting with v=spf1, that lists the IP addresses and services allowed to send email...
What Is DMARC? Policy Levels, Alignment and Reporting Explained (RFC 7489 to RFC 9989)
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS TXT record, published at _dmarc.yourdomain.com, that tells receiving...
ISO 27001 A.5.7: Threat Intelligence
ISO 27001 A.5.7 requires an organization to collect and analyze information about information security threats, turn it into threat intelligence, and...
ISO 27001 A.5.18: Access Rights
ISO 27001 A.5.18 requires that access rights to information and systems are provisioned, reviewed, modified, and removed across the whole lifecycle,...
ISO 27001 A.5.17: Authentication Information
ISO 27001 A.5.17 requires that authentication information, the passwords, keys, tokens, and secrets people and systems use to prove identity, is...
ISO 27001 A.5.16: Identity Management
ISO 27001 A.5.16 requires an organization to manage the full life cycle of identities, for both people and non-human accounts, from creation through...
ISO 27001 A.8.3: Information Access Restriction
ISO 27001 A.8.3 requires that access to information and application functions is restricted in line with the access control policy, enforced at the...
ISO 27001 A.8.12: Data Leakage Prevention
ISO 27001 A.8.12 requires data leakage prevention measures on the systems, networks, and devices that handle sensitive information, so that data...
ISO 27001 A.8.1: User Endpoint Devices
ISO 27001 A.8.1 requires that information stored on, processed by, or accessible through user endpoint devices, meaning laptops, desktops, phones,...
ISO 27001 A.8.4: Access to Source Code
ISO 27001 A.8.4 requires that read and write access to source code, development tools, and software libraries is restricted to what a person needs...
ISO 27001 A.8.28: Secure Coding
To satisfy ISO 27001 A.8.28, apply secure coding principles to how your team writes software: adopt language-specific coding standards, plan security...
ISO 27001 A.8.25: Secure Development Life Cycle
To satisfy ISO 27001 A.8.25, write down the rules that govern how your team builds software, then apply them consistently across the whole life...
ISO 27001 A.8.24: Use of Cryptography
ISO 27001 A.8.24 requires a policy on the use of cryptography, including key management, applied according to risk rather than encrypting everything...
ISO 27001 A.8.13: Information Backup
ISO 27001 A.8.13 requires that backup copies of information, software, and systems are maintained and tested against an agreed backup policy. It is a...
ISO 27001 A.8.7: Protection Against Malware
ISO 27001 A.8.7 requires that protection against malware is implemented and backed by appropriate user awareness across every system that runs code....
ISO 27001 A.8.9: Configuration Management
To satisfy ISO 27001 A.8.9, define a secure configuration baseline for your hardware, software, services, and networks, document every deviation from...
ISO 27001 A.8.8: Management of Technical Vulnerabilities
ISO 27001 A.8.8 requires that an organization obtain information about the technical vulnerabilities in the systems it uses, assess its exposure to...
ISO 27001 A.8.16: Monitoring Activities
ISO 27001 A.8.16 requires that networks, systems, and applications are monitored for anomalous behavior and that potential security incidents are...
ISO 27001 A.8.15: Logging
ISO 27001 A.8.15 requires an organization to produce, store, protect, and review logs that record activities, exceptions, faults, and security...
ISO 27001 A.8.5: Secure Authentication
ISO 27001 A.8.5 requires that secure authentication technologies and procedures are implemented based on how sensitive the information and system...
ISO 27001 A.5.15: Access Control
ISO 27001 A.5.15 requires an organization to establish and maintain an access control policy that governs who may reach information and systems,...
ISO 27001 A.5.24: Information Security Incident Management Planning and Preparation
ISO 27001 A.5.24 requires an organization to plan and prepare for security incidents before they happen: define the roles, the response process, the...


























