Browse the Learning Center
Email infrastructure
DNS, MX, MTA-STS, BIMI, and the routes mail relies on.
50 guides
Read in order
All Email infrastructure guides
ESMTPS: What It Means in an Email HeaderESMTPS in an email header means ESMTP crossed a TLS-protected hop. Learn how it differs from ESMTP, ESMTPSA, STARTTLS, and implicit TLS connections.
Valid Characters for an Email AddressValid characters for an email address are letters, digits, and punctuation such as ! # $ % & ' * + - _ in the local part, with dots only between them.
Reverse DNS and email spam: what PTR checks really meanReverse DNS email spam checks use PTR records as one sender signal. Learn what Google requires, what receivers may do, and how to validate it.
Valimail BIMI checker: what you can verifyValimail BIMI checker guidance: confirm the available product scope, check public BIMI DNS evidence, and separate it from message and mailbox results.
Analyze email headers onlineAnalyze email headers online by separating message evidence from DNS and MX checks, then use the right source for routing and transport issues.
BIMI logo checker: check and interpret your BIMI recordBIMI logo checker guide: check a domain's BIMI record, interpret Palisade results, repair DMARC enforcement or record issues, and retest now.
DMARC MX tools: check the right DNS recordDMARC MX tools separate DMARC TXT-record checks from MX routing checks, so you can repair the right DNS record, verify public DNS, and retest it.
Email reverse DNS best practicesEmail reverse DNS best practices: set a PTR for every sending IP, confirm forward DNS, match EHLO, and recheck after IP changes for production senders.
Email reverse DNS checkEmail reverse DNS check: look up an email server's PTR record, confirm its forward DNS, and interpret iprev results for Gmail compliance today.
Email reverse DNS lookup: check and interpret a PTR recordEmail reverse DNS lookup: check an SMTP sending IP's PTR record, confirm forward DNS, interpret results, and retest the mail path for reliable mail.
How does reverse DNS work for email?How does reverse DNS work for email? Learn how PTR records map sending IP addresses to hostnames, and how forward confirmation works for email delivery.
MXToolbox DMARC monitoring: check, interpret, and retestMXToolbox DMARC monitoring starts with a DNS check. Learn what a result can show, when to investigate further, and how to retest safely today.
Reverse DNS for email serverReverse DNS for email server setup requires the IP owner to publish a PTR record and a matching forward DNS record for the sending hostname.
Reverse DNS lookup email validationReverse DNS lookup email validation checks whether an IP address has a PTR hostname. Learn what PTR results show and what they cannot validate.
SMTP and POP3 difference: sending versus retrieving emailSMTP and POP3 difference: SMTP sends and relays email, while POP3 retrieves messages from a server to a client mailbox.
Why is my BIMI SVG format causing logo issues?Why BIMI SVG format causes logo issues: check the public SVG Tiny PS asset, BIMI DNS record, certificate status, and delivered-message evidence.
How do you fix 'Reverse DNS does not match SMTP banner'?Reverse DNS does not match SMTP banner means the tested server greeting and PTR hostname differ. Compare the route, repair the owning layer, and retest.
How can I create a DMARC record in DNS with Palisade?Create a DMARC record in DNS with Palisade, publish the correct TXT value, check the public record, and safely validate real sender alignment.
How do I fix the 'SPF PermError: too many DNS lookups' error?SPF PermError: too many DNS lookups means SPF exceeded its 10-term DNS limit. Map the lookup chain, remove or separate senders, then retest.
RFC 5321.MailFrom vs RFC 5322.From: what's the difference?RFC 5321.MailFrom vs RFC 5322.From: learn how SMTP envelope and visible header identities differ, how SPF checks them, and how DMARC alignment works.
What is a PTR record and how does reverse DNS use it?PTR records map an IP address to a hostname. Learn how reverse DNS works, validate forward confirmation, and troubleshoot email sending IPs.
How long does DNS propagation take for email records?DNS changes take effect as cached copies expire, not on a fixed timer. What TTL controls for MX, SPF, DKIM and DMARC, and how to verify a change landed.
DNS TXT SPF record: what it is and how it worksAn SPF policy is published in DNS as a TXT record starting with v=spf1. Learn the record format, size limits, and how to check if your domain has one.
What is a DNS changer? Speed, privacy and securityWhat is a DNS changer? It switches the DNS resolver your device uses, which can affect lookup speed, query privacy, and DNS filtering in practice.
How does DNS poisoning work and how can teams defend against it?DNS poisoning works when a resolver caches a forged DNS answer. Learn how cache poisoning redirects users and how to validate and defend DNS.
SMTP vs IMAP vs POP3: what's the difference?SMTP vs IMAP vs POP3: SMTP sends mail, while IMAP syncs server mail and POP3 downloads it. Learn the secure ports and validation steps clearly.
What is an AAAA DNS record (Quad-A explained)?AAAA DNS records map host names to IPv6 addresses. Learn the Quad-A record format, when to publish it, and how to validate IPv6 DNS for services.
What is MTA-STS and how does it secure SMTP with TLS?MTA-STS is an SMTP transport policy that requires supporting senders to use authenticated TLS with a domain's authorized MX hosts. Learn how to deploy it.
Difference between IMAP and SMTPIMAP retrieves and manages mail stored on a server; SMTP transfers and submits outgoing mail between systems, per RFC 9051, RFC 5321, and RFC 6409.
How can DNS poisoning redirect traffic and what stops it?DNS poisoning redirects traffic by causing a resolver to return a false DNS answer. Learn how DNSSEC, resolver controls, and validation reduce the risk.
What DNS records does a business email domain need?DNS records for business email include MX for receiving mail, plus SPF, DKIM, and DMARC to authenticate the domain's outgoing messages and DMARC policy.
How can retail brands use BIMI to boost email open rates?BIMI can help retail brands make authenticated email easier to recognize. Learn the requirements, rollout checks, and how to measure open-rate impact.
What is a CNAME record and how do DNS aliases work?CNAME record explained: learn how DNS aliases work, why they cannot share a name, when email systems reject them, and how to validate a target.
What is a TXT record? DNS text records explainedTXT records store DNS text used for SPF, DKIM, DMARC, verification, and other domain policies. Learn their format, limits, validation, and uses.
What is an email header?What is an email header? Learn what message headers show, how Received and Authentication-Results work, and how to validate a delivered email.
MXToolbox DMARC: how to interpret a public record lookupMXToolbox DMARC lookup results show a public DNS policy record, not message delivery. Learn how to interpret, verify, and retest them for your domain.
End to End Encryption Email Services: How to ChooseCompare end to end encryption email services by recipient workflow, metadata exposure, interoperability, and operational fit.
MxToolbox email deliverability tool: read the reportSend a test message to MxToolbox, open the email deliverability report, interpret its message-path evidence, choose the next check, and retest.
What does no MX record found mean in a bounce?No MX record found in a bounce can mean no usable mail route, a null MX, DNS failure, or a bad address. Diagnose the DNS result and retest safely.
Why is Google sending MTA-STS TLS reports to my domain?Google MTA-STS TLS reports explain SMTP TLS delivery results for your domain, the policy Google found, failures, and a safe validation workflow.
Active vs passive monitoring: what's the difference?Active vs passive monitoring: active sends synthetic test traffic; passive watches real traffic already flowing. Learn the difference and when to use each.
Mailgun SPF and DKIM Setup: Exact DNS RecordsSet up Mailgun SPF and DKIM with the exact DNS records. Learn when to use DKIM CNAMEs, why send-only domains skip Mailgun MX, and how to verify alignment.
How does POP3 work and why should security teams care?How POP3 works step by step, why its download-and-delete model creates security gaps, and how MSPs can lock down or retire legacy mail clients.
How Gmail’s Blue Verified Checkmarks Affect BIMI AdoptionEmail authentication protocols like SPF, DKIM, and DMARC have become standard practice for protecting brand reputation, but many organizations still…
What is an A record and how does DNS use it for web and email?An A record is a DNS record that maps a domain name to an IPv4 address. DNS uses it to find a website's server, and MX records rely on it for mail hosts.
What is an MUA? Mail User Agents Explained SimplyAn MUA is a mail user agent, the email client you read and write in. It sends over SMTP, fetches over IMAP or POP, and renders the messages you receive.
What is a VMC? Verified Mark Certificates for BIMIA Verified Mark Certificate (VMC) proves logo ownership so BIMI can display your brand in Gmail and Yahoo inboxes. What it requires, costs, and how to get one.
What is DNS and how does the Domain Name System work?DNS is the Domain Name System, the internet's address book. It maps names to IP addresses and carries the TXT records holding SPF, DKIM, and DMARC values.
What is an MX Record? Mail Exchange DNS ExplainedWhat an MX record is, how mail servers use priority to route email, the exact records for Google Workspace and Microsoft 365, and how to check yours.
What is BIMI and how do Brand Indicators for Message Identification work?BIMI is an email standard that lets supporting inboxes display a verified brand logo after DMARC authentication and receiver checks for supported senders.