Backscatter: The Bounces You Never Sent
When spammers forge your domain as their envelope sender, the bounces come to you. What backscatter is, why it happens, and how to stop causing and receiving it.
Deep dives into communication security, including encryption protocols, authentication systems, phishing prevention, spam protection, fraud mitigation, secure messaging infrastructure, and the technologies protecting digital communication networks.
When spammers forge your domain as their envelope sender, the bounces come to you. What backscatter is, why it happens, and how to stop causing and receiving it.
Every email trust decision resolves through DNS, and DNSSEC is what makes those answers tamper-proof. What it buys email, what DANE requires, and safe operations.
The NIS2 directive makes email authentication and transport security a regulatory matter for thousands of EU organizations. What it requires and where email fits.
TLS-RPT delivers daily JSON reports on every failed TLS negotiation to your domain. The record, the report format, and how to turn failures into fixes.
MTA-STS closes the STARTTLS downgrade hole by letting domains require verified TLS for inbound mail. The policy file, the DNS record, and the gotchas in between.
A DKIM signature stays valid no matter who forwards the message. How replay attacks abuse that property to spend your reputation, and the defenses that limit the damage.
Spam traps are addresses that never belonged on your list. The types, who operates them, how they end up in your database, and the hygiene that keeps them out.

How to remove your IP or domain from Spamhaus, SORBS, UCEPROTECT, and other blocklists. Which lists matter, which to ignore, and the delisting process for each.

How to rotate DKIM keys in production without breaking signatures. Dual-selector strategy, 2048-bit key sizes, and the rotation cadence that actually works.