Daily DMARC News
  • Home
  • Posts
  • Excello Mail ↗
  • EN
  • ES
  • PT

All Posts

Every post we’ve published — newest first.

News on this site is aggregated and summarized automatically from public industry sources. Occasional inaccuracies are possible and always unintentional — if you spot one, we’ll gladly correct or remove it. Report an issue.

  • July 26, 2026 5 min read

    One Preview, 90 Days of Mail: Russia's LAUNDRY BEAR Exploits a Zimbra Bug DMARC Cannot See

    CISA, the NSA, the FBI, and cybersecurity agencies from more than a dozen allied nations, including the Netherlands, the UK, Australia, and Canada, issued a joint advisory this week exposing an active campaign by LAUNDRY …

  • July 25, 2026 6 min read

    Washington Cut CEMA Damages by 80%. The Class Action Wave Against Email Marketers Has Not Slowed Down.

    In May we covered the wave of class action lawsuits filed under Washington’s Commercial Electronic Mail Act, or CEMA, after the state Supreme Court’s decision in Brown v. Old Navy held that the law’s …

  • July 24, 2026 4 min read

    Financial Institutions Lead DMARC Adoption. They Are Still the Number One Phishing Target.

    PowerDMARC’s United States DMARC & MTA-STS Adoption Report 2026, drawn from more than 900 domains across major industries, put national DMARC adoption at 95.8% and national DMARC enforcement, a policy of …

  • July 23, 2026 5 min read

    Operation Olympus Blade Took Down Kratos. 1,800 Customers Ran 15,000 Phishing Campaigns a Month With It.

    Germany’s Federal Criminal Police Office and the Frankfurt public prosecutor’s cybercrime unit, working alongside the FBI’s Dallas Field Office and the US Attorney’s Office for the Northern …

  • July 22, 2026 5 min read

    Cracking a DKIM Key Costs $8. Six Mailbox Providers Still Accept Ones That Weak.

    DKIM is the part of email authentication that proves a message was not altered in transit and really was signed by the domain it claims to come from. That guarantee is only as strong as the key doing the signing and the …

  • July 21, 2026 4 min read

    Check Point Found 3,200 Copies of One Job Scam. Every Single One Passed DMARC.

    Check Point Research recently disclosed a phishing campaign that did not need a single fake domain, a spoofed sender, or a cloned login page to work. Researchers found more than 3,200 copies of the same message: a summer …

  • July 20, 2026 5 min read

    Netcraft Found 70 Bluekit Phishing Sites in One Week. None of Them Proxy Your Login. That Is the Point.

    Bluekit is not a new name. Varonis Threat Labs first documented the phishing-as-a-service kit in April 2026, cataloguing an AI assistant built on jailbroken language models, more than 40 templates spoofing brands from …

  • July 19, 2026 4 min read

    LastPass and Bitwarden Users Are Being Phished by Domains DMARC Was Never Built to Stop

    On July 13, 2026, LastPass’s Threat Intelligence, Mitigation, and Escalation team flagged an active phishing campaign built around two freshly registered domains, lastpassnewsletter.com and lastpasscompliance.com. …

  • July 18, 2026 5 min read

    Fake Recruiter Phishing Ring Impersonates 34 Brands and Hides Behind Legitimate SaaS Redirects to Steal Google Logins

    Will Thomas, a senior advisor at the threat intelligence firm Team Cymru, has spent the past several weeks pulling apart a phishing operation that has been running for at least five months without much attention. The …

  • July 17, 2026 5 min read

    GMX, WEB.DE and mail.com Start Rejecting DMARC Failures at the SMTP Level, While Half a Million Domains Still Have the Alarm Switched Off

    The postmaster team at 1&1 Mail & Media, the company behind GMX, WEB.DE and mail.com, told the mailop mailing list this quarter that it is rolling out full inbound DMARC enforcement across its infrastructure, …

  • July 16, 2026 5 min read

    Ghost Phishing: EvilTokens Hides Malicious Pages Behind Encrypted HTML Until Your Browser Decrypts Them

    Researchers at ANY.RUN have spent the past several weeks documenting a phishing kit called EvilTokens, active since at least February 2026 and sold through Telegram channels, that hides its Microsoft 365 credential-theft …

  • July 15, 2026 5 min read

    CVE-2026-45185 'Dead.Letter': One Stray Byte Gives an Attacker Root on Your Mail Server

    Researchers at XBOW disclosed a critical vulnerability in Exim, nicknamed Dead.Letter and tracked as CVE-2026-45185, that lets an unauthenticated attacker execute arbitrary code on a mail server by sending a single stray …

  • ««
  • «
  • 3
  • 4
  • 5
  • 6
  • 7
  • »
  • »»
Daily DMARC News

Daily news, analysis, and guidance on DMARC and email security.

Explore

  • Home
  • All posts
  • RSS feed

From the team

  • Excello Mail ↗
  • About
  • Contact
© 2026 Daily DMARC News. All rights reserved. From the team at Excello Mail.