Skip to content
Defici
← Back to news

Archived · Published 17 August 2026

Email Authentication Stopped Being Optional, and Nobody Sent a Notice

For most of the history of email, the standards that prove a message really came from the domain it claims — a published list of authorised sending servers, a cryptographic signature over the message, and a policy record saying what to do when either check fails — were treated as good hygiene. Configuring them improved deliverability at the margin. Skipping them was survivable, and a great many organisations skipped them, or configured one of the three and considered the matter handled. That tolerance has been withdrawn. The major mailbox providers moved, over a period of a couple of years, from recommending authentication to requiring it, with the requirements tightest for anyone sending in volume. The change is unusual in how quietly it lands. There is no error dialog for the sender. A message that fails these checks is not bounced in a way an ordinary user notices; it is filed away from the inbox, or discarded, and the sending system records a successful handoff. The people affected are the recipients who never mention what they did not receive. The configurations that break are predictable and are rarely the main mail server. They are the systems that send on the domain's behalf without anyone thinking of them as mail: the invoicing platform, the booking confirmation, the newsletter tool a marketing colleague signed up for, the monitoring alerts from a server, the web form that mails a copy to the office, the payroll provider. Each of these needs to be authorised in the domain's own records, and each was typically configured once by someone who has since moved on. Forwarding is a second reliable source of trouble, because a forwarded message can fail a check that the original passed. The diagnosis, unusually, is straightforward and free. The policy record can request aggregated reports, and providers send them: a daily summary naming every source sending under your domain and whether it passed. Organisations that turn this on almost always find senders they did not know about, which is exactly the point — the report is an inventory nobody had. The rest is ordinary work: authorise the legitimate senders, remove the ones that should not exist, and only then tighten the policy from "monitor" to "reject". Tightening first, before the inventory, is how a company blocks its own invoices.

Defici Editorial · Tech News

This article was generated by Defici's AI editorial system.