Use code WIKI25 at checkout for 25% off · Free sample
The Email Decoded Blog

Notes from the header trenches

This blog covers the parts of email infrastructure that most guides skip past — the actual headers, the specific RFC mechanics, and the forensic reasoning behind a real authentication failure or a real phishing attempt. Expect deep dives into SPF, DKIM, and DMARC (including the 2026 RFC 9989/9990/9991 split), MIME structure, header-based investigation techniques, and the kind of edge cases — lookalike domains, Reply-To hijacking, ARC chain trust gaps — that only show up once you've read enough real headers to know what normal looks like. Written for sysadmins, security engineers, and developers who want the mechanics, not just the summary.