Alex Shakhov

Email Security & Deliverability | Founder at SH Consulting

Crafting secure email systems and optimizing deliverability while sharing insights on security and infrastructure.

2025
Backscatter Injection Attacks Exploiting Legitimate Infrastructure

Attackers use backscatter emails to bypass filters, harming servers and delivering phishing content.

Backscatter Injection Attacks Exploiting Legitimate Infrastructure
When Marketing and Engineering Disconnect at ChatGPT

Billing emails failed due to template errors, highlighting coordination gaps between marketing and engineering.

When Marketing and Engineering Disconnect at ChatGPT
The Risks of Abruptly Enforcing DMARC p=reject in Organizations

Sudden DMARC enforcement can disrupt workflows, block emails, and impact organizational operations significantly.

The Risks of Abruptly Enforcing DMARC p=reject in Organizations
How a Fake Bank Transfer Email Nearly Fooled Me

Spoofed emails can mimic trusted senders, highlighting risks in elementary school communications.

How a Fake Bank Transfer Email Nearly Fooled Me
Why Emails Should Have Expiration Dates to Reduce Carbon Footprint

Auto-deleting outdated emails could cut storage, energy use, and environmental impact from email systems.

Why Emails Should Have Expiration Dates to Reduce Carbon Footprint
Microsoft 365 Groups Bypass DMARC, Exposing Organizations to Spoofing

Microsoft 365 groups can deliver spoofed emails despite failing SPF, DKIM, and enforced DMARC policies.

Microsoft 365 Groups Bypass DMARC, Exposing Organizations to Spoofing
Why Subdomain DMARC Policies Are Often Unnecessary

Proper DMARC enforcement on the root domain protects non-existent subdomains without needing separate policies.

Why Subdomain DMARC Policies Are Often Unnecessary
Why Regular Password Changes Still Matter in Real Cybersecurity

Even with MFA, forced password resets help contain breaches and limit ongoing attacker access.

Why Regular Password Changes Still Matter in Real Cybersecurity
The Power of Personal Touch in Client Deliveries

Physical gifts from clients create lasting impact beyond digital connections and virtual meetings.

The Power of Personal Touch in Client Deliveries
Why Reusing Passwords Is Dangerous: The JustDropped Example

Reusing passwords puts accounts at risk, as some platforms store and email credentials in plaintext.

Why Reusing Passwords Is Dangerous: The JustDropped Example
Cloudflare Outage Disrupts Multiple Services Including ChatGPT

Cloudflare downtime affects ChatGPT, Klaviyo, and other services, impacting user experience and trust.

Cloudflare Outage Disrupts Multiple Services Including ChatGPT
Why Personal Style Matters in Business Calls

Your appearance on calls influences impressions, recall, and the speed of business opportunities.

Why Personal Style Matters in Business Calls
Unexpected DMARC Reports Flood emvdmarc[.]com After Domain Acquisition

New domain emvdmarc[.]com receives DMARC reports from random organizations, creating unexpected security concerns.

Unexpected DMARC Reports Flood emvdmarc[.]com After Domain Acquisition
The Challenges of Enforcing DMARC p=reject in Modern Email Infrastructure

Implementing DMARC p=reject stops spoofing but often clashes with business workflows and new systems.

The Challenges of Enforcing DMARC p=reject in Modern Email Infrastructure
How SaaS Platforms in Real Estate Enable Spam and Phishing

Architectural flaws in real estate SaaS platforms allow phishing campaigns through trusted email infrastructure.

How SaaS Platforms in Real Estate Enable Spam and Phishing
Phishing Attacks Highlight Need for Mandatory Email Security Training

Employees lacking phishing awareness risk credential compromise, even from fully authenticated DKIM/SPF emails.

Phishing Attacks Highlight Need for Mandatory Email Security Training
Why Security and Deliverability Professionals Stand Out on LinkedIn

True security experts connect without pitching, unlike spammers who turn networking into product promotion.

Why Security and Deliverability Professionals Stand Out on LinkedIn
How a DMARC Misconfiguration Exposed Sensitive Email Data

Neglected DMARC reporting addresses can leak internal email infrastructure and sensitive organizational information.

How a DMARC Misconfiguration Exposed Sensitive Email Data
Phishing Alert: Netflix Subscription Cancellation Scams on the Rise

Scammers exploit lookalike domains to send fake Netflix cancellation emails targeting unsuspecting users.

Phishing Alert: Netflix Subscription Cancellation Scams on the Rise
Why Google Removed the IP Reputation Graph from Postmaster Tools

Removal limits visibility into ESP/CRM health, making it harder to monitor email deliverability risks.

Why Google Removed the IP Reputation Graph from Postmaster Tools
How Misconfigured DMARC Can Enable Email-Based DoS Attacks

Wildcard EDV misconfigurations let attackers flood inboxes with DMARC reports, disrupting email flow.

How Misconfigured DMARC Can Enable Email-Based DoS Attacks
Mailchimp SPF Misconfigurations Can Expose Domains to Spoofing

Including Mailchimp IPs in root SPF unnecessarily exposes domains to spoofing despite strict DMARC policies.

Mailchimp SPF Misconfigurations Can Expose Domains to Spoofing
Google Postmaster v1 Deprecation: Impact on Email Deliverability and Security

Google Postmaster v1 is ending, reducing visibility into domain/IP reputation for email deliverability.

Google Postmaster v1 Deprecation: Impact on Email Deliverability and Security
Massive Phishing Campaign Targets Yahoo Using Client’s Domain

Over 72,000 phishing emails exploited a past client’s domain, bypassing DMARC monitoring protections.

Massive Phishing Campaign Targets Yahoo Using Client’s Domain
How to Properly Add New Domains in Google Workspace

Use domain aliases in Google Workspace to simplify email management and avoid multiple organizations.

How to Properly Add New Domains in Google Workspace
How Threat Actors Exploit Redirect Chains to Bypass Spam Filters

Phishing attacks use legitimate infrastructure and redirects to obfuscate URLs and steal credentials.

How Threat Actors Exploit Redirect Chains to Bypass Spam Filters
Why GoDaddy’s Enforced DMARC Policies Raise Serious Security and Privacy Concerns

Registrar-enforced DMARC breaks email delivery and exposes sensitive reporting data to third parties.

Why GoDaddy’s Enforced DMARC Policies Raise Serious Security and Privacy Concerns
Expanding From Real Estate to Enterprise Email Security and Deliverability

Started in real estate; now offering email security and deliverability services across all industries.

Expanding From Real Estate to Enterprise Email Security and Deliverability
Why Enforcing Broken DMARC Models Harms Email Security and Deliverability

Forced DMARC subdomain records break standards, hide reports, and weaken customer email security visibility.

Why Enforcing Broken DMARC Models Harms Email Security and Deliverability
Why Downgrading DMARC Policies Puts Brands at Risk

Downgrading DMARC from reject to none enables spoofing and increases phishing exposure.

Why Downgrading DMARC Policies Puts Brands at Risk
Office 365 “Send Mail As” Issues with Proofpoint and Gmail

Gmail Send Mail As fails with Office 365 and Proofpoint despite SMTP, MFA, and credentials configured.

Office 365 “Send Mail As” Issues with Proofpoint and Gmail
Why Email Warm-Up Is Critical for Deliverability

Sending large volumes without warming up can damage sender reputation and trigger spam filtering.

Why Email Warm-Up Is Critical for Deliverability
Shared ChatGPT Links Can Expose Sensitive Data

Public ChatGPT links can unintentionally expose credentials, internal data, and confidential company information.

Shared ChatGPT Links Can Expose Sensitive Data
Phishing via Compromised SendGrid Accounts Bypasses Traditional Authentication

Compromised SendGrid credentials enable phishing emails to pass authentication and impersonate trusted organizations.

Phishing via Compromised SendGrid Accounts Bypasses Traditional Authentication
Why “Low-Volume” Spoofing Is Still a Serious Risk

Even minimal spoofing activity can enable targeted phishing and serious security incidents.

Why “Low-Volume” Spoofing Is Still a Serious Risk
Why DMARC Reports Don’t Always Reveal Spoofing Activity

Lack of DMARC report coverage hides phishing attempts, leaving business emails vulnerable to threat actors.

Why DMARC Reports Don’t Always Reveal Spoofing Activity
Why “Spam Trigger Words” Don’t Actually Exist

Modern spam filtering relies on behavior and reputation, not simple keyword detection or outdated trigger-word myths.

Why “Spam Trigger Words” Don’t Actually Exist
Why Email Deliverability Complexity Can Be an Advantage

Complex email deliverability creates opportunities to outsmart competitors using advanced strategies and best practices.

Why Email Deliverability Complexity Can Be an Advantage
Why Sudden Newsletter Volume Spikes Damage Deliverability

Large, sudden email sends trigger spam filters and quickly damage sender and domain reputation.

Why Sudden Newsletter Volume Spikes Damage Deliverability
Why Google Groups Can Be a Security Risk for Shared Emails

Using Google Groups for shared inboxes can expose teams to phishing and security risks.

Why Google Groups Can Be a Security Risk for Shared Emails
How a Single DMARC Misconfiguration Can Trigger an Email-Based DDoS

Wildcard DMARC EDV records can be exploited, flooding mailboxes with thousands of legitimate-looking reports.

How a Single DMARC Misconfiguration Can Trigger an Email-Based DDoS
We’re Hiring Remote Email Deliverability Specialists

We’re hiring remote email deliverability specialists to support enterprise clients and large-scale sending programs.

We’re Hiring Remote Email Deliverability Specialists
Invalid DMARC RUA Addresses Should Be Penalized

Invalid DMARC RUA addresses harm reporting infrastructure and signal negligence toward email security standards.

Invalid DMARC RUA Addresses Should Be Penalized
Phishing Attempt Exploits Server Without SPF or DMARC

Phishing attack on vertigo360.me highlights risks when SPF and DMARC policies are missing.

Phishing Attempt Exploits Server Without SPF or DMARC
Choose the Right Domain to Improve Email Deliverability

Selecting the correct domain and TLD is crucial for avoiding spam filters and improving deliverability.

Choose the Right Domain to Improve Email Deliverability
DMARC and Deliverability Challenges with Real Estate ESPs

Using wildcard DMARC policies without SPF support can negatively impact email deliverability and client trust.

DMARC and Deliverability Challenges with Real Estate ESPs
Client Ignoring Evidence of Targeted Spoofing Attacks

A client under spoofing attack refuses to enforce DMARC despite clear phishing evidence.

Client Ignoring Evidence of Targeted Spoofing Attacks
Google Postmaster Updates Spam Complaint Visualization

New Google Postmaster graph helps monitor spam complaints, keeping email campaigns under compliance thresholds.

Google Postmaster Updates Spam Complaint Visualization
DMARC Reject Blocks Spoofing Attempt on Personal Domain

Strict DMARC policy prevented a spoofing attack, protecting domain despite spam filter bypass.

DMARC Reject Blocks Spoofing Attempt on Personal Domain
Yahoo CFL Domains Not Recognized by Mailchimp Spam Reports

Some Yahoo-owned domains bypass Mailchimp spam report recognition, leaving unsubscribed users active.

Yahoo CFL Domains Not Recognized by Mailchimp Spam Reports
Why Top-Level Domains Still Matter for Email Deliverability

Top level domain choice significantly impacts email deliverability and spam filtering outcomes for marketing campaigns.

Why Top-Level Domains Still Matter for Email Deliverability
Email Security and Deliverability Take Center Stage in Real Estate

The real estate community is embracing email security and deliverability as essential modern business practices.

Email Security and Deliverability Take Center Stage in Real Estate
Casual Industry Dinner with Luke Martinez and Lauren Meyer

Unforgettable evening with top email deliverability experts filled with conversation, laughs, and great food.

Casual Industry Dinner with Luke Martinez and Lauren Meyer
Office 365 SMTP Issues with Proofpoint and Gmail Send Mail As

Office 365 emails fail sending via Gmail Send Mail As despite SMTP, Proofpoint, and authentication settings enabled.

Office 365 SMTP Issues with Proofpoint and Gmail Send Mail As
New SendGrid Dedicated IP Immediately Listed on DNS Blacklists

Dedicated SendGrid IPs appearing on multiple DNSBLs can hurt email deliverability and sender reputation.

New SendGrid Dedicated IP Immediately Listed on DNS Blacklists
Analyzing Google Postmaster: Unexpected Spam Report Spikes

Google Postmaster graphs sometimes show high spam rates despite low email traffic or legitimate messages.

Analyzing Google Postmaster: Unexpected Spam Report Spikes
SendGrid 2FA Issue Locks Access to 50+ Client Accounts

2FA verification failures locked multiple accounts, halting business operations for over 36 hours.

SendGrid 2FA Issue Locks Access to 50+ Client Accounts
Hiring: Email Implementation Specialist for DNS & Deliverability

Join SH Consulting to manage email implementation, DNS zones, and client deliverability workflows.

Hiring: Email Implementation Specialist for DNS & Deliverability
Is External Destination Verification Required for DMARC Reporting?

EDV records appear optional since DMARC reports often send successfully without explicit external destination verification.

Is External Destination Verification Required for DMARC Reporting?
Protect Your Domain and Emails When Switching IDX Providers

Always export your DNS zone to prevent service disruptions and protect email and domain security.

Protect Your Domain and Emails When Switching IDX Providers
DMARC p=reject Reduces Spoofing, But Doesn’t Guarantee Full Protection

Even with p=reject, some email servers may still accept spoofed messages, creating residual risks.

DMARC p=reject Reduces Spoofing, But Doesn’t Guarantee Full Protection
When Gradual Sending Doesn’t Prevent Spam Folder Placement

Even with careful guidance, emails can still land in spam without proper authentication and monitoring.

When Gradual Sending Doesn’t Prevent Spam Folder Placement
Monthly Database Cleanup: Boost Email Deliverability

Remove spam traps, throwaway accounts, and low-quality leads to improve email deliverability.

Monthly Database Cleanup: Boost Email Deliverability
Mailchimp Auto-DKIM Can Overwrite Strict DMARC Policies

Mailchimp’s auto-DKIM setup may replace strict DMARC, exposing domains to spoofing and phishing attacks.

Mailchimp Auto-DKIM Can Overwrite Strict DMARC Policies
CRM Email Rejections Caused by Missing DKIM and DMARC Settings

Emails bounced in CRM due to missing DKIM signatures and strict DMARC reject policy.

CRM Email Rejections Caused by Missing DKIM and DMARC Settings
Why Email Templates Must Stay Under 102KB

Oversized email templates risk clipping, broken tracking, compliance issues, and reduced inbox placement across providers.

Why Email Templates Must Stay Under 102KB
Suspicious Google Calendar Emails Trigger DMARC Failures

Attackers exploited Google Calendar to send phishing emails, causing DMARC failures for Yahoo recipients.

Suspicious Google Calendar Emails Trigger DMARC Failures
Namecheap DNS TTL Limit Creates Microsoft DKIM Challenges

Namecheap’s TTL limit affects DKIM validation, risking spam filtering and degraded email deliverability.

Namecheap DNS TTL Limit Creates Microsoft DKIM Challenges
Google/Yahoo Email Regulations: Prepare DKIM, SPF, and DMARC Compliance

Non-compliant emails face gradual rejection; ensure DKIM, SPF, and DMARC are properly configured.

Google/Yahoo Email Regulations: Prepare DKIM, SPF, and DMARC Compliance
Polish Museum Chooses 63-Character Domain – And Yes, They’ve Got Email

Museum of Professional Miniature Art in Poland uses a 63-character domain for branding.

Polish Museum Chooses 63-Character Domain – And Yes, They’ve Got Email
Microsoft DMARC Reports Expose Recipient Domains – A Critical Risk

Microsoft DMARC aggregate reports reveal recipient domains, creating insider threats and increasing phishing risk.

Microsoft DMARC Reports Expose Recipient Domains – A Critical Risk
Microsoft Begins Rejecting Emails Without Proper Authentication

Outlook now bounces unauthenticated emails; ensure SPF, DKIM, and DMARC are correctly configured.

Microsoft Begins Rejecting Emails Without Proper Authentication
Unauthorized DNS Changes Suggest Possible GoDaddy Issue

Unexpected SPF and CNAME modifications bypassed DMARC, raising concerns about domain security with GoDaddy.

Unauthorized DNS Changes Suggest Possible GoDaddy Issue
Consistent Deliverability Maximizes Results, Even on Basic Plans

Maintaining strong sending practices ensures top-tier reputation and excellent inbox placement for all campaigns.

Consistent Deliverability Maximizes Results, Even on Basic Plans
Why Ignoring Email Deliverability Can Ruin Your Marketing ROI

Ads fail if emails go to spam; reaching the inbox is crucial for engagement.

Why Ignoring Email Deliverability Can Ruin Your Marketing ROI
Targeted Phishing Exploits Real-Time Delivery Data at Major Logistics Company

Precision phishing leveraged live DPD delivery data, exposing potential system-level breaches and GDPR risks.

Targeted Phishing Exploits Real-Time Delivery Data at Major Logistics Company
Why Email Security and Compliance Matter More Than Authentication

Domain authentication alone doesn’t guarantee deliverability; security and compliance are critical for email success.

Why Email Security and Compliance Matter More Than Authentication
Google DMARC Reports Stopped Since April 13

Google has ceased sending DMARC reports, creating blind spots for email security monitoring.

Google DMARC Reports Stopped Since April 13
GoDaddy Sign-In Issues Affecting Multiple Accounts

Delegated access accounts impacted as GoDaddy redirects signed-in users to 404 errors today.

GoDaddy Sign-In Issues Affecting Multiple Accounts
First Look at Google Postmaster — What You Should Do

Connecting Google Postmaster reveals email issues; prompt action is crucial to protect deliverability.

First Look at Google Postmaster — What You Should Do
Mailchimp Newsletter Blocked Despite Strict DMARC Policy

p=reject DMARC blocked Mailchimp emails due to DKIM failures, despite unchanged DNS and Cloudflare settings.

Mailchimp Newsletter Blocked Despite Strict DMARC Policy
Hidden SPF Abuse via Look-Alike SendGrid Domain

A typo-based SPF include exposed how look-alike domains can bypass security.

Hidden SPF Abuse via Look-Alike SendGrid Domain
Why Some Domains Are Heavily Spoofed While Others Are Safe

Spoofing targets depend on domain exposure, authentication gaps, and automation—not company size or staff count.

Why Some Domains Are Heavily Spoofed While Others Are Safe
Yahoo Rejecting Forwarded Emails Due to Authentication Failures

Yahoo appears to reject forwarded emails due to authentication and header modification issues.

Yahoo Rejecting Forwarded Emails Due to Authentication Failures
Google & Yahoo Email Regulations — June 1 Compliance Deadline

June 1 marks strict enforcement of Google and Yahoo email authentication requirements for senders.

Google & Yahoo Email Regulations — June 1 Compliance Deadline
How a Rare 3-Character Domain Exposes the Reality of Email Spoofing

Even small, lightly-used domains can be exploited for spoofing, phishing, and scams without owner knowledge.

How a Rare 3-Character Domain Exposes the Reality of Email Spoofing
Avoid Homoglyphs in HTML to Prevent Email Spam Issues

Ensure email HTML templates avoid homoglyphs to prevent spam filters blocking legitimate marketing emails.

Avoid Homoglyphs in HTML to Prevent Email Spam Issues
Spoofed AppSheet Email Highlights Limits of DKIM, SPF, and DMARC

Threat actors abused AppSheet to send phishing emails that passed DKIM and DMARC checks.

Spoofed AppSheet Email Highlights Limits of DKIM, SPF, and DMARC
Why Email Open Rates and Click-Through Rates Can Be Misleading

Open and click rates don’t always reflect true engagement—manual replies tell the real story.

Why Email Open Rates and Click-Through Rates Can Be Misleading
SH Consulting Partners with Ylopo to Enhance Email Deliverability

SH Consulting teams with Ylopo to ensure emails reach inboxes with security and precision.

SH Consulting Partners with Ylopo to Enhance Email Deliverability
When not into email security - out on the golf course.

When not into email security - out on the golf course.

When not into email security - out on the golf course.
Mailchimp Sending Non-Authenticated Emails Despite DKIM and DMARC

Mailchimp rejects emails due to DMARC p=reject, sending 100% non-authenticated despite DKIM setup.

Mailchimp Sending Non-Authenticated Emails Despite DKIM and DMARC
Email Security is the Foundation of Email Deliverability

DKIM, SPF, and DMARC form the foundation for secure email delivery and prevent spoofing.

Email Security is the Foundation of Email Deliverability
Microsoft and Google DMARC Reports Ignore Syntax Errors

DMARC aggregate reports continue despite significant syntax errors, as Microsoft and Google overlook issues.

Microsoft and Google DMARC Reports Ignore Syntax Errors
How Long Will Google Own Gmail.com?

Gmail.com’s ownership by Google seems indefinite, with no foreseeable reason for it to expire.

How Long Will Google Own Gmail.com?
Speaking at Real Estate Distilled: Email Security & Deliverability Insights

Shared practical tips on DMARC, email security, and deliverability with 175 engaged real estate professionals.

Speaking at Real Estate Distilled: Email Security & Deliverability Insights
How to Safely Manage High-Volume Email Campaigns

Avoid sudden email spikes; warm up your server to maintain deliverability and domain reputation.

How to Safely Manage High-Volume Email Campaigns
SH Consulting: Building a World-Class Email Deliverability & Security Team

We’re hiring top experts to elevate email security and deliverability to the highest standard.

SH Consulting: Building a World-Class Email Deliverability & Security Team
Yahoo Postmaster Updates Help Monitor Spam Reports Effectively

Yahoo Postmaster tool now tracks individual spam complaints, helping marketers maintain low complaint rates.

Yahoo Postmaster Updates Help Monitor Spam Reports Effectively
Why You Should Avoid Hosting DNS Zones with Wix

Wix DNS limitations prevent adding MX records, affecting email authentication and deliverability for platforms.

Why You Should Avoid Hosting DNS Zones with Wix
2024
Happy Holidays from Your Email Security Team

Wishing you secure emails, joyful holidays, and stronger connections throughout the festive season and New Year.

Happy Holidays from Your Email Security Team
Urgent Email List Cleanup: Avoid Deliverability Issues

Clean your email lists now to prevent spam complaints and protect future deliverability success.

Urgent Email List Cleanup: Avoid Deliverability Issues
2023
No items found.

Contact

If you're interested in contacting me, feel free to send an email connect with me on LinkedIn or Facebook , or visit my company’s official website at SH.Consulting and book a call.