Zum Inhalt

2026

Parked and Inactive Domains: Are SPF, DKIM, and DMARC Still Necessary?

Parked and inactive domains are easy to forget, yet attackers can still abuse them for phishing, domain spoofing, and brand impersonation. If a domain has no email authentication records at all, nothing stops someone else from sending mail that looks like it comes from you. Here i explain what SPF, DMARC, MX, and DKIM records you should publish for a parked domain, and why each one closes a specific gap attackers would otherwise use.

Microsoft 365 Mail Adoption in Switzerland - Statistics

How widespread is Microsoft 365 and its Exchange Online (mail service) around Swiss domains? To answer that question, I have analyzed a sample of around 24,000 Swiss .ch and related domains using public DNS records (MX), Microsoft AutodiscoverV2 endpoints. It should represent a snapshot of the Swiss mail landscape.

How to Report Security Vulnerabilities: From Discovery to CVE-2026-21535

Finding a security vulnerability can be quite a story. In my case, it started with confusion when testing a feature or noticing something unexpected. After wider testing, you might confirm that something is broken or there could be an underlying issue. Then the real question kicks in: where do you report it, and how do you do it responsibly?

What do I need, and where do I report it?

If you don't work in this space daily, you mostly hear about CVE's. But do you actually need one for every vulnerability, and how do you get it?