Generator Labs @generatorlabs.com · 13hFriday afternoon DNS change? We've all done it exactly once. 000
Generator Labs @generatorlabs.com · 29/09/2026A footer unsubscribe link doesn't satisfy Gmail and Yahoo. They want the one-click List-Unsubscribe header, signed by DKIM. Is anyone still seeing big senders miss it? generatorlabs.com/blog/gmail-y... 001
Generator Labs @generatorlabs.com · 29/09/2026Give every service that sends mail its own subdomain. Marketing and receipts each get one, and a bad campaign has a much harder time dragging your password resets into spam with it. 000
Generator Labs @generatorlabs.com · 28/09/2026Port 25 outbound is blocked by default on AWS, Google Cloud and most Azure subscriptions, so a new mail server there can look perfectly set up and still never deliver a thing. docs.aws.amazon.com/AWSEC2/lates... 000
Generator Labs @generatorlabs.com · 27/09/2026What's the oldest thing still sending mail as your domain that nobody on the team remembers setting up? Our money's on a printer or an old monitoring box. 000
Generator Labs @generatorlabs.com · 26/09/2026ERR_CERT_COMMON_NAME_INVALID only on www usually means the cert doesn't list www. The redirect can't help, because the browser checks the cert before the redirect ever runs. generatorlabs.com/blog/wildcar... 000
Generator Labs @generatorlabs.com · 25/09/2026If DMARC has sat at p=none for years, the reports it's collected show the servers sending mail as your domain. Worth a read before you move to quarantine. mrdns.com/dmarc-check 000
Generator Labs @generatorlabs.com · 24/09/2026400 Bad Request No required SSL certificate was sent nginx completes the TLS handshake and refuses at the HTTP layer, so an expired client certificate reads as a broken client. mTLS doubles the certificates you have to keep alive: generatorlabs.com/blog/mtls-in... 000
Generator Labs @generatorlabs.com · 23/09/2026How many DNS lookups does your SPF record really cost? Count every include your vendors nest inside theirs. Past ten, it fails with permerror: generatorlabs.com/blog/spf-ten... 010
Generator Labs @generatorlabs.com · 23/09/20265 days. That is how long Postfix holds deferred mail by default before it gives up and bounces it. A blocklist listing you clear on day six does not bring that mail back, and the default config sends the user no warning while the clock runs. 000
Generator Labs @generatorlabs.com · 22/09/2026Now in Blacklist Monitoring: Google Postmaster Tools. Gmail grades your domain every day. A bad grade now reaches you as an alert, the same day, like a blacklist listing would: generatorlabs.com/changelog/go... 000
Generator Labs @generatorlabs.com · 22/09/2026When a certificate expiry alert fires at 2am, who receives it? If it lands in one person's inbox and that person left two years ago, the alert is going somewhere nobody reads. Where do yours point? 000
Generator Labs @generatorlabs.com · 21/09/2026Nobody sets a calendar reminder for the internal root CA that signs everything. 000
Generator Labs @generatorlabs.com · 20/09/2026example.com. IN CAA 0 iodef "mailto:security@example.com" CAA records usually stop at issue and issuewild. The iodef tag adds an address for the CA to report a refused request to, so you hear when someone else asks for a certificate on your domain. 000
Generator Labs @generatorlabs.com · 15/09/2026Leave the old DKIM selector up for a week after you rotate. Mail you signed yesterday may still be sitting in a retry queue, and it can't verify against a record you deleted: generatorlabs.com/blog/dkim-ke... 000
Generator Labs @generatorlabs.com · 15/09/2026Did the vendor who "warmed up" your new sending domain also get it blocklisted? The Validity Heatwave DBL lists domains seen in inbox-warming traffic. It's now in Blacklist Monitoring on every plan, so you can check before the next send: generatorlabs.com/changelog/va... 000
Generator Labs @generatorlabs.com · 13/09/2026Every bounce your mail server sends goes out with an empty envelope sender, MAIL FROM:<>. SPF has nothing to check there, so receivers fall back to the HELO hostname. If that name has no SPF record of its own, your bounces fail SPF at any receiver that enforces it. 100
Generator Labs @generatorlabs.com · 12/09/2026Self-signed certificates on internal tools do more harm than good. Every warning a user clicks through trains them to click through the next one, including the one that matters. Run an internal CA and push its root to every device. 001
Generator Labs @generatorlabs.com · 11/09/2026Issuer: C=US, O=Let's Encrypt, CN=R11 That intermediate is already retired. Let's Encrypt has gone from R3 to R10/R11 to the YR/YE set, and its page says a backup can start issuing at any time, without warning. Pin an intermediate and you are on a timer. Trust the root. 000
Generator Labs @generatorlabs.com · 10/09/2026Cert expiry and blacklist listings, on the Datadog dashboard your team already watches. Integration v2 adds metrics: generatorlabs.com/changelog/da... 000
Generator Labs @generatorlabs.com · 10/09/2026Renewed the cert, kept the private key? If the key leaked, so did the renewal. 000
Generator Labs @generatorlabs.com · 09/09/2026Which of your mailbox providers tells you who hit the spam button? Yahoo does. Microsoft sends headers only now, so you need your own per-recipient ID in there. Gmail reports a campaign-level rate and no addresses. Apple sends nothing. generatorlabs.com/blog/feedbac... 000
Generator Labs @generatorlabs.com · 08/09/2026A reputation feed that dies quietly is worse than none at all, because you think you're covered. Microsoft retired the SNDS access key. Our new sign-in connection refreshes itself, so the data keeps coming: generatorlabs.com/changelog/mi... 000
Generator Labs @generatorlabs.com · 08/09/2026NET::ERR_CERT_DATE_INVALID Users report it as expired. Chrome shows the same page for a cert that is not valid yet, and for a visitor whose own clock is wrong. Read notBefore and notAfter off what the server is sending before you blame the renewal. 000
Generator Labs @generatorlabs.com · 07/09/20261.4 billion IPv4 addresses, almost 40% of routable space, are on Spamhaus's PBL. It is a policy list: a mail server on an ISP's end-user block is listed before it sends its first message, however clean. The fix is usually a move. 000
Generator Labs @generatorlabs.com · 06/09/2026Two kinds of DMARC report, and people constantly conflate them. rua is the aggregate feed: daily rollups of who is sending as your domain and whether they pass. It is the one you actually receive. 100
Generator Labs @generatorlabs.com · 05/09/2026SPF checks the envelope sender. The visible From address goes unchecked. 000
Generator Labs @generatorlabs.com · 04/09/2026421 4.7.0 too many messages from your IP The receiver is throttling you, one step short of a block. Reputation degrades well before it gets you listed, and a 421 is usually where that decline first shows up. 000
Generator Labs @generatorlabs.com · 03/09/2026Feedback loop coverage is uneven. Yahoo sends a full ARF report with the recipient. Microsoft is header-only. Gmail gives you an aggregate rate, no addresses. Apple sends nothing. What each one tells you shapes how you act on a complaint: generatorlabs.com/blog/feedbac... 010
Generator Labs @generatorlabs.com · 03/09/2026TLS 1.0 and 1.1 should be turned off everywhere by now. Both were formally deprecated back in 2021. If a client still needs them, that client is the security problem you are actually solving, and weak transport just hides it. 000
Generator Labs @generatorlabs.com · 02/09/2026What's your DKIM key rotation cadence? Most domains publish one selector and never touch it again. If you can't name the last time you rotated, that is the answer. See what your domain is publishing: mrdns.com/dkim-check 000
Generator Labs @generatorlabs.com · 01/09/2026256 vs 3072. A 256-bit ECDSA key matches the strength of a 3072-bit RSA key, at roughly half the certificate size and far faster signing on the server. Default to ECDSA P-256 for anything new: generatorlabs.com/blog/rsa-vs-... 000
Generator Labs @generatorlabs.com · 31/08/2026X509v3 Extended Key Usage: TLS Web Server Authentication Miss this line and a valid, unexpired cert still gets refused as a server cert. Some internal CAs mint client-auth-only certs by default. The handshake fails and the expiry date looks perfectly fine. 100
Generator Labs @generatorlabs.com · 30/08/2026Certificate authorities no longer trust a single view of your DNS. Let's Encrypt validates your domain from several network vantage points at once and requires them to agree before issuing. 100
Generator Labs @generatorlabs.com · 29/08/2026Your leaf cert is valid for months. The intermediate above it can expire first. 000
Generator Labs @generatorlabs.com · 28/08/2026Manual certificate renewal is a reminder you will eventually miss, and lifetimes are shrinking every year. Automating issuance is the only safe path, but the automation itself needs monitoring, or it fails silently: generatorlabs.com/blog/acme-au... 000
Generator Labs @generatorlabs.com · 27/08/2026You watch the cert's expiry date. When does the domain name itself expire? A lapsed registration takes down every service on the domain at once, and it renews on a registrar's calendar nobody thinks to check: mrdns.com/whois 010
Generator Labs @generatorlabs.com · 26/08/2026550 5.7.1 Service unavailable; client host blocked using Spamhaus The receiver refused the message at the door. Your sender sees it in the bounce; the people you were trying to reach never learn the mail existed. A listing you don't monitor is mail you're quietly losing. 100
Generator Labs @generatorlabs.com · 25/08/2026Good news on the RSA vs ECDSA question: you don't have to choose. Point nginx at both certs and each visitor gets the one their browser likes. New clients get the fast ECDSA cert, older ones still get RSA, nobody's left out: generatorlabs.com/blog/rsa-vs-... 000
Generator Labs @generatorlabs.com · 25/08/20261024. That's the DKIM key length a lot of senders are still signing with. It validates, but the Gmail and Yahoo bulk-sender rules call for 2048-bit RSA. A weak signing key is one more reason a receiver downgrades your mail. 000
Generator Labs @generatorlabs.com · 24/08/2026ARC-Authentication-Results: i=1; spf=pass dkim=pass A forwarder or mailing list rewrites the path and breaks SPF and DKIM. ARC records that the original checks passed, so the final receiver can still honor DMARC on mail that was relayed. 000
Generator Labs @generatorlabs.com · 23/08/2026Accept a message, then bounce it because the mailbox does not exist, and that bounce goes to whoever the spammer forged in the From line. Do it at volume and you land on a backscatter blocklist for spam you never sent. 100
Generator Labs @generatorlabs.com · 22/08/2026OCSP stapling proves your cert isn't revoked in the handshake. Enable it. 000
Generator Labs @generatorlabs.com · 21/08/2026Is your logo showing up next to your mail in Gmail yet? BIMI only renders once DMARC sits at quarantine or reject and both the record and the VMC validate. See what you have published: mrdns.com/bimi-check 000
Generator Labs @generatorlabs.com · 20/08/2026~all on your SPF record is a hedge that means nothing in practice. Every receiver reads softfail its own way, so a spoof still gets a coin flip at the door. Once you actually know every source that sends as you, publish -all and mean it. 000
Generator Labs @generatorlabs.com · 19/08/2026Kilobytes, where an ECDSA signature was tens of bytes. Post-quantum certificates run that much larger, and a chain that once fit in a single packet now spans several. Handshake latency and old middleboxes both feel it: generatorlabs.com/blog/post-qu... 010
Generator Labs @generatorlabs.com · 18/08/2026Default to a multi-SAN cert, not a wildcard. A wildcard key compromise hands over your entire namespace; a named cert limits the blast radius to the hostnames you listed. Reach for the wildcard only when you're minting subdomains dynamically: generatorlabs.com/blog/wildcar... 000
Generator Labs @generatorlabs.com · 18/08/2026451 4.7.1 Greylisted, please try again later The receiver is stalling a first-time sender to see whether you retry like a real mail server. Legit queues come back in minutes. Most spam engines never do, so the delay is doing its job. 000
Generator Labs @generatorlabs.com · 17/08/2026List-Unsubscribe-Post: List-Unsubscribe=One-Click Bulk senders to Gmail and Yahoo have had to honor this header since early 2024. Skip it and your mail gets throttled quietly, well before a single spam complaint is ever filed. 000
Generator Labs @generatorlabs.com · 16/08/2026Certificate Transparency makes a poor inventory. It records what public CAs issued, so everything from your internal CA is invisible to it, and those are the certificates sitting in front of your databases. 000