Generator Labs @generatorlabs.com · 14hFriday afternoon DNS change? We've all done it exactly once. 000
Generator Labs @generatorlabs.com · 29/09/2026A footer unsubscribe link doesn't satisfy Gmail and Yahoo. They want the one-click List-Unsubscribe header, signed by DKIM. Is anyone still seeing big senders miss it? generatorlabs.com/blog/gmail-y... 001
Generator Labs @generatorlabs.com · 29/09/2026Give every service that sends mail its own subdomain. Marketing and receipts each get one, and a bad campaign has a much harder time dragging your password resets into spam with it. 000
Generator Labs @generatorlabs.com · 28/09/2026Port 25 outbound is blocked by default on AWS, Google Cloud and most Azure subscriptions, so a new mail server there can look perfectly set up and still never deliver a thing. docs.aws.amazon.com/AWSEC2/lates... 000
Generator Labs @generatorlabs.com · 27/09/2026What's the oldest thing still sending mail as your domain that nobody on the team remembers setting up? Our money's on a printer or an old monitoring box. 000
Generator Labs @generatorlabs.com · 26/09/2026DNSSEC is handled by whoever serves your DNS, so it doesn't have to come from the web host. You could keep DNS with a provider that signs zones and point it at any SA host that ticks the PHP and DirectAdmin boxes. Would that open up more options? 210
Generator Labs @generatorlabs.com · 26/09/2026ERR_CERT_COMMON_NAME_INVALID only on www usually means the cert doesn't list www. The redirect can't help, because the browser checks the cert before the redirect ever runs. generatorlabs.com/blog/wildcar... 000
Generator Labs @generatorlabs.com · 25/09/2026If DMARC has sat at p=none for years, the reports it's collected show the servers sending mail as your domain. Worth a read before you move to quarantine. mrdns.com/dmarc-check 000
Generator Labs @generatorlabs.com · 25/09/2026The plain one reports 0 or 1 for every container all the time, so it's one steady series you can alert on. The _reason one only emits while a container is waiting, with value 1 for the current reason. A reason label on the first would have nothing to hold while the container's running. 010
Generator Labs @generatorlabs.com · 24/09/2026400 Bad Request No required SSL certificate was sent nginx completes the TLS handshake and refuses at the HTTP layer, so an expired client certificate reads as a broken client. mTLS doubles the certificates you have to keep alive: generatorlabs.com/blog/mtls-in... 000
Generator Labs @generatorlabs.com · 23/09/2026How many DNS lookups does your SPF record really cost? Count every include your vendors nest inside theirs. Past ten, it fails with permerror: generatorlabs.com/blog/spf-ten... 010
Generator Labs @generatorlabs.com · 23/09/20265 days. That is how long Postfix holds deferred mail by default before it gives up and bounces it. A blocklist listing you clear on day six does not bring that mail back, and the default config sends the user no warning while the clock runs. 000
Generator Labs @generatorlabs.com · 23/09/2026For Unbound: trust-anchor-file is static and never learns 38696 on its own. auto-trust-anchor-file does, via RFC 5011, but needs write access to the file and its directory, so check resolvers running from read-only mounts or container images. 111
Generator Labs @generatorlabs.com · 22/09/2026Now in Blacklist Monitoring: Google Postmaster Tools. Gmail grades your domain every day. A bad grade now reaches you as an alert, the same day, like a blacklist listing would: generatorlabs.com/changelog/go... 000
Generator Labs @generatorlabs.com · 22/09/2026When a certificate expiry alert fires at 2am, who receives it? If it lands in one person's inbox and that person left two years ago, the alert is going somewhere nobody reads. Where do yours point? 000
Generator Labs @generatorlabs.com · 21/09/2026Nobody sets a calendar reminder for the internal root CA that signs everything. 000
Generator Labs @generatorlabs.com · 20/09/2026example.com. IN CAA 0 iodef "mailto:security@example.com" CAA records usually stop at issue and issuewild. The iodef tag adds an address for the CA to report a refused request to, so you hear when someone else asks for a certificate on your domain. 000
Generator Labs @generatorlabs.com · 20/09/2026Quarantine at pct=100 qualifies, so reject is not required for the logo. The tag that catches people is sp: per the spec, BIMI processing stops if the DMARC record carries sp=none, even with p=reject. 000
Generator Labs @generatorlabs.com · 17/09/2026Amazon-provided IPv6 is a fixed /56, and even five of them only yields 1280 /64s. For 4000 subnets per AZ you want a /48 or shorter, which means an IPAM pool or BYOIP. Also check the subnets-per-VPC quota: default is 200. 100
Generator Labs @generatorlabs.com · 15/09/2026Leave the old DKIM selector up for a week after you rotate. Mail you signed yesterday may still be sitting in a retry queue, and it can't verify against a record you deleted: generatorlabs.com/blog/dkim-ke... 000
Generator Labs @generatorlabs.com · 15/09/2026Did the vendor who "warmed up" your new sending domain also get it blocklisted? The Validity Heatwave DBL lists domains seen in inbox-warming traffic. It's now in Blacklist Monitoring on every plan, so you can check before the next send: generatorlabs.com/changelog/va... 000
Generator Labs @generatorlabs.com · 14/09/2026Before building that filter, Show original on a few of them and read the Authentication-Results header. SPF, DKIM and DMARC only prove the mail came from the domain it claims, so a spammer sending from a domain they own passes all three. 000
Generator Labs @generatorlabs.com · 13/09/2026The fix is one TXT record on the HELO name authorizing the server's own address. v=spf1 a -all covers most single hosts. Run the HELO hostname through the same checker you would use for the domain: mrdns.com/spf-check 000
Generator Labs @generatorlabs.com · 13/09/2026Every bounce your mail server sends goes out with an empty envelope sender, MAIL FROM:<>. SPF has nothing to check there, so receivers fall back to the HELO hostname. If that name has no SPF record of its own, your bounces fail SPF at any receiver that enforces it. 100
Generator Labs @generatorlabs.com · 12/09/2026Self-signed certificates on internal tools do more harm than good. Every warning a user clicks through trains them to click through the next one, including the one that matters. Run an internal CA and push its root to every device. 001
Generator Labs @generatorlabs.com · 11/09/2026Issuer: C=US, O=Let's Encrypt, CN=R11 That intermediate is already retired. Let's Encrypt has gone from R3 to R10/R11 to the YR/YE set, and its page says a backup can start issuing at any time, without warning. Pin an intermediate and you are on a timer. Trust the root. 000
Generator Labs @generatorlabs.com · 10/09/2026Cert expiry and blacklist listings, on the Datadog dashboard your team already watches. Integration v2 adds metrics: generatorlabs.com/changelog/da... 000
Generator Labs @generatorlabs.com · 10/09/2026Renewed the cert, kept the private key? If the key leaked, so did the renewal. 000
Generator Labs @generatorlabs.com · 09/09/2026Which of your mailbox providers tells you who hit the spam button? Yahoo does. Microsoft sends headers only now, so you need your own per-recipient ID in there. Gmail reports a campaign-level rate and no addresses. Apple sends nothing. generatorlabs.com/blog/feedbac... 000
Generator Labs @generatorlabs.com · 08/09/2026A reputation feed that dies quietly is worse than none at all, because you think you're covered. Microsoft retired the SNDS access key. Our new sign-in connection refreshes itself, so the data keeps coming: generatorlabs.com/changelog/mi... 000
Generator Labs @generatorlabs.com · 08/09/2026NET::ERR_CERT_DATE_INVALID Users report it as expired. Chrome shows the same page for a cert that is not valid yet, and for a visitor whose own clock is wrong. Read notBefore and notAfter off what the server is sending before you blame the renewal. 000
Generator Labs @generatorlabs.com · 08/09/2026CAA checking has been mandatory for public CAs since September 2017 (Ballot 187). The March 2027 change (SC098v2) makes CAs process the RFC 8657 accounturi and validationmethods parameters. A domain with no CAA record can still get a certificate from any CA. 000
Generator Labs @generatorlabs.com · 07/09/20261.4 billion IPv4 addresses, almost 40% of routable space, are on Spamhaus's PBL. It is a policy list: a mail server on an ISP's end-user block is listed before it sends its first message, however clean. The fix is usually a move. 000
Generator Labs @generatorlabs.com · 06/09/2026ruf is per-message forensic detail on the failures. Almost nobody emits it anymore, because a failed message can carry recipient data and privacy law pushed mailbox providers to stop. Build your reporting around rua. 000
Generator Labs @generatorlabs.com · 06/09/2026Two kinds of DMARC report, and people constantly conflate them. rua is the aggregate feed: daily rollups of who is sending as your domain and whether they pass. It is the one you actually receive. 100
Generator Labs @generatorlabs.com · 06/09/2026Worth checking that the DKIM d= or return-path domain is the new subdomain as well as the From header. Postmaster Tools keys its dashboards on those, and the subdomain has to be added separately to see it alone. Start it low; Google warns against volume spikes from a domain with no history. 110
Generator Labs @generatorlabs.com · 05/09/2026SPF checks the envelope sender. The visible From address goes unchecked. 000
Generator Labs @generatorlabs.com · 04/09/2026421 4.7.0 too many messages from your IP The receiver is throttling you, one step short of a block. Reputation degrades well before it gets you listed, and a 421 is usually where that decline first shows up. 000
Generator Labs @generatorlabs.com · 03/09/2026Feedback loop coverage is uneven. Yahoo sends a full ARF report with the recipient. Microsoft is header-only. Gmail gives you an aggregate rate, no addresses. Apple sends nothing. What each one tells you shapes how you act on a complaint: generatorlabs.com/blog/feedbac... 010
Generator Labs @generatorlabs.com · 03/09/2026TLS 1.0 and 1.1 should be turned off everywhere by now. Both were formally deprecated back in 2021. If a client still needs them, that client is the security problem you are actually solving, and weak transport just hides it. 000
Generator Labs @generatorlabs.com · 02/09/2026What's your DKIM key rotation cadence? Most domains publish one selector and never touch it again. If you can't name the last time you rotated, that is the answer. See what your domain is publishing: mrdns.com/dkim-check 000
Generator Labs @generatorlabs.com · 01/09/2026256 vs 3072. A 256-bit ECDSA key matches the strength of a 3072-bit RSA key, at roughly half the certificate size and far faster signing on the server. Default to ECDSA P-256 for anything new: generatorlabs.com/blog/rsa-vs-... 000
Generator Labs @generatorlabs.com · 31/08/2026X509v3 Extended Key Usage: TLS Web Server Authentication Miss this line and a valid, unexpired cert still gets refused as a server cert. Some internal CAs mint client-auth-only certs by default. The handshake fails and the expiry date looks perfectly fine. 100
Generator Labs @generatorlabs.com · 30/08/2026So a split-horizon setup or a firewall that answers differently by region can pass locally and still fail issuance. If a renewal breaks for no obvious reason, check what your domain looks like from outside your own network. 010
Generator Labs @generatorlabs.com · 30/08/2026Certificate authorities no longer trust a single view of your DNS. Let's Encrypt validates your domain from several network vantage points at once and requires them to agree before issuing. 100
Generator Labs @generatorlabs.com · 29/08/2026Your leaf cert is valid for months. The intermediate above it can expire first. 000
Generator Labs @generatorlabs.com · 28/08/2026Manual certificate renewal is a reminder you will eventually miss, and lifetimes are shrinking every year. Automating issuance is the only safe path, but the automation itself needs monitoring, or it fails silently: generatorlabs.com/blog/acme-au... 000
Generator Labs @generatorlabs.com · 28/08/2026SPF, DKIM and DMARC passing won't get you delivered on their own. Gmail also requires forward-confirmed reverse DNS: the sending IP's PTR resolving to a hostname whose A record points back to that same IP, which is easy to miss when you self-host. 110
Generator Labs @generatorlabs.com · 27/08/2026You watch the cert's expiry date. When does the domain name itself expire? A lapsed registration takes down every service on the domain at once, and it renews on a registrar's calendar nobody thinks to check: mrdns.com/whois 010
Generator Labs @generatorlabs.com · 26/08/2026550 5.7.1 Service unavailable; client host blocked using Spamhaus The receiver refused the message at the door. Your sender sees it in the bounce; the people you were trying to reach never learn the mail existed. A listing you don't monitor is mail you're quietly losing. 100