About this interactive
SPF, DKIM and DMARC are usually taught as a list of three acronyms, and the list survives contact with almost no real question. The details that decide whether a message is delivered are the ones the list leaves out: a domain with no SPF record produces `none`, which is not `fail`; SPF reads the envelope sender, which nobody is ever shown, and not the From: header, which is the only sender anybody sees; a DKIM signature dies the moment a mailing list appends a footer, with no attacker and no misconfiguration anywhere; a plain forward breaks SPF and leaves DKIM untouched; and a marketing platform can pass both checks flawlessly as itself and still fail DMARC, because DMARC is not asking whether something passed but whether the thing that passed is the domain in the From: header. This activity traces ten messages through a receiving server and asks you to call each verdict before it shows you, ending with the one thing an attacker who owns his own domain and publishes his own DNS still cannot forge.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →