Case Study. Must read. Fixing Gmail deliverability isn’t as simple as changing your IP or switching platforms. In one real case: A brand moved to a dedicated IP on their ESP’s advice, hoping it would fix domain reputation issues. Warm-up was done correctly. SPF, DKIM, and DMARC were all passing. But Gmail Postmaster reputation dropped to "bad" and stayed there Gmail inbox placement went to 0%. CTRs were around 0.2%, and nothing improved. The core issue wasn't technical. It was behavioral. Their student emails were opt-in. But corporate emails came from purchased ZoomInfo lists. Gmail picked up on this and punished the entire domain. Changing IPs just exposed the issue faster. Their suppression logic also made things worse: 1. Users were suppressed only after 10 sends with no clicks 2. That means 10 chances to hurt domain reputation 3. Engagement-based filtering is strict 4. If people don’t interact, Gmail assumes your content is unwanted Technical setup wasn't perfect either: 1. Their signup API lacked rate limits 2. Bots were likely abusing the form 3. This led to emails being sent to fake or unverified addresses More bad signals sent to Gmail A "0% spam complaint rate" looked good on paper, but it was misleading. If no one sees your email in the inbox, they can’t complain. That’s a sign your emails are already deep in spam. Should you ever change IPs? Yes, if recommended by an experienced deliverability expert because the IPs are burnt and beyond recovery anytime soon. But only after identifying and fixing the root cause. Changing IPs without fixing your behavior is just a temporary patch What can actually help? Along with all other best practices, 1. Stop mailing Gmail users for a while. 2. Start fresh with small, high-quality segments. 3. Promote your email content on your website or social media to drive awareness. Good deliverability doesn’t come from tools or IPs. It comes from permission, relevance, and engagement. I have seen a lot of marketers with no optin lists but with content relevance and positive engagement they are doing great. If Gmail doesn’t see real interest in your emails, nothing else will matter. Happy to chat if you're navigating a similar situation. #email #emailmarketing
Email Security Features
Explore top LinkedIn content from expert professionals.
-
-
Having anti-virus software DOES NOT give you a free pass against phishing threats. They do not prevent your users from falling for sophisticated social engineering attacks. No amount of legacy anti-virus software can stop an employee from entering their Office 365 credentials into a devious phishing site. Or keep an executive from approving a multi-million dollar fraudulent transaction. Phishing has evolved way beyond just malware delivery. Increasingly, it's a complex, multi-vector con job targeting your most important asset - your people. Phishers don't always need an infected device to succeed; just uninformed recipients. Here are 4 steps you can take to mitigate risks: 1. 𝐄𝐦𝐩𝐥𝐨𝐲𝐞𝐞 𝐓𝐫𝐚𝐢𝐧𝐢𝐧𝐠 𝐚𝐧𝐝 𝐀𝐰𝐚𝐫𝐞𝐧𝐞𝐬𝐬 𝐏𝐫𝐨𝐠𝐫𝐚𝐦𝐬: Regular training sessions with mock phishing scenarios can help employees recognize and avoid phishing attempts. This is crucial as phishing attacks often rely on tricking users into giving away their information. 2. 𝐃𝐲𝐧𝐚𝐦𝐢𝐜 𝐎𝐛𝐟𝐮𝐬𝐜𝐚𝐭𝐢𝐨𝐧: This is a technique where the information presented to potential attackers is constantly changing, making it difficult for them to gain a foothold. It can be particularly effective in protecting against phishing attacks that rely on gathering information about the system or the users. 3. 𝐏𝐡𝐢𝐬𝐡𝐢𝐧𝐠-𝐑𝐞𝐬𝐢𝐬𝐭𝐚𝐧𝐭 𝐌𝐮𝐥𝐭𝐢-𝐅𝐚𝐜𝐭𝐨𝐫 𝐀𝐮𝐭𝐡𝐞𝐧𝐭𝐢𝐜𝐚𝐭𝐢𝐨𝐧 (𝐌𝐅𝐀): While MFA is a common recommendation, using a phishing-resistant MFA adds an extra layer of security. This could involve using hardware tokens or biometric data, which are much harder for a phishing attack to replicate. 4. 𝐈𝐧𝐯𝐞𝐬𝐭 𝐢𝐧 𝐚 𝐂𝐨𝐦𝐩𝐫𝐞𝐡𝐞𝐧𝐬𝐢𝐯𝐞, 𝐌𝐮𝐥𝐭𝐢-𝐋𝐚𝐲𝐞𝐫𝐞𝐝 𝐄𝐦𝐚𝐢𝐥 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐒𝐨𝐥𝐮𝐭𝐢𝐨𝐧: Invest in a comprehensive, multi-layered, anti-phishing security solution that covers all aspects of your business. That means adding a specialist cloud email security solution like MailGuard, to your email security stack. Modern phishing protection must blend cutting-edge technology with comprehensive security awareness. Believing otherwise is the real virus that can leave you vulnerable.
-
If You’re Storing Client Data in Email, You Might as Well Hand It to Hackers Each week I receive 10-15 random emails from Law Firms all over the US that have clearly been hacked (because I am not a client of any of them). THIS IS A PROBLEM. - for more reasons than just my cluttered inbox. Law firms handle some of the most sensitive client data imaginable—financial records, medical documents, legal strategies, and personally identifiable information (PII). Yet, too many firms still use email like a filing cabinet. Here’s the reality: Email is NOT secure storage. Why? 📧 Emails get hacked daily and business email compromise (BEC) scams cost billions each year. 🔓 Attachments sit unsecured in inboxes, waiting for a breach. 🕵️ Phishing attacks target law firms because attackers know email is the weakest link. Now, imagine this: A cybercriminal gains access to your email. They don’t just steal client data—they sell it on the Dark Web, use it for fraud, or leak it to the opposition. 🚨 What should law firms do instead? ✅ Use a secure document management system—encrypted and access-controlled. ✅ Implement end-to-end encrypted communication tools for client discussions. ✅ Enforce strict email retention and deletion policies—keep only what’s necessary. ✅ Train employees on email security—human error is the #1 risk, BUT your employees SHOULD be your best defenders (if trained correctly). 💡 Cybersecurity isn’t just an IT issue—it’s a fiduciary duty. Your clients trust you to protect their data. Don’t let an outdated habit destroy that trust. 👇 What’s your law firm doing to secure client communications? Or is it? #CyberSecurity #LawFirms #DataProtection #ClientTrust #BECScams #GoldShieldCyber #KnowledgeIsProtection #CyBUrSmart
-
Let’s face it—despite next-gen firewalls and endpoint protection, most breaches still start the old-fashioned way: through email and web browsers. Why? Because they’re the tools we use every day, and that makes them the easiest to exploit. The Problem ✔ Email is a hacker’s best friend—phishing, BEC scams, and weaponized attachments keep evolving. Even with filters, one cleverly disguised email can bypass defenses and trick even savvy users. ✔ Browsers are the wild west—malicious ads, drive-by downloads, and rogue extensions turn routine web browsing into a minefield. And with SaaS apps everywhere, employees are constantly logging into new (and sometimes risky) sites. Basic spam filters and antivirus won’t cut it anymore. Attackers use AI-generated messages, zero-day exploits, and social engineering to slip past traditional defenses. What Actually Works ✅ AI-powered email filtering that detects subtle phishing cues (not just obvious spam). ✅ Browser isolation or strict extension controls to stop malicious code before it executes. ✅ Zero Trust policies—because assuming "trusted" users or devices is a recipe for disaster. ✅ Ongoing security training—because human error is still the weakest link. The Bottom Line If your security strategy isn’t obsessed with locking down email and browsers, you’re leaving the front door wide open. #CyberSecurity #EmailSecurity #BrowserSecurity #ZeroTrust #Phishing
-
Phishing used to be easy to spot—bad grammar, generic greetings, and outlandish claims offering millions. But today, AI has changed the game. It is helping attackers craft flawless, personalized, and highly convincing messages that mimic real conversations. These emails don’t just look legitimate—they sound like your boss, your colleague, or your financial institution. With AI, threat actors can now: 🔹𝐒𝐜𝐚𝐥𝐞 𝐬𝐩𝐞𝐚𝐫-𝐩𝐡𝐢𝐬𝐡𝐢𝐧𝐠 𝐚𝐭𝐭𝐚𝐜𝐤𝐬 that once took time. 🔹𝐁𝐲𝐩𝐚𝐬𝐬 𝐭𝐫𝐚𝐝𝐢𝐭𝐢𝐨𝐧𝐚𝐥 𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐦𝐞𝐚𝐬𝐮𝐫𝐞𝐬 like keyword-based spam filters and URL detection techniques. 🔹𝐄𝐱𝐩𝐥𝐨𝐢𝐭 𝐭𝐫𝐮𝐬𝐭 𝐚𝐧𝐝 𝐮𝐫𝐠𝐞𝐧𝐜𝐲 by posing as senior executives, vendors, or IT support The result? Employees are no longer just skimming suspicious emails—they’re engaging with them. Traditional defences like spam filters and one-time security awareness training aren’t enough to stop it. Organizations need a multi-layered email security strategy that goes beyond outdated methods. ✅ 𝐈𝐧𝐯𝐞𝐬𝐭 𝐢𝐧 𝐀𝐝𝐯𝐚𝐧𝐜𝐞𝐝 𝐓𝐡𝐫𝐞𝐚𝐭 𝐃𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧 Adopt solutions that leverage real-time behavioural analytics and machine learning to identify anomalies in email communication. ✅ 𝐄𝐧𝐡𝐚𝐧𝐜𝐞 𝐄𝐦𝐩𝐥𝐨𝐲𝐞𝐞 𝐓𝐫𝐚𝐢𝐧𝐢𝐧𝐠 Transition from generic phishing awareness to targeted training that exposes the evolving tactics of AI-powered attacks. Simulated phishing exercises that mimic current threats can help build resilience. ✅ 𝐈𝐦𝐩𝐥𝐞𝐦𝐞𝐧𝐭 𝐌𝐮𝐥𝐭𝐢-𝐅𝐚𝐜𝐭𝐨𝐫 𝐕𝐞𝐫𝐢𝐟𝐢𝐜𝐚𝐭𝐢𝐨𝐧 Encourage protocols such as secondary confirmation for sensitive transactions or requests, particularly those that deviate from the norm. ✅ 𝐑𝐞𝐠𝐮𝐥𝐚𝐫𝐥𝐲 𝐔𝐩𝐝𝐚𝐭𝐞 𝐚𝐧𝐝 𝐓𝐞𝐬𝐭 𝐃𝐞𝐟𝐞𝐧𝐬𝐞𝐬 Cybersecurity isn’t a set-it-and-forget-it deal. Continuously refine your email security protocols and conduct regular assessments to ensure your defences adapt to emerging threats. AI has made phishing smarter. Are we making our defences smarter, too? #EmailSecurity #CyberSecurity #AI
-
I burned through $15K perfecting cold email copy. Here's what I learned when I focused on deliverability instead. While I was obsessing over subject lines and CTAs, most of my emails were landing in spam folders. I had killer copy that nobody ever saw. But here's what happened when I fixed the infrastructure piece first… I went from ignored emails to 800,000+ monthly sends at ColdIQ. If your cold emails aren't working, deliverability beats copy every single time. WHY DELIVERABILITY IS EVERYTHING: 1. Perfect copy means nothing in spam. You can have killer targeting, perfect messaging, incredible offers... but if your email lands in spam? Game over. 2. It compounds everything else. Once your domain reputation is down, even your transactional emails start getting flagged and won't get delivered anymore. So how do you make your email in the primary? 1. Protect your main domain. Never send cold emails from your primary domain. We use 70+ secondary domains to keep our brand safe and our main inbox clean. 2. Distribute volume across multiple mailboxes. Set up 140+ mailboxes across those domains. Keep it under 50 sends per day per domain. High volume too early = instant red flag. 3. Get your technical foundation bulletproof. Set up SPF, DKIM, and DMARC authentication. Without proper technical set-up, you're flagged as suspicious by default. 4. Warm up. Send nothing for 2 weeks. Use premium warm-up tools to build trust gradually with ESPs. Ramp slowly to avoid triggering their spam filters. Patience here pays dividends later. 5. Natural variation. Use Spintax or tools like Twain to introduce variations in your messaging. Even small variations help you avoid the repetition triggers that scream "mass email blast" to spam filters. Remember, list quality plus message still matter most. Even with perfect infrastructure, if your list is off and your message is weak, you'll still land in spam. Deliverability gets you to the inbox, but the relevance keeps you there. Monitor everything rigorously. Use tools to track your sender reputation across all ESPs. We check deliverability rates daily (it's that critical). Infrastructure gets you to the inbox, but your targeting plus messaging determines what happens next. I've put together a 7-day GTM crash course that includes our exact setup, authentication templates, and the monitoring systems we use to protect the campaigns of our 70 clients. Reply with "SETUP" if you want access before your next campaign goes live.
-
A CISO once told me, "𝐖𝐞 𝐬𝐩𝐞𝐧𝐝 𝐦𝐢𝐥𝐥𝐢𝐨𝐧𝐬 𝐨𝐧 𝐟𝐢𝐫𝐞𝐰𝐚𝐥𝐥𝐬, 𝐛𝐮𝐭 𝐨𝐧𝐞 𝐟𝐨𝐫𝐠𝐨𝐭𝐭𝐞𝐧 𝐞𝐦𝐚𝐢𝐥 𝐠𝐨𝐭 𝐮𝐬 𝐡𝐚𝐜𝐤𝐞𝐝." What Actually happened? 🔹 A senior executive left the company. 🔹 His email account was never deactivated. 🔹 Six months later, attackers logged in using his credentials and moved through the network undetected. By the time they were caught, they had stolen gigabytes of sensitive data. What went wrong? They didn’t have a simple offboarding security habit. ✅ 𝐃𝐞𝐚𝐜𝐭𝐢𝐯𝐚𝐭𝐢𝐧𝐠 𝐮𝐧𝐮𝐬𝐞𝐝 𝐚𝐜𝐜𝐨𝐮𝐧𝐭𝐬 is one of the most overlooked cybersecurity practices—yet it’s one of the easiest ways to prevent breaches. If, in your company: → Old employee accounts? Still have access → Third-party vendors? Still are active → Former IT staff? Could still log in. Every forgotten account is an open door for attackers. High time to fix it today: ✔ Audit all user accounts every quarter. ✔ Implement auto-expiry for unused accounts. ✔ Set strict access revocation during offboarding. Hackers don’t need to break in if 𝐲𝐨𝐮’𝐯𝐞 𝐚𝐥𝐫𝐞𝐚𝐝𝐲 𝐥𝐞𝐟𝐭 𝐭𝐡𝐞 𝐝𝐨𝐨𝐫 𝐨𝐩𝐞𝐧. When was the last time your company 𝐜𝐥𝐞𝐚𝐧𝐞𝐝 𝐮𝐩 𝐢𝐧𝐚𝐜𝐭𝐢𝐯𝐞 𝐚𝐜𝐜𝐨𝐮𝐧𝐭𝐬? #AccessManagement #RiskManagement #CyberSecurity #DataProtection
-
𝐘𝐨𝐮𝐫 𝐝𝐨𝐦𝐚𝐢𝐧 𝐜𝐚𝐧 𝐛𝐞 𝐮𝐬𝐞𝐝 𝐭𝐨 𝐬𝐜𝐚𝐦 𝐩𝐞𝐨𝐩𝐥𝐞… and you might 𝐧𝐞𝐯𝐞𝐫 𝐤𝐧𝐨𝐰. 𝐇𝐞𝐫𝐞’𝐬 𝐡𝐨𝐰 𝐢𝐭 𝐚𝐜𝐭𝐮𝐚𝐥𝐥𝐲 𝐡𝐚𝐩𝐩𝐞𝐧𝐬 👇 That’s the scary part. No breach. No malware. No alerts. Just someone sending emails as you. If your setup is weak, it’s easy. That’s where 𝐒𝐏𝐅, 𝐃𝐊𝐈𝐌, 𝐚𝐧𝐝 𝐃𝐌𝐀𝐑𝐂 come in. Let’s break it down simply: ➤ SPF (Who can send) Think of it like a guest list It tells the internet: “These servers are allowed to send emails from us” If a server is not on the list → something’s off ➤ DKIM (Was it changed?) This is your digital signature Every email gets “signed” before it leaves If someone edits the message → signature breaks So receivers know: “This email is real and untouched” ➤ DMARC (What to do next) The rulebook If checks fail → you decide: -Ignore -Send to spam -Block it Plus, you get reports on everything Without them? Your domain becomes an easy target for spoofing and fraud. If you take ONE thing from this: Email security isn’t about tools. It’s about trust. And trust starts with proper configuration. 𝐇𝐚𝐯𝐞 𝐲𝐨𝐮 𝐚𝐜𝐭𝐮𝐚𝐥𝐥𝐲 𝐜𝐡𝐞𝐜𝐤𝐞𝐝 𝐲����𝐮𝐫 𝐃𝐌𝐀𝐑𝐂 𝐩𝐨𝐥𝐢𝐜𝐲… 𝐨𝐫 𝐣𝐮𝐬𝐭 𝐚𝐬𝐬𝐮𝐦𝐞𝐝 𝐢𝐭’𝐬 𝐬𝐞𝐭? ---- Hi, I’m Harris D. Schwartz, 𝐅𝐫𝐚𝐜𝐭𝐢𝐨𝐧𝐚𝐥 𝐂𝐈𝐒𝐎 & 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐋𝐞𝐚𝐝𝐞𝐫. I help CEOs and executive teams strengthen their security posture and build resilient, compliant organizations. With deep expertise across 𝐍𝐈𝐒𝐓, 𝐈𝐒𝐎, 𝐏𝐂𝐈, 𝐚𝐧𝐝 𝐆𝐃𝐏𝐑, I focus on making security a business enabler, not just a control function. If you’re planning how your security program should evolve in 2026, this is the right time to start the conversation. #CyberSecurity #EmailSecurity #DMARC #SPF #DKIM #InfoSec #SecurityAwareness #DataSecurity #CyberRisk #TechLeadership #ITSecurity #DigitalTrust #InfosecCommunity
-
Sending cold emails isn't what generates business. What generates business is those emails landing in the main inbox. A great email in spam earns you nothing. So before you obsess over copy, get the boring stuff right. 👉 Here are the 11 checks that decide whether your emails even get seen. ✅ Configuration: 1. Send outbound from a separate domain. Keep your main company domain out of the blast radius. 2. Warm new accounts before you scale. Start around 5 emails a day, then 10, 20, 30. Never push much past 30 from one address. 3. Set up SPF and DKIM. Without them you look like a spammer to other servers. 4. Know your provider's sending limits. Exceed them and the account gets blocked. ✅ Content: 5. Cut the salesy language. Words you'd never use emailing a friend trip the filters. 6. Keep the format plain. Heavy HTML, images, and gifs hurt your text-to-HTML ratio. 7. Don't track opens and links unless you need to. Tracking rewrites your link to another domain, and that looks suspicious. 8. Personalize for real. Identical emails sent at volume are what anti-spam systems are built to catch. ✅ Contact base: 9. Upload in small batches, not 5,000 at once. Smaller lists mean tighter control over quality. 10. Verify addresses before sending. A wave of bounces is a signal your reputation can't afford. 11. Send to named individuals at companies. A pile of info@ and office@ addresses kills your odds. Get these right and your copy gets a chance to do its job.
-
You’re sending emails. You’re testing different subject lines. You’re tweaking your messaging. But no one is booking calls. Maybe it’s not your copy. Maybe it’s your data. I worked with a solopreneur who was doing all the right things. ✅ Writing valuable emails ✅ Trying new angles to position her offer ✅ Experimenting with persuasive subject lines And yet—crickets. No replies. No bookings. Just… silence. She was convinced she had a messaging problem. Until we looked at her numbers. 📉 Open rates? 20% → Below average for her industry 📉 Click-through rates? Less than 1% → No one was taking action 📉 Spam complaints? Way too high It wasn’t her words. It was her email deliverability. Her emails were landing in spam and promotions—so the people who actually wanted to work with her? Never saw them. Once we fixed her authentication & engagement strategy: ✅ Open rates jumped to 40+% ✅ Click-through rates tripled ✅ And she finally started booking calls—without changing a word of her copy. If your emails aren’t converting, don’t just guess—check the data. It might not be your content. It might be your inbox placement. You can’t fix a visibility problem with better words. You fix it by making sure people see your emails. Are you tracking your email metrics, or just hoping for the best?