Blog

Compliance, decoded

Regulatory updates, product news, and practical guides for MSPs and compliance teams navigating NIS2, DORA, GDPR, EAA, and ISO 27001.

·9 min read

You do not need a privacy checkbox. Here is what you actually need.

Most SaaS signup forms carry an “I accept the Terms and Privacy Policy” checkbox because someone believed the law requires it. It does not. The Terms are a contract, the Privacy Policy is a notice, and GDPR Article 7(4) treats bundling the two as presumed-invalid consent. Swiss law asks for information, not consent. Three UX patterns compared, the row you must write server-side, and the three cases where a real checkbox is required.

·8 min read

Swiss web accessibility is not mandatory on 1 January 2027. Here is what is.

The 2027 date for accessible websites in Switzerland is the Federal Council’s plan for the BehiG revision, and parliament has not voted on it yet. What Article 6 BehiG already requires of private companies, what the draft would change, and why the European Accessibility Act is the deadline Swiss companies selling into the EU already face.

·8 min read

Getting your face into people’s inboxes

BIMI puts a brand logo in the inbox. The photo next to a human is a different story, routed through five separate mechanisms that no standards body owns and that European data protection law treats very differently. One table, three compliance paragraphs, and the four-layer stack a sender actually uses.

·10 min read

You changed the setting. The world still sees the old one. Why.

A plain-English walkthrough of why a configuration change can sit invisible for hours after you deploy it, and the elegant trick some systems use to force the world to notice. Grounded in a real email-security rollout shipped this week, with named incidents that illustrate the difference between systems that include a version tag and systems that forgot.

·6 min read

One Google form decides how every browser treats your website.

Firefox, Safari, Edge, Brave, and Tor all pull their HTTPS preload list from a single file in the Chromium repository. This post explains how one Google form ends up controlling browser behavior across the web, the four rules to get on the list, and why getting off it later is much harder than getting on.

·8 min read

Your DMARC reports look like garbage. Here is how to actually read them.

DMARC aggregate reports arrive as zipped XML, once a day, from every receiver you send to. The format is machine-readable, not human-readable. This post walks through the schema field by field, the three red-flag patterns worth acting on, the noise you can ignore, and the tools that turn raw XML into a weekly digest.

·7 min read

We sell DMARC scanners. We almost filed a bug on our own sending domain.

A narrative on why dig txt mail.yourdomain.com is the wrong question to ask about SPF, how modern ESPs split the sending domain into nested subdomains, and the three checks that actually audit alignment.

·8 min read

Microsoft 365 email is spoofable out of the box. Here is how to close the three gaps.

Microsoft 365 ships with DKIM off, no DMARC, and an SPF default that gets weakened during rollout. A Defender-portal walkthrough that closes all three gaps and stops outbound spoofing of your domain.

·8 min read

Anyone can spoof your Google Workspace email right now. Here is the 30-minute fix.

Google Workspace ships with weak SPF, DKIM off, and no DMARC record. A short admin walkthrough that closes all three gaps and stops outbound spoofing of your domain.