// WRITING
Notes from the work.
Mostly things I found myself explaining twice — how to buy a penetration test, why your domain is probably spoofable, and how the tooling I build actually works.
·4 min read
What a penetration test report should actually contain
Most people buying their first pentest have never seen a report. Here is what separates a document your engineers can act on from a scanner export with a logo on it.
pentestingbuying securityreporting
·3 min read
Your domain is probably spoofable — and you can check in ten seconds
Most companies have SPF and think they are protected. Without an enforcing DMARC policy, anyone on the internet can send email that appears to come from your CEO.
email securityDMARCSPFphishing