Glossary

Email, defined. No jargon left unexplained.

45 short definitions of the terms behind business email, from SPF and DMARC to bounces, warm-up and IMAP. Each links to the related terms and to a free tool that checks it.

Authentication→

ARC (Authenticated Received Chain)

ARC lets forwarders and mailing lists record the authentication results they saw, so later receivers can trust mail whose SPF or DKIM broke in transit.

/glossary/arc

Authentication→

BIMI (Brand Indicators for Message Identification)

BIMI lets supporting inboxes show a brand's logo next to its authenticated email, using a DNS record that points to an SVG logo and a mark certificate.

/glossary/bimi

Mailboxes→

Catch-all address

A catch-all accepts email sent to any address at a domain, even ones that were never set up, and delivers it to one mailbox.

/glossary/catch-all

DNS→

CNAME record (canonical name record)

A CNAME record makes one hostname an alias of another, so lookups for it are answered with the target's records.

/glossary/cname-record

Mailboxes→

Custom domain email

Custom domain email is an address on a domain you own, like you@yourcompany.com, instead of a free provider's domain.

/glossary/custom-domain-email

Authentication→

DKIM (DomainKeys Identified Mail)

DKIM adds a cryptographic signature to outgoing email, verified against a public key in the sender's DNS, proving the message is genuine and unaltered.

/glossary/dkim

Authentication→

DKIM selector

A DKIM selector is the label that tells receivers which of a domain's DKIM keys signed a message, found at selector._domainkey.domain.

/glossary/dkim-selector

Authentication→

DMARC (Domain-based Message Authentication, Reporting and Conformance)

DMARC tells receivers what to do with email that fails SPF and DKIM for your domain, and sends you reports about who is sending as you.

/glossary/dmarc

Authentication→

DMARC alignment

DMARC alignment means the domain that passed SPF or DKIM matches the domain in the visible From address, which is what DMARC actually requires.

/glossary/dmarc-alignment

Authentication→

DMARC reports (rua and ruf)

DMARC reports are feedback mailbox providers send domain owners: daily aggregate summaries (rua) and per-message failure reports (ruf).

/glossary/dmarc-reports

DNS→

DNS TTL (time to live)

A DNS record's TTL is how many seconds resolvers may cache it before asking again, which sets how quickly changes take effect.

/glossary/dns-ttl

Deliverability→

DNSBL (DNS-based blocklist)

A DNSBL is a list of IP addresses or domains linked to spam, published through DNS so mail servers can check senders in real time.

/glossary/dnsbl

Mailboxes→

Email alias

An email alias is an extra address that delivers into an existing mailbox, such as hello@ or billing@ arriving in your own inbox.

/glossary/email-alias

Mailboxes→

Email forwarding

Email forwarding automatically resends incoming mail to another address. It's convenient, but it can break SPF and DMARC along the way.

/glossary/email-forwarding

Mailboxes→

Email migration

Email migration is moving mailboxes, existing mail and DNS from one email provider to another without losing messages.

/glossary/email-migration

Authentication→

Email spoofing

Email spoofing is sending mail with a forged sender address, usually to impersonate a trusted company or person in phishing.

/glossary/email-spoofing

Deliverability→

Email warm-up

Email warm-up is gradually increasing sending volume from a new domain or IP, so mailbox providers can build a positive reputation for it.

/glossary/email-warm-up

Deliverability→

Feedback loop

A feedback loop is a mailbox provider's service that notifies a sender when recipients mark its mail as spam.

/glossary/feedback-loop

Deliverability→

Google and Yahoo sender requirements

Since 2024 Gmail and Yahoo require authentication, low spam rates and easy unsubscribes from senders, with stricter rules for bulk senders.

/glossary/bulk-sender-requirements

Deliverability→

Hard bounce

A hard bounce is a permanent delivery failure, such as a non-existent address or domain, signalled by a 5xx SMTP reply.

/glossary/hard-bounce

Protocols→

IMAP (Internet Message Access Protocol)

IMAP lets mail apps read and organise email that stays on the server, so every device sees the same folders and read state.

/glossary/imap

Mailboxes→

IMAP import

IMAP import copies existing mail from an old mail server to a new one over IMAP, keeping folders, dates and read status.

/glossary/imap-import

Protocols→

JMAP (JSON Meta Application Protocol)

JMAP is a modern IETF standard for mail apps that uses JSON over HTTPS for efficient syncing, pushing changes and sending.

/glossary/jmap

Deliverability→

List-Unsubscribe

List-Unsubscribe is an email header giving a mailto: or web address for unsubscribing, which mail apps turn into a built-in unsubscribe button.

/glossary/list-unsubscribe

Protocols→

Message-ID

Message-ID is a header holding a globally unique identifier for an email, used for threading replies and spotting duplicates.

/glossary/message-id

DNS→

MTA-STS (SMTP MTA Strict Transport Security)

MTA-STS lets a domain require that mail sent to it travels over TLS with a valid certificate, preventing downgrade and interception attacks.

/glossary/mta-sts

DNS→

MX record (Mail Exchanger record)

An MX record tells the internet which servers accept email for a domain, with a priority number to set the order they're tried in.

/glossary/mx-record

Deliverability→

One-click unsubscribe

One-click unsubscribe (RFC 8058) lets a mail app unsubscribe a user with a single background request, now required for bulk marketing mail to Gmail and Yahoo.

/glossary/one-click-unsubscribe

Protocols→

POP3 (Post Office Protocol version 3)

POP3 is an older protocol that downloads email from the server to one device, typically removing it from the server afterwards.

/glossary/pop3

DNS→

PTR record

A PTR record maps an IP address back to a hostname. Receivers expect every mail-sending IP to have one that matches its forward DNS.

/glossary/ptr-record

Protocols→

Return-Path

The Return-Path, or envelope sender, is the hidden address that bounces go to. SPF checks its domain, which often differs from the visible From.

/glossary/return-path

Security→

S/MIME (Secure/Multipurpose Internet Mail Extensions)

S/MIME uses personal certificates to digitally sign email and encrypt it end to end, so only the intended recipient can read it.

/glossary/s-mime

Deliverability→

Sender reputation

Sender reputation is mailbox providers' running assessment of a sending domain and IP, built from complaints, bounces, engagement and authentication.

/glossary/sender-reputation

Mailboxes→

Shared mailbox

A shared mailbox is one mailbox, like support@, that several people can open, read and reply from, with a single shared inbox state.

/glossary/shared-mailbox

Protocols→

SMTP (Simple Mail Transfer Protocol)

SMTP is the protocol that moves email between servers, and from your mail app to your provider when you send.

/glossary/smtp

Deliverability→

Soft bounce

A soft bounce is a temporary delivery failure, like a full mailbox or a busy server, signalled by a 4xx SMTP reply; the sender retries later.

/glossary/soft-bounce

Deliverability→

Spam trap

A spam trap is an email address that never asked for mail, run by a provider or blocklist to catch senders with poor list practices.

/glossary/spam-trap

Authentication→

SPF (Sender Policy Framework)

SPF is a DNS record listing the servers allowed to send email for a domain, so receivers can reject mail from anywhere else.

/glossary/spf

Authentication→

SPF 10-lookup limit

SPF allows at most 10 DNS lookups per evaluation; a record that needs more returns a permanent error, which receivers treat as an SPF failure.

/glossary/spf-lookup-limit

Authentication→

SPF flattening

SPF flattening replaces include mechanisms with the IP addresses they resolve to, cutting DNS lookups to get a record back under the 10-lookup limit.

/glossary/spf-flattening

Authentication→

SPF include

An SPF include pulls another domain's SPF record into yours, the usual way to authorise a provider like Google Workspace or Mailchimp to send as you.

/glossary/spf-include

DNS→

TLS-RPT (SMTP TLS Reporting)

TLS-RPT asks sending mail servers to report problems they hit establishing encrypted connections to your domain's mail servers.

/glossary/tls-rpt

Security→

Two-factor authentication

Two-factor authentication requires a second proof, such as a code from an authenticator app, on top of a password to sign in.

/glossary/two-factor-authentication

DNS→

TXT record

A TXT record holds free-form text in DNS. Email uses it for SPF, DKIM, DMARC, BIMI and MTA-STS, and services use it to verify domain ownership.

/glossary/txt-record

Authentication→

VMC and CMC (Verified Mark Certificate and Common Mark Certificate)

A VMC or CMC is a certificate that ties a logo to a domain, required by Gmail and Apple Mail before they display a BIMI logo.

/glossary/vmc

Want to see these on your own domain?

The free email checker reads your SPF, DKIM, DMARC, MX and MTA-STS records and explains each one in plain English.

Check your domain

Business email that lands in the inbox.

Every domain you run in one inbox, from $3 a mailbox. 14 days free, no card.