Lappu AI Journal

Practical writing on email security, infrastructure, engineering, and AI

Readable security explainers, implementation notes, and real-world email authentication guidance.

Featured Story

Latest writing

Vivek Uppal • Jun 21, 2026

Anatomy of a Small Business WordPress Compromise

A real incident response investigation into a compromised small business WordPress site, including visitor-facing social engineering, injected theme code, suspicious plugin-like persistence, session evidence, containment, and practical remediation lessons.

Vivek Uppal • May 23, 2026

Responsible AI Use in Tax and Accounting: Supervision, Assessment, and Governance

AI is not automatically forbidden in tax and accounting practices, but firms need competent supervision, human review, client data protections, and clear governance before adopting AI-assisted workflows.

Vivek Uppal • May 20, 2026

Securing Client Information in a Tax Practice: A WISP Is Only the Beginning

A Written Information Security Plan is the starting point for tax and accounting firm security, but real client protection depends on everyday controls around passwords, physical files, remote access, cloud tools, staff training, and accountability.

Lappu AI Staff • Mar 22, 2026

Hackers Abuse Microsoft Azure Monitor to Send "Legitimate" Scam Emails

Attackers are abusing Microsoft Azure Monitor alerts to send phishing emails from real Microsoft infrastructure, allowing the messages to pass SPF, DKIM, DMARC, and ARC while still carrying callback-phishing content.

Vivek Uppal • Mar 14, 2026

Why Tax and Accounting Firms Should Not Use Free Gmail, Yahoo, or Hotmail for Business Email

Free consumer email accounts may feel convenient, but they create real security, compliance, and credibility risks for tax and accounting firms. A domain-based business email system provides stronger protection against spoofing, better administrative control, improved deliverability, and more trust with clients.

Vivek Uppal • Mar 13, 2026

Is a WISP Enough for a Tax and Accounting Practice?

A Written Information Security Plan is an important compliance requirement for tax and accounting firms, but documentation alone does not secure client data. Real protection requires practical controls such as disk encryption, secure email practices, segmented Wi-Fi, password managers, and careful use of VPNs.

Vivek Uppal • Dec 10, 2025

Anatomy of a Phishing Email

Phishing clues included a suspicious subject, bold red formatting, and identical unsubscribe and reward links. Header analysis exposed mismatched IPs, nonexistent domains, unrelated hostnames, missing DKIM keys, and inconsistent ARC authentication. Together, these anomalies confirmed the email was fraudulent, highlighting the value of header inspection in detecting phishing attempts.

Vivek Uppal • Oct 15, 2025

WISPs for Small Tax & Accounting Firms: How Lappu AI Can Help

Small tax and accounting firms must maintain a Written Information Security Plan (WISP) to meet IRS and FTC Safeguards Rule requirements. A WISP assigns roles, secures data, manages vendors, and prepares incident response. Lappu AI streamlines creation via short size-specific questionnaires, delivering audit-ready plans and ongoing maintenance for small practices.

Vivek Uppal • Sep 30, 2025

Common Misconfigurations in Google Workspace Email Security (and How to Fix Them)

Most businesses unknowingly misconfigure Google Workspace email security. Here's how to fix SPF, DKIM, DMARC, and BIMI to keep your domain safe and trusted.

Lappu AI Staff • Sep 22, 2025

Case Studies: Real Email Misconfigurations We Fixed

Real-world email security issues, a DKIM misalignment in Microsoft 365 and a broken DMARC record, and how they impacted DMARC compliance. This highlights the importance of correctly configuring authentication records to ensure deliverability and visibility into potential spoofing.

Vivek Uppal • Aug 3, 2025

How to Read and Act on DMARC Reports

DMARC reports are one of the most powerful tools for protecting your domain from spoofing and abuse - yet many businesses overlook them. In this post, we walk you through how to interpret DMARC aggregate reports and understand what they reveal about your domain’s email-sending behavior. You'll learn how to spot alignment issues with SPF and DKIM, detect potential spoofing attempts, and decide how to act based on the data. We use real anonymized XML snippets and visual examples to break down common scenarios: when everything is aligned, when only DKIM passes, and when neither SPF nor DKIM aligns. You’ll also learn why alignment is critical, how to identify third-party senders misconfigured on your behalf, and what actions to take before tightening your DMARC policy. Whether you’re just starting out with DMARC or looking to make data-driven decisions, this guide gives you the confidence to protect your domain’s reputation.

Sushma Mukku • Aug 2, 2025

DNS: The Quiet Hero of Email Security

DNS (Domain Name System) has a critical role in email security. DNS translates domain names into IP addresses and is publicly accessible, meaning anyone—including attackers—can view your domain’s DNS records. During email delivery, DNS handles routing via MX records and powers authentication through SPF, DKIM, and DMARC. Misconfigured or missing DNS records can result in failed email delivery, spoofing, and phishing attacks.

Vivek Uppal • Aug 1, 2025

Demystifying DKIM: Protecting Email Integrity

DKIM is an email authentication protocol that ensures an email message **hasn’t been modified in transit and that it really came from your domain. In this blog post we will explore what DKIM is, how it works, and how to get it set up correctly for your domain.

Sushma Mukku • Jul 28, 2025

# How a Simple Domain Name Can Make or Break Email Security

Choosing a clear, brand-consistent domain and securing domain variants directly impacts email deliverability and anti-spoofing. We Highlight risks from look-alike domains, the need for SPF/DKIM/DMARC alignment, subdomain strategy for marketing vs. transactional mail, and practical steps: register typos, enforce DMARC p=reject, enable MTA-STS/TLS-RPT, and monitor abuse.

Vivek Uppal • Jul 27, 2025

Understanding DMARC: Your Defense Against Spoofing

A clear primer on DMARC as your frontline against spoofed email: how SPF/DKIM alignment and policy (none→quarantine→reject) work, what the tags mean, how to roll out safely using reports, and common pitfalls to avoid, so you can audit your domain and move to enforcement confidently.

Sushma Mukku • Jul 21, 2025

Phishing or Legit? A Real-Life Email Security Walkthrough.

Demonstrate how to verify the authenticity of suspicious emails using a real example involving an unsolicited message.

Vivek Uppal • Jul 17, 2025

What Is SPF and How to Get It correct

A plain-English guide to SPF: what it is, how the DNS TXT record authorizes senders, and how to build a correct policy - using include, ip4/ip6, and -all. Covers pitfalls (multiple records, 10-lookup limit), testing steps, and best practices that align SPF with DKIM/DMARC for reliable deliverability.

Vivek Uppal • Jul 7, 2025

Why Email security matters for Small Businesses

Small businesses are prime targets: one spoofed email can drain funds, expose PII, and erode trust. This post outlines common attacks (phishing, BEC), regulatory stakes, and a practical defense stack - SPF, DKIM, DMARC, MFA, training, and monitoring - with phased enforcement to protect deliverability and credibility.

Vivek Uppal • Jun 1, 2025

Email Spoofing: The Silent Threat to Every Organization

Email spoofing is one of the most overlooked yet potentially devastating security risks. It affects organizations of all sizes, yes even yours

Vivek Uppal • Mar 11, 2025

Why Organizations Need SOC 2 Compliance

Why organizations need and want SOC 2 compliance

Vivek Uppal • Mar 10, 2025

SOC 2 Type 1 vs. SOC 2 Type 2 Certification: Pros and Cons

SOC-2 Type 1 vs SOC 2Type 2 - Pros and Cons

Vivek Uppal • Mar 9, 2025

SOC 2 Certification: Steps to Get SOC 2 Certified

Comprehensive guide to getting SOC-2 certified in weeks.