Skip to main content
ShieldMarc
Engineering

Engineering articles and product updates

How ShieldMarc is built: threat detection internals, architecture choices, mission pieces, and public progress updates.

Why we publish this

Security products ask customers to trust claims they cannot easily verify. Publishing how the system works is the closest thing to a remedy: if we describe the detection logic, the architecture and the trade-offs we chose, a technical reader can judge whether the claims are plausible instead of taking a marketing page at face value.

These articles cover how DMARC aggregate reports are parsed and stored, how threat scoring distinguishes a genuine spoofing attempt from a forwarding artefact, and where the architecture makes deliberate compromises. They also cover mistakes, because a post that only describes decisions that worked is not an honest account of building anything.

Product updates are recorded here as they ship rather than collected into periodic announcements, so the history is a record of what actually changed and when. Readers evaluating ShieldMarc against alternatives are the intended audience as much as existing customers.