Practical guides to domains that must work.
Why each part of DNS, email authentication and monitoring matters — what breaks when it is missing, and how to check yours in under a minute.
Making SMTP Encryption Something You Can Rely On
STARTTLS is optional by design, and anyone in the network path can remove the offer. MTA-STS and TLS-RPT turn "we probably used TLS" into something you can require and verify.
Read the guide →The Bulk Sender Checklist for Gmail, Yahoo and Microsoft
Since February 2024 the large mailbox providers stopped treating authentication as optional. Here is the full checklist and what happens when you miss an item.
Read the guide →From p=none to p=reject Without Breaking Your Mail
Publishing an enforcing policy on day one is how legitimate mail disappears. Here is the staged path, plus what to do about forwarding and mailing lists.
Read the guide →The SPF 10-Lookup Limit and the Silent PermError
Add one more vendor to your SPF record and mail can start failing for everyone — with no bounce, no error in your sending dashboard and nothing in your logs.
Read the guide →SPF, DKIM and DMARC: How a Receiver Actually Decides
Follow one message from your server to somebody's inbox and see exactly where each protocol is consulted — and why two out of three is often the same as none.
Read the guide →Stop reading, start checking.
Run a free Domain Health report — no account needed — or monitor your domains continuously from $89 a year.