All systems operationalReal-time DNS, email and infrastructure monitoring
SupportAPIContactSign in
PLAYBOOK

Practical guides to domains that must work.

Why each part of DNS, email authentication and monitoring matters — what breaks when it is missing, and how to check yours in under a minute.

MTA-STS policy enforcing TLS between mail serversSending servergmail.comYour MXmail.example.com_mta-sts TXTv=STSv1; id=20260901https://mta-sts.example.commode: enforce · mx: mail.example.comSTARTTLS · valid certificate · TLS 1.2+Downgrade attempt → refused, reported via TLS-RPT
Email deliverability11 min read

Making SMTP Encryption Something You Can Rely On

STARTTLS is optional by design, and anyone in the network path can remove the offer. MTA-STS and TLS-RPT turn "we probably used TLS" into something you can require and verify.

Read the guide →
Bulk sender requirements checklistBulk sender requirements — Gmail · Yahoo · MicrosoftSPF and DKIM on every sending domainDMARC record (p=none is enough to start)From domain aligned with SPF or DKIMValid forward and reverse DNS (PTR)TLS on every connection!One-click List-Unsubscribe (RFC 8058)!Spam rate below 0.3 % in Postmaster Tools
Email deliverability10 min read

The Bulk Sender Checklist for Gmail, Yahoo and Microsoft

Since February 2024 the large mailbox providers stopped treating authentication as optional. Here is the full checklist and what happens when you miss an item.

Read the guide →
DMARC rollout timeline from none to rejectp=noneWeek 0–4Collect reports, fix sendersReports: mostly failquarantinepct=25Small share to spamReports: improvingquarantinepct=100All failures to spamReports: ≥ 98% passp=rejectEnforcedSpoofed mail rejectedReports: stableOnly move to the next stage when aggregate reports show your legitimate senders alignedv=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc@yourdomain.com; adkim=r; aspf=r
Email deliverability11 min read

From p=none to p=reject Without Breaking Your Mail

Publishing an enforcing policy on day one is how legitimate mail disappears. Here is the staged path, plus what to do about forwarding and mailing lists.

Read the guide →
SPF include tree exceeding the 10 DNS lookup limitv=spf1 include:… -all0include:_spf.google.com1include:sendgrid.net2include:spf.protection…3_netblocks.google.com4_netblocks2.google.com5include:… (vendor)6spf-a.outlook.com7spf-b.outlook.com8a:mail.vendor.net9mx10include:legacy-crm.io1111 / 10 lookupsPermError → SPF fails
Email deliverability9 min read

The SPF 10-Lookup Limit and the Silent PermError

Add one more vendor to your SPF record and mail can start failing for everyone — with no bounce, no error in your sending dashboard and nothing in your logs.

Read the guide →
How a receiving mail server checks SPF, DKIM and DMARCYour mail serverSPF recordIs this IP allowed?DKIM public keyIs the signature valid?DMARC policyDo they align? What now?Receiving serverGmail, Outlook, Yahoo…InboxSpamRejectSends a messagefrom you@example.com
Email deliverability10 min read

SPF, DKIM and DMARC: How a Receiver Actually Decides

Follow one message from your server to somebody's inbox and see exactly where each protocol is consulted — and why two out of three is often the same as none.

Read the guide →

Stop reading, start checking.

Run a free Domain Health report — no account needed — or monitor your domains continuously from $89 a year.