# Domain email hygiene checklist

Four checks on a domain's email setup. They work for any domain with a mailbox, whether it sends three emails a week or runs campaigns. Fill in the blanks as you go.

Domain: ____________   Date: ________
Everything that sends mail as this domain (mailbox provider, newsletter, invoicing, booking, website forms): ____________

Google and Microsoft require SPF, DKIM and DMARC from anyone who sends more than 5,000 messages a day to Gmail or Outlook.com addresses, and both recommend the same setup to every other sender.

## 1. SPF: one record that lists everything that sends

Look up the domain's TXT records with any DNS lookup tool.

- [ ] Exactly one record starts with `v=spf1`. Two records make the check return an error.
- [ ] Every service in the list above is in it.
- [ ] It needs 10 DNS lookups or fewer. Each `include:`, `a`, `mx` and `redirect` counts, and so does everything inside an include.

## 2. DKIM: signed by your own domain

Send a real message from your normal setup to an inbox you can open. Open its full headers (Gmail: More, then Show original. Outlook.com: More actions, then View, then View message details).

- [ ] The `DKIM-Signature` header has `d=` set to your domain or a subdomain of it.
- [ ] If `d=` names the mail provider, switch on signing for your own domain in the provider's admin settings. The provider's signature passes the DKIM check, and DMARC does not count it, because DMARC only counts a signature from the domain in your From address.
- [ ] Repeat for every other tool in the list. A tool can send with its own bounce address, so SPF passes without counting for DMARC, and your DKIM signature is what counts.

## 3. DMARC: a record, even at p=none

Look up the TXT record at `_dmarc.` plus your domain.

- [ ] One record, starting `v=DMARC1;`. Two records are both discarded.
- [ ] `p=none` or stricter. `p=none` asks receivers for no action while you collect reports.
- [ ] `rua=mailto:` plus the address of a mailbox you can search. Without `rua`, receivers do not send reports. If that mailbox is on another domain, that domain needs a TXT record named `<your domain>._report._dmarc.<its domain>` with the value `v=DMARC1`, or receivers ignore the address.
- [ ] Reports come as XML files, usually compressed, typically one a day from each receiver that sends them. A sender you do not recognise is a forgotten tool or someone using your address.

## 4. A real message to a fresh Gmail and a fresh Outlook inbox

- [ ] Make a new Gmail account and a new Outlook.com account that have never heard from this domain.
- [ ] Send one ordinary message to each, from the mailbox or tool that will send for real.
- [ ] Record where each landed: in Gmail, the tab or Spam; in Outlook.com, Inbox or Junk Email; or nowhere. Gmail: ______  Outlook.com: ______
- [ ] In the headers, find the Authentication-Results line. SPF, DKIM and DMARC should all read pass.

Checks 1 to 3 show whether the mail is authenticated. Where it lands also depends on content, how often you send and how recipients react, so only this check shows the result.

## A domain that never sends or receives mail

Three records say so:

- SPF at the domain: `v=spf1 -all`
- DMARC at `_dmarc.` plus the domain: `v=DMARC1; p=reject;`
- Null MX at the domain: a single MX record with preference 0 and target `.`

Leave the null MX off any domain that sends mail. Receivers may reject mail from a domain that publishes one.

Sources: RFC 7208 (SPF), RFC 6376 (DKIM), RFC 9989 and RFC 9990 (DMARC), RFC 7505 (null MX); Google, Email sender guidelines; Microsoft, the Outlook.com high-volume sender requirements post (April 2025) and the Microsoft Learn email authentication pages; UK NCSC, Protecting parked domains. Checked 5 October 2026.
