Domain email hygiene checklist

template

The problem

Every domain with an email address on it has a few DNS records that let receiving servers tell its mail from mail that uses its name without permission. Mail that fails those checks is more likely to land in spam or be rejected.

A wrong record can go unnoticed, because mail filed as spam does not bounce. I wanted one short list to run on any domain before it sends anything that matters, a freelancer's or a company's.

What I built

A checklist of four checks, each with what to look at and what a pass looks like.

SPF. One record listing every service that sends as the domain, so receivers can tell its mail from a forgery. A second record makes the check return an error.

DKIM, signed by the domain itself. Many mail services sign with their own domain until you switch on yours. That signature passes DKIM, and DMARC does not count it, because DMARC only counts a signature from the domain in the From address.

DMARC, even at p=none. It asks receivers for no action, and its rua address asks them for daily reports listing the servers that sent mail in the domain's name. A forgotten tool or a forged address shows up there.

A real message to a fresh Gmail and a fresh Outlook inbox. The first three show the mail is authenticated. Where it lands depends on more than that, so only looking shows the result.

The file also covers domains that never send mail, and names the standards and the Google and Microsoft pages behind each check.

Proof

domain-email-hygiene.md54 lines
# Domain email hygiene checklist

Four checks on a domain's email setup. They work for any domain with a mailbox, whether it sends three emails a week or runs campaigns. Fill in the blanks as you go.

Domain: ____________   Date: ________
Everything that sends mail as this domain (mailbox provider, newsletter, invoicing, booking, website forms): ____________

Google and Microsoft require SPF, DKIM and DMARC from anyone who sends more than 5,000 messages a day to Gmail or Outlook.com addresses, and both recommend the same setup to every other sender.

## 1. SPF: one record that lists everything that sends

Look up the domain's TXT records with any DNS lookup tool.

- [ ] Exactly one record starts with `v=spf1`. Two records make the check return an error.
- [ ] Every service in the list above is in it.
- [ ] It needs 10 DNS lookups or fewer. Each `include:`, `a`, `mx` and `redirect` counts, and so does everything inside an include.

## 2. DKIM: signed by your own domain

Send a real message from your normal setup to an inbox you can open. Open its full headers (Gmail: More, then Show original. Outlook.com: More actions, then View, then View message details).

- [ ] The `DKIM-Signature` header has `d=` set to your domain or a subdomain of it.
- [ ] If `d=` names the mail provider, switch on signing for your own domain in the provider's admin settings. The provider's signature passes the DKIM check, and DMARC does not count it, because DMARC only counts a signature from the domain in your From address.
- [ ] Repeat for every other tool in the list. A tool can send with its own bounce address, so SPF passes without counting for DMARC, and your DKIM signature is what counts.

## 3. DMARC: a record, even at p=none

Look up the TXT record at `_dmarc.` plus your domain.

- [ ] One record, starting `v=DMARC1;`. Two records are both discarded.
- [ ] `p=none` or stricter. `p=none` asks receivers for no action while you collect reports.
- [ ] `rua=mailto:` plus the address of a mailbox you can search. Without `rua`, receivers do not send reports. If that mailbox is on another domain, that domain needs a TXT record named `<your domain>._report._dmarc.<its domain>` with the value `v=DMARC1`, or receivers ignore the address.
- [ ] Reports come as XML files, usually compressed, typically one a day from each receiver that sends them. A sender you do not recognise is a forgotten tool or someone using your address.

## 4. A real message to a fresh Gmail and a fresh Outlook inbox

- [ ] Make a new Gmail account and a new Outlook.com account that have never heard from this domain.
- [ ] Send one ordinary message to each, from the mailbox or tool that will send for real.
- [ ] Record where each landed: in Gmail, the tab or Spam; in Outlook.com, Inbox or Junk Email; or nowhere. Gmail: ______  Outlook.com: ______
- [ ] In the headers, find the Authentication-Results line. SPF, DKIM and DMARC should all read pass.

Checks 1 to 3 show whether the mail is authenticated. Where it lands also depends on content, how often you send and how recipients react, so only this check shows the result.

## A domain that never sends or receives mail

Three records say so:

- SPF at the domain: `v=spf1 -all`
- DMARC at `_dmarc.` plus the domain: `v=DMARC1; p=reject;`
- Null MX at the domain: a single MX record with preference 0 and target `.`

Leave the null MX off any domain that sends mail. Receivers may reject mail from a domain that publishes one.

Sources: RFC 7208 (SPF), RFC 6376 (DKIM), RFC 9989 and RFC 9990 (DMARC), RFC 7505 (null MX); Google, Email sender guidelines; Microsoft, the Outlook.com high-volume sender requirements post (April 2025) and the Microsoft Learn email authentication pages; UK NCSC, Protecting parked domains. Checked 5 October 2026.

What happened

I run it before a new domain sends its first message. The method comes from checking the email setup of real domains in September and October 2026.

The file is the checklist with my own context taken out, so it works on any domain. I will add or drop a check as running it on more domains shows which ones turn something up.

Get in touch

Which of the four checks, if any, found something to fix on your domain?

alfred.seeliger@prospectfoundries.com