Email, SMS and Lifecycle · Deliverability audit (SPF, DKIM, DMARC, BIMI)
Fourteen days, every sending source mapped, and a DMARC enforcement path you can defend — read against 30 days of your own aggregate reports.
About this service
Two weeks, and what you get at the end is a DMARC decision you can defend to your CTO. Most sending estates we open contain between 6 and 20 systems mailing as the corporate domain: the ESP, the CRM, the invoicing platform, the help desk, an HR tool nobody remembered, and two vendors who left three years ago. Publishing p=reject before that inventory exists is how a company stops receiving its own signed contracts.
How the audit runs:
We collect 30 days of DMARC aggregate reports before writing a word. If you have no RUA history, we publish the record and wait — there is no version of this work that produces trustworthy conclusions from one day of XML. Against that data we identify every legitimate source, check SPF against the 10 DNS lookup and 2 void lookup limits that quietly return permerror, confirm DKIM keys are 2048-bit and actually rotated, and establish whether forwarded mail survives via ARC or dies at mailing lists and corporate relays.
Then the part that authentication audits skip. We read Google Postmaster Tools and Microsoft SNDS over the same window and put domain reputation, complaint rate and TLS delivery next to the DNS findings. Gmail and Yahoo have enforced a 0.3 percent complaint ceiling on senders above 5,000 messages a day since February 2024, with 0.1 percent as the working target, and Microsoft applied its own requirements to Outlook.com in May 2025. A record set that validates cleanly while complaints sit at 0.28 percent is not a passing audit. It is a list problem with correct DNS, and we will say so in the first paragraph of the report.
On BIMI:
We scope it, and we tell you when not to buy it. BIMI requires a mark registered in a registry the certificate authorities accept, a Verified Mark Certificate from DigiCert or Entrust, artwork in the SVG Tiny Portable/Secure profile, and DMARC already enforcing at quarantine or reject. If your mark is still in examination at EUIPO, the answer is next year. We do not sell BIMI as a deliverability improvement, because it is not one.
Regulated senders:
For pharma and medtech we cover the send-side controls your MLR reviewers ask about: which subdomains carry HCP communication, whether transactional and promotional streams share a reputation they should not share, and whether unsubscribe handling meets Art. 130 of the Codice Privacy rather than a US reading of it. RFC 8058 one-click unsubscribe is checked as a header pair, not as a footer link.
What lands on your desk:
A source inventory with an owner and a disposition for each sender. A staged enforcement path with the conditions that must be true before each move, not a calendar. Findings on complaint rate, engagement decay and suppression hygiene, ordered by what they cost. Corrected records ready to publish, with a note on what breaks if they go out in the wrong order.
Not included:
We do not migrate ESPs, rebuild templates, write campaigns, or run the sending afterwards. No ongoing monitoring at this tier. We do not touch your zone; your team publishes and we verify.
Who this is not for:
Anyone who needs p=reject inside a month to close a compliance ticket. Anyone whose recovery plan is a fresh domain. Anyone who wants a grade from an online checker rather than an argument about their own data — checkers grade syntax, and syntax has never been the reason a campaign landed in Promotions.