Email, SMS and Lifecycle · Deliverability audit (SPF, DKIM, DMARC, BIMI)
An inventory of every source sending as your domain, then a staged path to DMARC p=reject and a straight answer on whether BIMI earns its certificate.
About this service
About one domain in three that we audit publishes an SPF record resolving to more than the ten DNS lookups RFC 7208 permits. The record returns permerror, receivers treat SPF as absent, and nobody notices because the mail still mostly arrives. That is the shape of the problem at this level: authentication that is present, plausible, and not working.
What we look at:
Every source sending as your domain, not the ones you remember. We pull ninety days of DMARC aggregate reports into Parsedmarc or Dmarcian and read them, which is how the invoicing system, the recruiting tool, two former vendors and one developer's script get found. Then DKIM key length and rotation history, whether the d= domain aligns with the visible From, whether your Return-Path belongs to you or to a vendor, ARC handling on forwarded mail, and the subdomain policy tag — the one most often left implicit and then contradicted by a subdomain that publishes its own record.
Getting to enforcement:
p=none is not a policy, it is telemetry. The work is reaching p=quarantine and then p=reject without breaking a payroll notification, and that is a sequencing problem rather than a DNS problem. We stage it: authenticate every legitimate source first, watch aggregate reports across two full reporting cycles at each step, then tighten. On a large estate that takes six to ten weeks, and most of it is waiting for report data rather than editing records. Anyone offering p=reject next week is either publishing it blind or has a very small estate.
The bulk sender rules:
Gmail and Yahoo have required aligned SPF or DKIM, DMARC on the From domain, and RFC 8058 one-click unsubscribe from senders above five thousand messages a day since February 2024. Microsoft applied its own version to Outlook.com in 2025. The requirement that ends programs, though, is complaint rate: Postmaster Tools has to stay under 0.3 percent, and anything sustained above 0.1 percent is already a warning. We test that the unsubscribe header actually honours a POST, because a header that renders the button and then does nothing is worse than no header at all.
BIMI, and when to skip it:
BIMI needs DMARC at enforcement, a logo in SVG Tiny PS, and a certificate — a VMC against a registered trademark, or a CMC where the mark is not registered. The certificate runs into four figures a year, renewed annually. It earns that for a publisher whose logo is the reason a subscriber picks the message out of a crowded promotions tab. It rarely earns it for an organisation whose Hebrew wordmark is not the mark that was actually registered, and we will check the registration before recommending the spend rather than after.
Not included:
Subject lines, templates, or any opinion about your creative. No filter mysticism: we do not claim to know how Gmail's classifier weights anything, and consultants who do are guessing in a confident voice. Blocklist delisting is not part of this either — that is repair work with a different method and a different timeline.
Not for you if:
You want a report to hand a vendor so the vendor can be blamed. You want records changed this week without waiting for two reporting cycles. Or your actual problem is an old list and a high complaint rate, in which case authentication is correct, irrelevant, and we will tell you so on the call before you buy anything.
What you receive:
The record set to publish, in publishing order, with the wait between each step. A source inventory with a named owner against each entry. And the aggregate report pipeline running against a mailbox you control, so the monitoring outlives the engagement.