Sample Email Deliverability Audit Report

This sample shows the level of specificity included in the 48-hour audit. The real report is customized to the submitted domain, sender tools, message headers, DNS records, and business symptoms.

Example outcome: mixed public DNS risk, incomplete sender inventory, DMARC monitor-only policy, and unclear DKIM alignment across marketing and outbound tools.

1. Executive Summary

The submitted domain has partial authentication in place, but the setup is not yet trustworthy enough for tighter DMARC enforcement. The highest-risk issue is not one DNS record; it is that active senders have not been mapped against real message headers. The first repair priority is to confirm every platform sending as the domain, then clean SPF and DKIM alignment before moving DMARC beyond monitoring.

2. Audit Scope

Area Status Why it matters
MX routing Healthy Receiving mail servers are published and reachable.
SPF Review Visible record exists, but lookup count and sender coverage need confirmation.
DKIM Review Public selector discovery is inconclusive without real headers.
DMARC Fix next Policy is p=none and aggregate reporting is incomplete.
Sender inventory Fix first Google Workspace, marketing tools, outbound tools, and transactional senders must be mapped.

3. Priority Findings

  1. Sender inventory is incomplete. The domain appears to send through multiple systems, but not every sender is confirmed in SPF, DKIM, and DMARC alignment evidence.
  2. SPF may become brittle. The record should be checked for DNS lookup count, stale includes, and senders that are authorized but no longer active.
  3. DKIM cannot be trusted from public DNS alone. Real headers are required to confirm signing domain, selector, and alignment for each sending platform.
  4. DMARC is not ready for enforcement. Moving directly to quarantine or reject could block legitimate mail until sender alignment is proven.

4. Header Evidence Requested

The audit asks for one recent delivered or spam-folder header from each active sender: Google Workspace or Microsoft 365, CRM or marketing platform, outbound tool, and transactional system. We do not need mailbox passwords.

5. Repair Plan

  1. Collect and label headers by sender platform.
  2. Build a sender inventory showing visible From domain, return-path domain, DKIM signing domain, and sending IP or provider.
  3. Remove stale SPF includes and keep the record below provider lookup limits.
  4. Enable or repair DKIM for every active platform.
  5. Add or verify DMARC aggregate reporting before enforcement.
  6. Move from p=none only after legitimate senders pass alignment consistently.
Want us to handle the diagnosis?The audit turns these checks into a prioritized repair plan for your exact domain and sender stack.

Start Audit – $399

6. Final Deliverable

The final report includes a prioritized repair list, DNS record recommendations, platform-specific notes, risk warnings, and an approval-ready plan for whoever manages DNS or email tools.

What The Audit Does Not Promise

No honest provider can guarantee inbox placement. The audit identifies technical sender-trust issues that can be verified and repaired.