A monthly email authentication checklist
Authentication is not a project you finish. Thirty minutes a month keeps SPF, DKIM and DMARC from drifting out from under you.
Records that were correct last quarter break on their own: vendors change IP ranges, marketing signs up for a new platform, a key expires, someone adds a second SPF record. Here is a review that fits in half an hour.
Records
- Confirm exactly one SPF record exists on each sending domain, and count its lookups against the limit of ten.
- Confirm the DMARC record still resolves and still has the policy you think it has.
- Look up each live DKIM selector and confirm the key is present and 2048-bit.
- Check the rua mailbox is still receiving reports. Silence usually means a broken address, not a quiet month.
Reports
- Scan the last few aggregate reports for sources that were not there last month.
- Check the aligned-pass rate has not slipped.
- Chase any sender still failing after it was supposedly fixed.
Inventory
- Ask whether any new service started sending as your domain this month.
- Remove SPF includes and DKIM selectors for services you have stopped using.
- Confirm newly registered domains got the parked-domain records.
Certificates and adjacent checks
- Check TLS certificate expiry on mail hosts.
- Check your sending IPs against the major blocklists.
- Confirm PTR records still resolve and forward-confirm.
Put it in the calendar with a named owner. An unowned checklist is a document; an owned one is a control. Continuous monitoring is better still, because it catches the change on the day it happens rather than up to a month later.
More on Fundamentals
Email authentication in plain English
SPF, DKIM and DMARC are three DNS records answering one question for a receiving server: should this message, claiming to be from your domain, be trusted?
DNS hygiene for email administrators
TTLs, string limits, propagation and stale records cause more email incidents than the protocols themselves. A short checklist for keeping the zone honest.
Locking down domains that never send mail
Parked domains, redirect domains and internal subdomains are spoofed precisely because nobody protects them. Three records fix it permanently.