All tips
Fundamentals 2 min read

A monthly email authentication checklist

Authentication is not a project you finish. Thirty minutes a month keeps SPF, DKIM and DMARC from drifting out from under you.

Records that were correct last quarter break on their own: vendors change IP ranges, marketing signs up for a new platform, a key expires, someone adds a second SPF record. Here is a review that fits in half an hour.

Records

  • Confirm exactly one SPF record exists on each sending domain, and count its lookups against the limit of ten.
  • Confirm the DMARC record still resolves and still has the policy you think it has.
  • Look up each live DKIM selector and confirm the key is present and 2048-bit.
  • Check the rua mailbox is still receiving reports. Silence usually means a broken address, not a quiet month.

Reports

  • Scan the last few aggregate reports for sources that were not there last month.
  • Check the aligned-pass rate has not slipped.
  • Chase any sender still failing after it was supposedly fixed.

Inventory

  • Ask whether any new service started sending as your domain this month.
  • Remove SPF includes and DKIM selectors for services you have stopped using.
  • Confirm newly registered domains got the parked-domain records.

Certificates and adjacent checks

  • Check TLS certificate expiry on mail hosts.
  • Check your sending IPs against the major blocklists.
  • Confirm PTR records still resolve and forward-confirm.

Put it in the calendar with a named owner. An unowned checklist is a document; an owned one is a control. Continuous monitoring is better still, because it catches the change on the day it happens rather than up to a month later.

Run a full health check on your domain
operationschecklistmonitoring