Applicable controls marked verified
Check the control.
Attach the proof.
Turn deliverability readiness into an evidence review with applicability, named gaps, source-backed tests, owners, and an exportable remediation queue.
- No fake grade
- 28 controls
- Local evidence
Known blocker gaps require containment or remediation.
1 blocker gap · 17 unknown states · 0 evidence handoff gaps.
Receiver decisions remain contextual and dynamic. This audit tests whether the sender can establish controls, observe outcomes, and respond with evidence.
1 blocker gap
3 blocker unknowns
Derived from scope or marked N/A
Readiness by evidence family.
0 gaps · 2 unknown
1 gaps · 3 unknown
0 gaps · 7 unknown
2 gaps · 5 unknown
20 open controls; start with blocker gap.
Implement RFC 8058 end to end; header syntax alone is not completion.
Align DKIM d= or the authenticated return path with the visible From identity.
Quarantine questionable sources, stop sending, and preserve the investigation trail.
Repair complaint ingestion and stop affected traffic when complaint data is unavailable or rising.
Register before incidents and document which traffic each portal does and does not represent.
Define stop conditions, evidence collection, escalation, staged recovery, and follow-up.
Escalate provider-owned DNS or TLS gaps and correct malformed message generation.
Add layered controls and use confirmation where unsolicited third-party signup risk is material.
Test, classify, and attach the handoff.
Every production sender and identity is inventoried
Test and remediation details
List every platform, vendor, domain, subdomain, DKIM identity, return-path domain, and production IP pool that can send for this program.
Current inventory with owner, purpose, environment, provider, domain, and retirement status.
Reconcile DNS, provider accounts, application code, and vendor contracts into one owned inventory.
SPF authorizes the intended MAIL FROM path without invalid policy
Test and remediation details
Resolve the actual envelope sender domain, trace include and redirect chains, and verify authorization plus lookup-budget behavior.
Timestamped DNS trace and a passing message header from each production route.
Remove stale mechanisms, correct authorization, and keep the policy within RFC evaluation limits.
DKIM signatures verify for every production stream
Test and remediation details
Send through every route and verify a valid signature, current selector, appropriate key, and preserved signed headers.
Raw headers showing DKIM pass plus the exact selector and signing domain.
Repair signing, selector DNS, canonicalization-breaking transformations, or key lifecycle gaps.
DMARC is published, parsed, and receiving aggregate evidence
Test and remediation details
Resolve the author domain's policy, validate tags and external reporting authorization, then confirm recent aggregate reports arrive.
Current record, report destination authorization, and a recent aggregate-report sample.
Publish a valid policy, establish reporting, and stage enforcement only after legitimate flows are aligned.
The visible From domain aligns through DKIM or SPF
Test and remediation details
Inspect representative delivered headers for DMARC pass and identify which authenticated identifier aligns with the RFC 5322 From domain.
Raw headers from each stream and receiver showing alignment, not merely SPF or DKIM pass in isolation.
Align DKIM d= or the authenticated return path with the visible From identity.
Forward/reverse DNS, TLS, and message format are verified
Test and remediation details
Confirm sending IP forward and reverse DNS, TLS use, one valid From mailbox, Message-ID, Date, and syntactically valid messages.
Provider configuration, live DNS evidence, TLS delivery evidence, and representative raw headers.
Escalate provider-owned DNS or TLS gaps and correct malformed message generation.
Permission evidence is retained for every subscription source
Test and remediation details
Sample every acquisition source and reconstruct what the person saw, what they agreed to, when, where, and for which sender.
Source, timestamp, consent language/version, IP or request context where appropriate, and confirmation evidence.
Stop sources that cannot establish expectation and repair consent-event retention.
Signup paths resist automated and third-party abuse
Test and remediation details
Test rate controls, confirmation, duplicate handling, typo feedback, disposable-risk policy, and abuse monitoring without blocking legitimate people blindly.
Abuse test results, form-event samples, alert thresholds, and the owner of the response process.
Add layered controls and use confirmation where unsolicited third-party signup risk is material.
Purchased, scraped, appended, or otherwise unpermissioned lists are prohibited
Test and remediation details
Review imports, vendors, enrichment, partner transfers, sales workflows, and contract language for hidden list acquisition.
Policy, import approvals, source audit, and vendor obligations.
Quarantine questionable sources, stop sending, and preserve the investigation trail.
Every subscription message has a clear working unsubscribe path
Test and remediation details
Use the delivered message as a recipient would, complete the body-link flow, and verify the correct subscription scope is suppressed.
Delivered-message capture, flow test, suppression event, and a subsequent no-send verification.
Fix broken, hidden, misleading, authenticated-only, or scope-confused unsubscribe experiences.
Bulk promotional traffic implements authenticated one-click unsubscribe
Test and remediation details
Inspect List-Unsubscribe and List-Unsubscribe-Post, DKIM coverage, opaque recipient/list identity, HTTPS POST behavior, and suppression propagation.
Raw headers, receiver-style POST test, DKIM h= coverage, endpoint response, and queue suppression evidence.
Implement RFC 8058 end to end; header syntax alone is not completion.
Suppression is authoritative across queues, products, imports, and vendors
Test and remediation details
Create unsubscribe, complaint, and permanent-failure test states, then attempt sends through every connected route and re-import path.
Cross-system test matrix, event timestamps, queue cancellation behavior, and exception process.
Establish one authoritative policy and idempotent synchronization with failure alerts.
Complaint feedback is authenticated, processed, and durable
Test and remediation details
Verify available provider feedback loops and complaint events produce immediate durable suppression with idempotent processing.
Signed event sample, processing log, suppression record, and duplicate/replay test.
Repair complaint ingestion and stop affected traffic when complaint data is unavailable or rising.
Delivery and bounce events are authenticated, idempotent, and reconciled
Test and remediation details
Replay valid, duplicate, delayed, and out-of-order provider events; reconcile terminal recipient state against provider activity.
Webhook verification config, replay results, idempotency keys, lag metrics, and reconciliation output.
Fix event authenticity, ordering, deduplication, retention, or reconciliation before trusting rates.
Failures preserve raw SMTP evidence and map to cause-aware actions
Test and remediation details
Sample enhanced codes and raw replies across address, mailbox, routing, content, security, and policy outcomes.
Mapping table version, raw response samples, remote host, retry history, and final action.
Separate recipient invalidity from sender, policy, content, and temporary infrastructure failures.
Retry behavior is bounded by cause, receiver, and message value
Test and remediation details
Inspect retry eligibility, backoff, maximum age, receiver shaping, queue capacity, and terminal event generation.
Retry policy, queue configuration, incident sample, and terminal-state test.
Stop infinite or indiscriminate retry and align lifetime with each stream's usefulness.
Critical and subscription traffic have intentional reputation boundaries
Test and remediation details
Map domains, DKIM identities, return paths, pools, rate controls, and suppression policy by message stream.
Architecture diagram plus provider configuration and representative headers.
Separate traffic where consent, urgency, volume, or risk differs materially.
Volume changes and new identities have readiness gates
Test and remediation details
Review launch, migration, restart, and volume-increase procedures for authentication, audience quality, receiver mix, and live health gates.
Dated ramp plan, change approval, per-receiver metrics, pause rules, and owner.
Stage wanted traffic, monitor response, and pause on evidence rather than following a fixed calendar blindly.
Sending IP pool ownership and reputation responsibilities are known
Test and remediation details
Identify every outbound IP/pool, whether shared or dedicated, who controls neighbors and routing, and which monitoring is available.
Provider/pool inventory, allocation history, reverse DNS, traffic ownership, and escalation path.
Choose shared or dedicated infrastructure based on control and traffic needs—not a universal volume slogan.
Representative messages satisfy format, identity, and unsubscribe contracts
Test and remediation details
Inspect raw messages for one valid From mailbox, stable identity, MIME alternatives, links, signed headers, list headers, and source-size risks.
Raw fixtures from every template family and automated regression results.
Turn message-format and required-header checks into pre-deployment tests.
Redirect, tracking, image, and destination domains are inventoried and controlled
Test and remediation details
Resolve every URL hop in representative templates and verify ownership, TLS, destination consistency, and compromise monitoring.
Link-domain inventory, redirect traces, certificate evidence, and alert ownership.
Remove unknown shorteners and stale destinations; isolate third-party domain risk.
Delivery outcomes are segmented by receiver, stream, source, and identity
Test and remediation details
Confirm dashboards preserve attempted counts, temporary and permanent failures, complaints, unsubscribe, and acceptance by actionable dimensions.
Dashboard/query links, field definitions, denominator contract, and sample incident view.
Replace account-wide averages with segments that can identify a cause and owner.
Relevant receiver feedback and reputation portals are configured
Test and remediation details
Verify domain/IP registration, access ownership, data availability, and limitations for each material receiver.
Portal inventory, verified domains/IPs, access owners, screenshots or exports, and review cadence.
Register before incidents and document which traffic each portal does and does not represent.
Raw headers, SMTP replies, provider events, and change context are retained
Test and remediation details
Retrieve representative evidence from a recent message and incident without relying on a transient dashboard.
Retention policy, storage location, redaction/access controls, and retrieval test.
Preserve enough normalized and raw evidence to reproduce classification and timeline.
Material delivery changes alert a named owner with receiver context
Test and remediation details
Trigger or simulate alerts for event-pipeline lag, auth failure, bounce/complaint changes, receiver deferrals, and suppression failure.
Alert definitions, thresholds, routing, test events, acknowledgement, and escalation.
Create actionable alerts tied to denominators, baseline, receiver, stream, and runbook.
DNS, infrastructure, audience, and template changes are timestamped
Test and remediation details
Take a recent delivery chart and identify deployments, DNS edits, imports, campaigns, vendor changes, and pool changes on the same timeline.
Change records with timestamp, owner, scope, before/after evidence, and rollback.
Connect deployment and marketing change records to delivery monitoring.
The team can contain, diagnose, recover, and verify a delivery incident
Test and remediation details
Tabletop a receiver-specific deferral, authentication failure, complaint spike, and compromised source.
Runbook, exercise notes, contacts, containment authority, recovery gates, and retrospective owner.
Define stop conditions, evidence collection, escalation, staged recovery, and follow-up.
Readiness is re-evaluated after material change and on a defined cadence
Test and remediation details
Find the previous audit, its evidence, closed gaps, accepted risks, and the event that schedules the next review.
Dated audit history, sign-off, exceptions, remediation tickets, and next review trigger.
Treat this checklist as a living control review, not a one-time launch ceremony.
1 blocking integrity issue.
Contain affected traffic where necessary and remediate these controls before treating the program as launch-ready.
Unknown is not a pass. Execute the documented test and attach evidence.
Authentication and operational controls improve observability and compliance with sender expectations, but receiver decisions remain contextual.
Export scope, applicability, statuses, evidence, owners, queue, and findings.
Unknown is not a pass, and not applicable needs a reason.
Verified means the test was performed and evidence is attached. Gap means the control is known to fail or is absent. Unknown means the team has not established the state. N/A is reserved for controls outside the declared stream scope.
A checkbox should point to something another operator can reproduce.
Useful evidence includes timestamped DNS answers, raw headers, signed provider events, query definitions, suppression tests, screenshots with scope, change tickets, runbook exercises, and named owners. Never paste secrets or unnecessary recipient data.
SPF, DKIM, and DMARC must be proven on actual production routes.
A DNS record existing somewhere is not the test. Inspect the envelope domain, signature, visible From identity, alignment, receiver result, and report flow for every production stream.
- 01Inventory
Know every sender, source, domain, pool, vendor, and stream.
- 02Test
Exercise the real message, event, unsubscribe, suppression, and retry paths.
- 03Observe
Segment outcomes and preserve receiver, identity, and raw diagnostic context.
- 04Contain
Give an owner authority to stop risky traffic and protect critical streams.
- 05Verify recovery
Resume deliberately and confirm the affected evidence changes.
Why is there no percentage score or letter grade?+
Control priorities, scope, and evidence are not interchangeable points. One blocker can matter more than many advisory checks.
Does verified authentication guarantee inbox placement?+
No. Authentication establishes identities and policy inputs; receivers also evaluate reputation, recipient behavior, content, traffic patterns, and other signals.
Can a control be marked verified without evidence text?+
The interface allows it but flags the missing handoff. Verified should ultimately point to reproducible proof.
When is one-click unsubscribe applicable?+
The audit applies it to subscription or mixed traffic when the sender declares bulk traffic to personal Gmail. Other receiver or provider requirements may also apply.
How often should the audit be repeated?+
After material sender, provider, domain, list-source, message, or suppression changes and on the organization's documented review cadence.