All tools
IDENTITY / PERMISSION / OPERATIONS / RESPONSE

Check the control.
Attach the proof.

Turn deliverability readiness into an evidence review with applicability, named gaps, source-backed tests, owners, and an exportable remediation queue.

  • No fake grade
  • 28 controls
  • Local evidence
READINESS STATE / NOT A DELIVERY SCORE

Known blocker gaps require containment or remediation.

1 blocker gap · 17 unknown states · 0 evidence handoff gaps.

8/28controls verified0 verified without evidence
A completed checklist cannot prove inbox placement.

Receiver decisions remain contextual and dynamic. This audit tests whether the sender can establish controls, observe outcomes, and respond with evidence.

Verified8

Applicable controls marked verified

Known gaps3

1 blocker gap

Unknown state17

3 blocker unknowns

Not applicable0

Derived from scope or marked N/A

CONTROL COVERAGE

Readiness by evidence family.

Identity & authentication4/6

0 gaps · 2 unknown

Consent & suppression3/7

1 gaps · 3 unknown

Delivery operations1/8

0 gaps · 7 unknown

Monitoring & response0/7

2 gaps · 5 unknown

REMEDIATION QUEUE

20 open controls; start with blocker gap.

01
Bulk promotional traffic implements authenticated one-click unsubscribe

Implement RFC 8058 end to end; header syntax alone is not completion.

blockergap
02
The visible From domain aligns through DKIM or SPF

Align DKIM d= or the authenticated return path with the visible From identity.

blockerunknown
03
Purchased, scraped, appended, or otherwise unpermissioned lists are prohibited

Quarantine questionable sources, stop sending, and preserve the investigation trail.

blockerunknown
04
Complaint feedback is authenticated, processed, and durable

Repair complaint ingestion and stop affected traffic when complaint data is unavailable or rising.

blockerunknown
05
Relevant receiver feedback and reputation portals are configured

Register before incidents and document which traffic each portal does and does not represent.

highgap
06
The team can contain, diagnose, recover, and verify a delivery incident

Define stop conditions, evidence collection, escalation, staged recovery, and follow-up.

highgap
07
Forward/reverse DNS, TLS, and message format are verified

Escalate provider-owned DNS or TLS gaps and correct malformed message generation.

highunknown
08
Signup paths resist automated and third-party abuse

Add layered controls and use confirmation where unsolicited third-party signup risk is material.

highunknown
EVIDENCE CHECKLIST

Test, classify, and attach the handoff.

28 shown
Identity & authentication

Every production sender and identity is inventoried

blocker
Test and remediation details
TEST

List every platform, vendor, domain, subdomain, DKIM identity, return-path domain, and production IP pool that can send for this program.

EXPECTED EVIDENCE

Current inventory with owner, purpose, environment, provider, domain, and retirement status.

WHEN MISSING

Reconcile DNS, provider accounts, application code, and vendor contracts into one owned inventory.

Identity & authentication

SPF authorizes the intended MAIL FROM path without invalid policy

blocker
Test and remediation details
TEST

Resolve the actual envelope sender domain, trace include and redirect chains, and verify authorization plus lookup-budget behavior.

EXPECTED EVIDENCE

Timestamped DNS trace and a passing message header from each production route.

WHEN MISSING

Remove stale mechanisms, correct authorization, and keep the policy within RFC evaluation limits.

Identity & authentication

DKIM signatures verify for every production stream

blocker
Test and remediation details
TEST

Send through every route and verify a valid signature, current selector, appropriate key, and preserved signed headers.

EXPECTED EVIDENCE

Raw headers showing DKIM pass plus the exact selector and signing domain.

WHEN MISSING

Repair signing, selector DNS, canonicalization-breaking transformations, or key lifecycle gaps.

Identity & authentication

DMARC is published, parsed, and receiving aggregate evidence

blocker
Test and remediation details
TEST

Resolve the author domain's policy, validate tags and external reporting authorization, then confirm recent aggregate reports arrive.

EXPECTED EVIDENCE

Current record, report destination authorization, and a recent aggregate-report sample.

WHEN MISSING

Publish a valid policy, establish reporting, and stage enforcement only after legitimate flows are aligned.

Identity & authentication

The visible From domain aligns through DKIM or SPF

blocker
Test and remediation details
TEST

Inspect representative delivered headers for DMARC pass and identify which authenticated identifier aligns with the RFC 5322 From domain.

EXPECTED EVIDENCE

Raw headers from each stream and receiver showing alignment, not merely SPF or DKIM pass in isolation.

WHEN MISSING

Align DKIM d= or the authenticated return path with the visible From identity.

Identity & authentication

Forward/reverse DNS, TLS, and message format are verified

high
Test and remediation details
TEST

Confirm sending IP forward and reverse DNS, TLS use, one valid From mailbox, Message-ID, Date, and syntactically valid messages.

EXPECTED EVIDENCE

Provider configuration, live DNS evidence, TLS delivery evidence, and representative raw headers.

WHEN MISSING

Escalate provider-owned DNS or TLS gaps and correct malformed message generation.

Consent & suppression

Permission evidence is retained for every subscription source

blocker
Test and remediation details
TEST

Sample every acquisition source and reconstruct what the person saw, what they agreed to, when, where, and for which sender.

EXPECTED EVIDENCE

Source, timestamp, consent language/version, IP or request context where appropriate, and confirmation evidence.

WHEN MISSING

Stop sources that cannot establish expectation and repair consent-event retention.

Consent & suppression

Signup paths resist automated and third-party abuse

high
Test and remediation details
TEST

Test rate controls, confirmation, duplicate handling, typo feedback, disposable-risk policy, and abuse monitoring without blocking legitimate people blindly.

EXPECTED EVIDENCE

Abuse test results, form-event samples, alert thresholds, and the owner of the response process.

WHEN MISSING

Add layered controls and use confirmation where unsolicited third-party signup risk is material.

Consent & suppression

Purchased, scraped, appended, or otherwise unpermissioned lists are prohibited

blocker
Test and remediation details
TEST

Review imports, vendors, enrichment, partner transfers, sales workflows, and contract language for hidden list acquisition.

EXPECTED EVIDENCE

Policy, import approvals, source audit, and vendor obligations.

WHEN MISSING

Quarantine questionable sources, stop sending, and preserve the investigation trail.

Consent & suppression

Every subscription message has a clear working unsubscribe path

blocker
Test and remediation details
TEST

Use the delivered message as a recipient would, complete the body-link flow, and verify the correct subscription scope is suppressed.

EXPECTED EVIDENCE

Delivered-message capture, flow test, suppression event, and a subsequent no-send verification.

WHEN MISSING

Fix broken, hidden, misleading, authenticated-only, or scope-confused unsubscribe experiences.

Consent & suppression

Bulk promotional traffic implements authenticated one-click unsubscribe

blocker
Test and remediation details
TEST

Inspect List-Unsubscribe and List-Unsubscribe-Post, DKIM coverage, opaque recipient/list identity, HTTPS POST behavior, and suppression propagation.

EXPECTED EVIDENCE

Raw headers, receiver-style POST test, DKIM h= coverage, endpoint response, and queue suppression evidence.

WHEN MISSING

Implement RFC 8058 end to end; header syntax alone is not completion.

Consent & suppression

Suppression is authoritative across queues, products, imports, and vendors

blocker
Test and remediation details
TEST

Create unsubscribe, complaint, and permanent-failure test states, then attempt sends through every connected route and re-import path.

EXPECTED EVIDENCE

Cross-system test matrix, event timestamps, queue cancellation behavior, and exception process.

WHEN MISSING

Establish one authoritative policy and idempotent synchronization with failure alerts.

Consent & suppression

Complaint feedback is authenticated, processed, and durable

blocker
Test and remediation details
TEST

Verify available provider feedback loops and complaint events produce immediate durable suppression with idempotent processing.

EXPECTED EVIDENCE

Signed event sample, processing log, suppression record, and duplicate/replay test.

WHEN MISSING

Repair complaint ingestion and stop affected traffic when complaint data is unavailable or rising.

Delivery operations

Delivery and bounce events are authenticated, idempotent, and reconciled

blocker
Test and remediation details
TEST

Replay valid, duplicate, delayed, and out-of-order provider events; reconcile terminal recipient state against provider activity.

EXPECTED EVIDENCE

Webhook verification config, replay results, idempotency keys, lag metrics, and reconciliation output.

WHEN MISSING

Fix event authenticity, ordering, deduplication, retention, or reconciliation before trusting rates.

Delivery operations

Failures preserve raw SMTP evidence and map to cause-aware actions

high
Test and remediation details
TEST

Sample enhanced codes and raw replies across address, mailbox, routing, content, security, and policy outcomes.

EXPECTED EVIDENCE

Mapping table version, raw response samples, remote host, retry history, and final action.

WHEN MISSING

Separate recipient invalidity from sender, policy, content, and temporary infrastructure failures.

Delivery operations

Retry behavior is bounded by cause, receiver, and message value

high
Test and remediation details
TEST

Inspect retry eligibility, backoff, maximum age, receiver shaping, queue capacity, and terminal event generation.

EXPECTED EVIDENCE

Retry policy, queue configuration, incident sample, and terminal-state test.

WHEN MISSING

Stop infinite or indiscriminate retry and align lifetime with each stream's usefulness.

Delivery operations

Critical and subscription traffic have intentional reputation boundaries

high
Test and remediation details
TEST

Map domains, DKIM identities, return paths, pools, rate controls, and suppression policy by message stream.

EXPECTED EVIDENCE

Architecture diagram plus provider configuration and representative headers.

WHEN MISSING

Separate traffic where consent, urgency, volume, or risk differs materially.

Delivery operations

Volume changes and new identities have readiness gates

high
Test and remediation details
TEST

Review launch, migration, restart, and volume-increase procedures for authentication, audience quality, receiver mix, and live health gates.

EXPECTED EVIDENCE

Dated ramp plan, change approval, per-receiver metrics, pause rules, and owner.

WHEN MISSING

Stage wanted traffic, monitor response, and pause on evidence rather than following a fixed calendar blindly.

Delivery operations

Sending IP pool ownership and reputation responsibilities are known

high
Test and remediation details
TEST

Identify every outbound IP/pool, whether shared or dedicated, who controls neighbors and routing, and which monitoring is available.

EXPECTED EVIDENCE

Provider/pool inventory, allocation history, reverse DNS, traffic ownership, and escalation path.

WHEN MISSING

Choose shared or dedicated infrastructure based on control and traffic needs—not a universal volume slogan.

Delivery operations

Representative messages satisfy format, identity, and unsubscribe contracts

high
Test and remediation details
TEST

Inspect raw messages for one valid From mailbox, stable identity, MIME alternatives, links, signed headers, list headers, and source-size risks.

EXPECTED EVIDENCE

Raw fixtures from every template family and automated regression results.

WHEN MISSING

Turn message-format and required-header checks into pre-deployment tests.

Delivery operations

Redirect, tracking, image, and destination domains are inventoried and controlled

high
Test and remediation details
TEST

Resolve every URL hop in representative templates and verify ownership, TLS, destination consistency, and compromise monitoring.

EXPECTED EVIDENCE

Link-domain inventory, redirect traces, certificate evidence, and alert ownership.

WHEN MISSING

Remove unknown shorteners and stale destinations; isolate third-party domain risk.

Monitoring & response

Delivery outcomes are segmented by receiver, stream, source, and identity

high
Test and remediation details
TEST

Confirm dashboards preserve attempted counts, temporary and permanent failures, complaints, unsubscribe, and acceptance by actionable dimensions.

EXPECTED EVIDENCE

Dashboard/query links, field definitions, denominator contract, and sample incident view.

WHEN MISSING

Replace account-wide averages with segments that can identify a cause and owner.

Monitoring & response

Relevant receiver feedback and reputation portals are configured

high
Test and remediation details
TEST

Verify domain/IP registration, access ownership, data availability, and limitations for each material receiver.

EXPECTED EVIDENCE

Portal inventory, verified domains/IPs, access owners, screenshots or exports, and review cadence.

WHEN MISSING

Register before incidents and document which traffic each portal does and does not represent.

Monitoring & response

Raw headers, SMTP replies, provider events, and change context are retained

high
Test and remediation details
TEST

Retrieve representative evidence from a recent message and incident without relying on a transient dashboard.

EXPECTED EVIDENCE

Retention policy, storage location, redaction/access controls, and retrieval test.

WHEN MISSING

Preserve enough normalized and raw evidence to reproduce classification and timeline.

Monitoring & response

Material delivery changes alert a named owner with receiver context

high
Test and remediation details
TEST

Trigger or simulate alerts for event-pipeline lag, auth failure, bounce/complaint changes, receiver deferrals, and suppression failure.

EXPECTED EVIDENCE

Alert definitions, thresholds, routing, test events, acknowledgement, and escalation.

WHEN MISSING

Create actionable alerts tied to denominators, baseline, receiver, stream, and runbook.

Monitoring & response

DNS, infrastructure, audience, and template changes are timestamped

operational
Test and remediation details
TEST

Take a recent delivery chart and identify deployments, DNS edits, imports, campaigns, vendor changes, and pool changes on the same timeline.

EXPECTED EVIDENCE

Change records with timestamp, owner, scope, before/after evidence, and rollback.

WHEN MISSING

Connect deployment and marketing change records to delivery monitoring.

Monitoring & response

The team can contain, diagnose, recover, and verify a delivery incident

high
Test and remediation details
TEST

Tabletop a receiver-specific deferral, authentication failure, complaint spike, and compromised source.

EXPECTED EVIDENCE

Runbook, exercise notes, contacts, containment authority, recovery gates, and retrospective owner.

WHEN MISSING

Define stop conditions, evidence collection, escalation, staged recovery, and follow-up.

Monitoring & response

Readiness is re-evaluated after material change and on a defined cadence

operational
Test and remediation details
TEST

Find the previous audit, its evidence, closed gaps, accepted risks, and the event that schedules the next review.

EXPECTED EVIDENCE

Dated audit history, sign-off, exceptions, remediation tickets, and next review trigger.

WHEN MISSING

Treat this checklist as a living control review, not a one-time launch ceremony.

INTEGRITY REVIEW

1 blocking integrity issue.

1 blocker control is a known gap

Contain affected traffic where necessary and remediate these controls before treating the program as launch-ready.

3 blocker states are unknown

Unknown is not a pass. Execute the documented test and attach evidence.

Readiness is not inbox placement

Authentication and operational controls improve observability and compliance with sender expectations, but receiver decisions remain contextual.

AUDIT HANDOFF

Export scope, applicability, statuses, evidence, owners, queue, and findings.

Unknown is not a pass, and not applicable needs a reason.

Verified means the test was performed and evidence is attached. Gap means the control is known to fail or is absent. Unknown means the team has not established the state. N/A is reserved for controls outside the declared stream scope.

VerifiedTested with evidenceMaintain
GapKnown missing or failingRemediate
UnknownState not establishedTest
N/AScope excludes controlExplain

A checkbox should point to something another operator can reproduce.

Useful evidence includes timestamped DNS answers, raw headers, signed provider events, query definitions, suppression tests, screenshots with scope, change tickets, runbook exercises, and named owners. Never paste secrets or unnecessary recipient data.

SPF, DKIM, and DMARC must be proven on actual production routes.

A DNS record existing somewhere is not the test. Inspect the envelope domain, signature, visible From identity, alignment, receiver result, and report flow for every production stream.

  1. 01
    Inventory

    Know every sender, source, domain, pool, vendor, and stream.

  2. 02
    Test

    Exercise the real message, event, unsubscribe, suppression, and retry paths.

  3. 03
    Observe

    Segment outcomes and preserve receiver, identity, and raw diagnostic context.

  4. 04
    Contain

    Give an owner authority to stop risky traffic and protect critical streams.

  5. 05
    Verify recovery

    Resume deliberately and confirm the affected evidence changes.

Why is there no percentage score or letter grade?+

Control priorities, scope, and evidence are not interchangeable points. One blocker can matter more than many advisory checks.

Does verified authentication guarantee inbox placement?+

No. Authentication establishes identities and policy inputs; receivers also evaluate reputation, recipient behavior, content, traffic patterns, and other signals.

Can a control be marked verified without evidence text?+

The interface allows it but flags the missing handoff. Verified should ultimately point to reproducible proof.

When is one-click unsubscribe applicable?+

The audit applies it to subscription or mixed traffic when the sender declares bulk traffic to personal Gmail. Other receiver or provider requirements may also apply.

How often should the audit be repeated?+

After material sender, provider, domain, list-source, message, or suppression changes and on the organization's documented review cadence.