All tools
AUTHENTICATION / PERMISSION / MESSAGE / OPERATIONS

Score the evidence.
Expose the risk.

Inspect a final message and its operating signals without turning a heuristic into an inbox promise.

  • Transparent point ledger
  • Raw-header inspection
  • Ordered repair queue
SCORE97/100
STRONG MECHANICAL EVIDENCE

The fixture clears this model's mechanical controls.

This score describes the pasted fixture and declared operating conditions. It does not measure private reputation, guarantee acceptance, or predict inbox placement.

Evidence coverage85%
14 observed · 8 declared · 0 missing
Blocking failures0

Failed controls that can make the message ineligible or unsafe to send.

Review items1

Warnings and unknowns that require evidence or a deliberate decision.

Link domains1

links.northstar.example

HTML size688 B

Encoded MIME size and provider transformations can be larger.

Score composition
Applicable points only
Evidence and deduction ledger
Identity · Passed

SPF result from the received route

Authentication-Results reports spf=pass.

6/6
Identity · Passed

DKIM signature validates

Authentication-Results reports dkim=pass.

7/7
Identity · Passed

DMARC passes with visible-From alignment

Authentication-Results reports dmarc=pass.

9/9
Identity · Passed

Visible From identity is parseable

Observed From domain: news.northstar.example.

4/4
Identity · Passed

Forward and reverse DNS evidence

Declared verified by the operator.

2/2
Operations · Passed

TLS observed on the delivery route

Declared verified by the operator.

2/2
Permission · Passed

Recipient relationship supports this traffic

Declared confirmed opt-in with explicit recipient action.

8/8
Permission · Passed

Visible body unsubscribe

A visible unsubscribe or preference link was found in the rendered HTML.

5/5
Permission · Passed

One-click unsubscribe headers

List-Unsubscribe contains HTTPS and List-Unsubscribe-Post declares One-Click.

6/6
Permission · Passed

Unsubscribe headers covered by DKIM

The parsed DKIM h= list includes both unsubscribe fields.

3/3
Permission · Passed

Suppression propagation is verified

Declared: opt-outs and terminal failures stop future sends.

3/3
Message · Passed

Core message fields are present

Date, Message-ID, MIME-Version, and From were found.

5/5
Message · Passed

Plain-text and HTML alternatives are signaled

Content-Type declares multipart/alternative.

3/3
Message · Passed

Links use reviewable destinations

3 links across 1 absolute domains; no narrow mechanical link warning.

5/5
Message · Passed

Images have alternative text

All 1 images include an alt attribute.

3/3
Message · Passed

Copy avoids mechanical deception signals

No narrow mechanical copy warning was triggered.

3/3
Message · Passed

Display name identifies the sender

Observed display name: Northstar Updates.

3/3
Message · Passed

HTML payload stays reviewable

688 B of HTML was pasted.

3/3
Operations · Review

Spam complaint rate is controlled

Declared rate: 0.12%; below 0.3% but above the model's full-credit range.

Define the receiver-specific numerator and denominator, stop risky sources, and suppress complainants.
4/7
Operations · Passed

Hard-bounce rate is controlled

Declared rate: 0.42%.

4/4
Operations · Passed

Volume change has a controlled ramp

Declared: a planned ramp is in use.

4/4
Operations · Passed

Complaint signals have an owner

Declared: complaint telemetry is monitored.

3/3
Receiver requirement lens
Scope-aware, not placement predictions
GmailPersonal Gmail · high-volume lens

Mechanical requirements appear represented.

The lens checks SPF, DKIM, DMARC alignment, low complaints, and subscription one-click mechanics for the declared high-volume profile.

Google's scope and private enforcement signals remain receiver-controlled.
Yahoo / AOLBulk sender lens

The fixture covers the scored sender controls.

The lens separates all-sender authentication and DNS basics from bulk authentication and marketing unsubscribe controls.

Yahoo does not publish a universal volume threshold for its bulk classification.
Outlook.comConsumer domains · high-volume lens

The scored authentication trio passes.

For the declared high-volume profile, this lens checks SPF, DKIM, and DMARC results from the pasted received message.

Acceptance and placement still depend on Microsoft's broader filtering and sender history.
Ordered repair queue
1 actions
  1. 01
    Spam complaint rate is controlled

    Define the receiver-specific numerator and denominator, stop risky sources, and suppress complainants.

    Review
HANDOFF, NOT CERTIFICATION

Keep the score, evidence boundary, and next actions together.

The manifest records every point and declared input so another operator can reproduce the result. Receiver reputation and placement remain outside this browser-only model.

Read the full agent guide

A score is a triage instrument, not a receiver verdict.

The model rewards observable message evidence and clearly marked operating declarations. It cannot see private reputation systems, recipient-level engagement, historical traffic, current blocklists, provider configuration, DNS state, or the final SMTP conversation.

Use it to find missing controls and preserve a repeatable handoff. Use delivered fixtures, provider telemetry, receiver portals, DNS traces, and SMTP responses to establish what happened in production.

  1. 01
    Receive

    Send through the real production route and copy headers from the received message.

  2. 02
    Declare

    Record traffic purpose, permission, DNS/TLS evidence, complaints, bounces, and volume change.

  3. 03
    Inspect

    Review authentication, alignment, unsubscribe, structure, links, and message-size deductions.

  4. 04
    Repair

    Resolve failed identity and recipient-rights controls before cosmetic content warnings.

  5. 05
    Verify

    Resend the final build and archive receiver-specific evidence with the revision.

What does the score leave out?

Anything the browser cannot establish from the pasted fixture or your explicit declarations remains outside the claim.

Does 100 mean the email will reach the inbox?+

No. It means the applicable checks in this limited model earned all available points. Receivers still evaluate reputation, recipient behavior, traffic history, content, security signals, and context this tool cannot observe.

Why is evidence coverage separate from the score?+

A plausible declaration and a received-message observation are not equally strong. Coverage shows how much of the result comes from observable headers or content versus declarations or missing evidence.

Why can authentication failures outweigh content warnings?+

Authentication and alignment can determine eligibility under receiver requirements and protect identity. Rewriting a phrase cannot compensate for failed sender identity or broken opt-out mechanics.

Should transactional mail include one-click unsubscribe?+

Not universally. The tool marks subscription-only unsubscribe controls not applicable for a transactional profile. Classification must reflect the real purpose and recipient expectation, not a label chosen to avoid a control.

Is 0.3% a safe complaint target?+

No. Gmail and Yahoo publish 0.3% as an important upper boundary in specified contexts, not a healthy target. The scorer reserves full points for a lower declared rate and still requires receiver-specific denominator definitions.

Can pasted headers contain sensitive data?+

Yes. Raw headers can include recipient addresses, message identifiers, routing details, and unsubscribe tokens. Redact unnecessary personal data and secrets before exporting or sharing the result.