Google Workspace SPF, DKIM, and DMARC setup review
Review Google Workspace authentication with cautious DNS-change guidance and official source links.
Read guidePractical, cautious guides for DMARC, SPF, DKIM, BIMI, MTA-STS, and sender-readiness diagnostics. Start with public DNS signals, then review changes with your DNS/admin team.
Run a public DNS diagnostic first, then use the guides below to understand what each finding means.
Check the public sender-auth records mailbox providers expect.
Keep one URL with evidence, owner steps, and decisions.
Add human review, provider context, and verification steps.
Review DMARC policy strength before a high-volume send.
Overall sender readiness
Needs attention
Sample output: one warning and one fail mean this domain is not campaign-ready yet.
The scan becomes a focused work surface: evidence, owner action, verification, and the paid context a public lookup cannot infer.
Review Google Workspace authentication with cautious DNS-change guidance and official source links.
Read guideCheck Microsoft 365 authentication and Outlook.com high-volume sender readiness signals.
Read guideReview Shopify sender email authentication, Klaviyo branded sending domains, DMARC alignment, and ecommerce DNS caveats.
Read guideReview Mailchimp Marketing and Transactional authentication, DKIM CNAME records, DMARC TXT records, and DNS caveats before changing sender records.
Read guideReview Twilio SendGrid domain authentication, automated security, return-path and link-branding records, and DMARC caveats before changing sender DNS.
Read guideReview Mailgun domain verification, SPF/DKIM DNS records, optional MX/CNAME records, and DMARC staging before changing sender DNS.
Read guideReview Postmark domain verification, DKIM, SPF alignment, custom Return-Path, and DMARC caveats before changing sender DNS.
Read guideReview HubSpot email sending domains, generated DKIM CNAME records, SPF include merging, DMARC inheritance, and connected inbox caveats before changing sender DNS.
Read guideReview Brevo sender-domain authentication, Brevo code TXT records, DKIM TXT/CNAME options, DMARC records, and dedicated-IP SPF caveats before changing sender DNS.
Read guideReview ActiveCampaign sending domains, DKIM, Mailserver Domain/SPF alignment, DMARC staging, and strict-policy caveats before changing sender DNS.
Read guideReview Kit verified sending domains, account-generated CNAME records, DKIM/SPF alignment, DMARC staging, and custom-domain caveats before changing sender DNS.
Read guideReview Zendesk external support addresses, SPF merging, DKIM CNAME records, DMARC staging, forwarding, and connector caveats before changing sender DNS.
Read guideReview Intercom email support domains, DKIM CNAME records, custom return-path SPF alignment, DMARC TXT records, forwarding, and link-branding caveats before changing sender DNS.
Read guideReview Salesforce application email, Account Engagement, Marketing Cloud Engagement, SPF includes, DKIM keys, and DMARC alignment caveats before changing sender DNS.
Read guideReview Gmail bulk sender readiness signals for SPF, DKIM, DMARC, alignment, unsubscribe, and DNS hygiene.
Read guideReview Yahoo sender readiness signals for authentication, alignment, unsubscribe, and complaint-rate hygiene.
Read guideReview Microsoft Outlook.com high-volume sender authentication requirements and public DNS signals.
Read guideUnderstand missing DMARC records, safe starter policy shape, and what to review before publishing p=none.
Read guideLearn what RUA aggregate reports show, how reporting destinations work, and what to review before DMARC enforcement.
Read guideUnderstand DMARC policy stages and what to review before moving a domain toward enforcement.
Read guideBuild a cautious DMARC TXT candidate for p=none, reporting, alignment, and subdomain policy before publishing DNS changes.
Read guideTurn report, sender-inventory, and alignment evidence into a cautious path from p=none toward quarantine or reject.
Read guideFind duplicate SPF TXT records and plan a cautious consolidation with your DNS owner.
Read guideBuild a cautious SPF TXT candidate from known senders, custom includes, and approved IPs before publishing DNS changes.
Read guideUnderstand SPF lookup limits, risky include sprawl, and cleanup paths before changing DNS.
Read guideUse message headers and provider settings to find the selector behind a DKIM record check.
Read guideRun a common-selector scan, then use provider settings or signed headers to confirm the active DKIM selector.
Read guideReview MTA-STS DNS records, HTTPS policy hosting, TLS reporting, testing mode, and enforce-mode caveats.
Read guideBuild a cautious MTA-STS DNS record, HTTPS policy file, and TLS-RPT TXT candidate before enforcing transport security.
Read guideReview BIMI DNS, DMARC enforcement, SVG Tiny PS logo assets, VMC/CMC requirements, and provider display caveats.
Read guideBuild a cautious BIMI TXT candidate from a logo URL and optional certificate URL before publishing DNS.
Read guideMap storefront, lifecycle, support, review, billing, and fulfillment senders before tightening DMARC.
Read guideReview newsletter SPF, DKIM, DMARC, alignment, and platform sender inventory.
Read guideReview product, billing, support, and lifecycle email streams before policy changes.
Read guideScope client sender-authentication audits, evidence boundaries, and handoff recommendations.
Read guidePlan client DMARC monitoring, alert severity, baselines, and escalation paths for managed domains.
Read guideReview donor, volunteer, newsletter, grant, and operations mail before authentication changes.
Read guideCoordinate authentication review for central IT, departments, students, alumni, and vendor senders.
Read guideStart with a domain scan, then confirm selectors and signed message headers with each sender.
Read guideReview public DNS signals before sending larger campaigns to Gmail, Yahoo, and Outlook.com users.
Read guide