Anyone can send an email pretending to be you. Nothing in the original design of email stops it. Three settings were added over the years to fix that, and Gmail, Yahoo and Microsoft now require them.

If they are missing or wrong, your mail gets junked or rejected. Most setups have at least one of the three wrong, and nothing anywhere tells you.

What usually goes wrong

Problem 1

One record is missing

Very common on new domains, and on any domain where someone added a new tool without updating the settings.

Problem 2

The record is too long

There’s a hidden limit. Add a CRM and a helpdesk and you quietly cross it. The setting still looks perfect.

Problem 3

Everything passes, mail still fails

The checks pass for the wrong domain. This is the most common fault I find, and there are only two fixes.

What I do

Set all three properly on every domain you send from, then prove they work.

1. SPF — who can send as you

This lists the services allowed to send email using your domain. Most people copy one from a blog post and never touch it again.

There’s a limit of ten lookups. Google, your sending tool, a CRM and a helpdesk together will push you over it — and past the limit, the whole thing is treated as broken. I build yours from the services that actually send for you and count it.

2. DKIM — a signature on every email

This adds a hidden signature so a receiver can prove the message really came from you and wasn’t altered on the way.

It’s the more reliable of the three, because it still works when someone forwards your email. Each provider needs its own key, so a domain sending through two tools needs two.

3. DMARC — what to do if the checks fail

This tells Gmail what to do when the first two fail: ignore it, send to spam, or reject it outright. It also emails you a daily report on what receivers saw.

Most domains sit on “ignore it” for years while the owner believes they’re protected. I start there deliberately, read the reports for a few weeks so nothing legitimate breaks, then turn it up.

what a protected domain looks like
SPFSays which services can send as you, under the limitdone
DKIMSigns every email so it can’t be fakeddone
DMARCTells Gmail what to do if the checks faildone
ReportsA real inbox receiving the daily reportsdone
MatchConfirmed against an email I actually sentdone
The last one is the step most setups skip, and it’s the one that catches the most common fault.

4. Check every domain, not just one

If you run a fleet, all of them get checked in one pass. I’ve found things like an entire batch of inboxes with no signature at all, quietly killing results for months.

How long it takes

how long it takes
Checking what you havesame day
Fixing the settings1–2 days
Reading reports2–4 weeks
Turned up to full protectionweek 4
The fixing is fast. The waiting is only so nothing legitimate breaks when protection is turned up.

What I need from you

Two things, and the second is the one people forget.

To start

Your domains

Every domain you send from, not just the main one.

Important

Everything else that sends

Your CRM, helpdesk, invoicing tool, newsletter. If I don’t know about them, turning on protection will break them.

To fix it

Domain access

Or approval to make the changes with you watching on a call.

Optional

A recent bad email

If mail is currently going to spam, one example tells me a lot.

Is this right for you?

Yes if

This is a good fit

  • You’re starting cold email and want it set up right
  • Gmail or Outlook started rejecting your mail
  • You have lots of domains and no idea which are protected
  • Someone told you to “set up DMARC” and you don’t know where to start
No if

Look elsewhere

  • You only send from one inbox and never send in bulk
  • You want it done today and you have twenty tools sending as you

What it costs

Priced on how many domains and how many other tools send as you. A single domain is a small job.

What I promise: you get a written price before I start, it doesn’t change unless the job does, and if you don’t actually need to hire anyone, I’ll tell you on the first call.

Check it yourself first

These are free and run in your browser. If they answer your question, you don’t need me.

Common questions

Is DMARC actually required?

For anyone sending in bulk to Gmail, Yahoo or Microsoft, effectively yes. The bare minimum passes their check, but it protects nothing — which is why most domains that “have DMARC” are not actually protected.

Why does my email fail when SPF and DKIM both pass?

Because they’re passing for your sending tool’s domain, not yours. The receiver checks that they match the name your recipient sees. There are two ways to fix it and I’ll set up whichever fits your tool.

Can you fix a record that’s over the limit?

Yes. It usually means removing services that no longer send, combining a few, or moving one onto its own sub-domain so it stops eating the budget.

Will turning this on break my other emails?

Not if it’s done in stages, which is exactly why I read the reports before turning protection up. That waiting period is the safety step.

Last reviewed

Related

Other things I do

Next step

Send me your domain list

I’ll tell you which are actually protected, which only look protected, and what it takes to close the gap.

What happens on the call

We look at your setup together, I tell you what’s wrong and what it takes to fix. If you can do it yourself, I’ll say so — that happens fairly often, and it’s fine.

Based inRangpur, Bangladesh — all time zones
RepliesWithin one business day
Inboxes200,000+ provisioned
← All servicesSet it upFix itMove itWatch itBook a call →
Back to top