Score a domain
How the score is built
| Check | Points | What earns full marks |
|---|---|---|
| DMARC enforcement | 18 | p=reject. Quarantine scores partial, none scores little. |
| DKIM signing | 15 | A real key with a public key present at a discoverable selector. |
| SPF record exists | 12 | A valid v=spf1 record published. |
| SPF enforcement | 10 | -all. Soft fail scores most of it; +all scores nothing. |
| DMARC record exists | 10 | A valid _dmarc record published. |
| SPF DNS lookups | 8 | Eight or fewer of the ten permitted lookups used. |
| MTA-STS | 6 | A policy published, so inbound TLS cannot be downgraded. |
| MX records | 5 | Mail routing published, or an explicit null MX. |
| DMARC reporting | 5 | An rua address, so you can see who sends as you. |
| DMARC alignment | 5 | Alignment declared. Strict scores full, relaxed scores most. |
| TLS reporting | 3 | A _smtp._tls record receiving TLS failure reports. |
| BIMI | 3 | Published. Only meaningful once DMARC is at enforcement. |
Why these weights
The weighting follows what receivers actually act on. DMARC enforcement carries the most because it is the only one of these that tells a receiver what to do when authentication fails — a domain at p=none is publishing a policy that asks for nothing, which is why it scores a fraction of one at reject. DKIM comes next because it survives forwarding, where SPF breaks, and because Google and Microsoft both now expect bulk senders to sign.
The lower-weighted items are real but secondary. MTA-STS, TLS reporting and BIMI improve security and presentation but no receiver rejects mail for their absence. A domain can score in the eighties with none of them and still deliver perfectly well, which is the point of showing every check rather than only the total.
What a score does and does not tell you
This grades configuration, not reputation. A domain can score 100 and still land in spam because it is sending to bad lists, from cold IPs, with content that gets complaints. Authentication is necessary and not sufficient: it earns the right to be judged on behaviour rather than discarded before that judgement happens.
Read a low score as a list of things that will actively hurt, and a high score as the floor being in place. If the score is strong and mail still lands in spam, the problem is warmup, list quality, volume ramp or content — none of which any DNS record can fix.
The order worth fixing in
Publish SPF and DKIM first, then DMARC at p=none, and only then read the reports before tightening. Moving straight to p=reject without checking aggregate reports is the classic way to silently block your own invoicing system or a newsletter tool nobody remembered was sending as the domain. The fix list is ranked by points lost, which usually matches the right order — but the p=none stage exists to be used, not skipped.
For the detail behind each check, use the dedicated tools: SPF, the lookup counter, DKIM and DMARC.
Questions
What is a good score?
Ninety or above means every record that receivers act on is in place and enforcing. Seventy to ninety is a working setup with real gaps, most often DMARC still at p=none. Below seventy, something receivers care about is missing outright.
Why did DKIM come back as not found?
DKIM keys live at a selector, and the selector name is chosen by whoever set it up. This checks the common ones used by the major providers. A custom selector will not be found even though signing works — the DKIM checker detects your provider from MX and tries the right names.
Does a perfect score guarantee inbox placement?
No. It grades configuration only. Sending behaviour, list quality, warmup and complaint rates decide placement once authentication passes, and no DNS record influences any of them.
Should every domain be at p=reject?
Every domain that sends mail, eventually — but only after aggregate reports confirm all legitimate sources pass. Parked and non-sending domains should go to p=reject immediately, since nothing legitimate can break.
More in this category
What to run next
The checks people most often reach for alongside this one.
When the tools tell you something is wrong
The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.
Deliverability rescue
Mail landing in spam, replies gone quiet, or a domain suddenly blocked. I find the actual cause rather than guessing, and fix it.
- Authentication and alignment failures
- Blocklist delistings and reputation repair
- Gateway and filter-level blocks
- A written report on what broke and why
Email & sending infrastructure
Sending domains, inboxes, authentication and warmup, built to survive volume instead of burning down in a month.
- Domain and inbox fleets at any scale
- SPF, DKIM, DMARC and tracking domains
- Google Workspace and Microsoft 365 inboxes
- Handover documentation you actually own
Domain, DNS & migration
Changing registrar, mail provider or host without a day of downtime or a week of mail silently failing.
- Registrar and nameserver moves
- Workspace and Microsoft 365 migrations
- MX, SSL and subdomain cutover
- Staged rollout with rollback at every step
Monitoring & retainer
Infrastructure drifts. Records get edited, certificates expire, domains get listed. Ongoing eyes on the fleet.
- Scheduled checks across every domain
- Alerts before your clients notice
- Monthly reporting
- Priority response when something breaks
Start with a call
Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.
Thirty minutes, no pitch
We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.