Web Technician Online

Email authentication checklist: test each sending source

Inventory mailbox mail, website forms, newsletters, invoices and automated alerts.

What does this mean?

Email authentication is a collection of checks, not a single DNS badge. SPF authorizes connecting senders for an envelope domain, DKIM verifies signatures and DMARC considers alignment with the visible From domain. The outcome must be observed on mail sent through each actual service.

What should I check first?

Inventory mailbox mail, website forms, newsletters, invoices and automated alerts. Record which domain each uses in From and which provider sends it. Save the DNS zone, identify the authoritative provider and obtain current setup instructions for every legitimate service.

How can I diagnose the cause?

Retrieve the single SPF policy, the exact DKIM selectors and the DMARC policy. Check provider dashboards for signing status, but also send controlled test messages to independent accounts. In their headers, compare the receiver’s authentication results and domains with your inventory.

How do I fix it safely?

Repair one source at a time using provider-supported signing and return-path settings. Preserve unrelated TXT records and avoid duplicate SPF policies. Plan stronger DMARC handling only after legitimate sources are aligned and reports are understood. A browser DNS query does not simulate all receiver evaluation rules.

Verify the fix and know when to contact your provider

Retest after a nameserver move, provider change or key rotation and keep redacted evidence of the working configuration. Ask providers about unsupported alignment, forwarding or complex SPF dependencies. Authentication improves trust but does not replace consent, secure accounts, good sending practices or delivery monitoring.

Work through these checks in order

  1. Create one row per sending service with its visible From domain, SPF envelope domain and DKIM signing domain and selector. Include forms and invoices, not just everyday mailbox mail.
  2. Check its published records and send a real controlled test. Record the receiving system’s result and alignment; a provider setup badge is supporting evidence rather than the final delivery observation.
  3. Repeat the matrix after DNS migration or key rotation. Keep redacted working examples so you can compare a later failure without guessing which domain or selector changed.

Which tool can help?

SPF DNS record checker · DKIM public record checker · DMARC DNS record checker · MX record checker

DNS tools show one resolver’s public answers. Record explainers do not authenticate a message, and calculators do not monitor a server. Use the evidence alongside your provider’s logs.

Reference

Official technical documentation