Email deliverability is the likelihood that a message you send reaches the recipient's inbox, rather than their spam folder or nowhere at all. It is not a single setting. It is the combined result of how your domain is configured, how your servers behave, who you send to and how they respond. This checklist is organised so that a business owner or IT administrator can work through it once, fix what is missing, and then repeat the monitoring section regularly.
Section 1: Domain authentication
These are the foundations. Mailbox providers increasingly treat them as mandatory.
- ☐ One SPF record on your sending domain, listing every service that sends as you, ending in
~allor-all. - ☐ SPF within 10 DNS lookups, including nested includes.
- ☐ DKIM enabled with your own domain (
d=yourdomain) on your mailbox provider and on every marketing, CRM and transactional platform. - ☐ DKIM keys of 2048 bits where the provider allows it.
- ☐ DMARC published at
_dmarcwith aruareporting address. - ☐ A plan to move DMARC to enforcement (
quarantine, thenreject) once reports show all legitimate mail passing. - ☐ Non-sending domains locked down with
v=spf1 -alland a DMARCp=rejectrecord.
Our SPF, DKIM and DMARC checker verifies all three in one pass.
Section 2: Sending infrastructure
If you use only a hosted provider such as Google Workspace or Microsoft 365, most of this is handled for you. If any system sends mail directly from your own servers, check each item.
- ☐ Reverse DNS (PTR) on every sending IP, resolving to a host name that resolves back to the same IP.
- ☐ HELO/EHLO name matches that host name.
- ☐ TLS enabled for outbound connections (STARTTLS), with a valid certificate on any server that receives mail.
- ☐ Not on major blocklists. Check the IPs and your domain.
- ☐ Authenticated submission only. Applications and staff submit mail on port 587 (or 465) with a username and password; nothing relays mail unauthenticated.
- ☐ Web forms protected with rate limiting or a CAPTCHA, so bots cannot use your contact form to send spam from your domain.
- ☐ Application mail relayed through an email service rather than sent directly from a web server, unless you are prepared to manage IP reputation yourself.
Section 3: Separating mail streams
- ☐ Marketing mail on its own subdomain, such as
news.example.com, so complaints about newsletters do not drag down invoices and staff mail. - ☐ Transactional mail (password resets, receipts) on a separate stream or subdomain, and never mixed with promotional content.
- ☐ Consistent From addresses per stream, so recipients and filters learn what to expect.
- ☐ Gradual warm-up for any new domain, subdomain or dedicated IP, increasing volume over days and weeks rather than sending a full campaign on day one.
Section 4: List quality and consent
- ☐ Every recipient opted in. No purchased, rented or scraped lists.
- ☐ Confirmed (double) opt-in for newsletter sign-ups where practical.
- ☐ Hard bounces removed immediately and repeated soft bounces removed after a few attempts.
- ☐ Unengaged recipients (no opens or clicks for many months) moved to a re-engagement campaign or removed.
- ☐ Visible unsubscribe link in every marketing message, honoured within two days.
- ☐ One-click unsubscribe headers (
List-UnsubscribeandList-Unsubscribe-Post) on bulk marketing mail. - ☐ Compliance with local law on consent and identification, such as anti-spam and data protection laws in the countries you send to.
Section 5: Message content and format
- ☐ A plain-text part alongside the HTML version.
- ☐ A sensible text-to-image balance; never a single image as the whole message.
- ☐ Links to your own domains, not public link shorteners, and link text that matches the destination.
- ☐ HTTPS on every linked page, with valid certificates. The SSL checker catches expired or mismatched certificates on landing pages.
- ☐ No risky attachments; share large or sensitive files via links.
- ☐ Clear sender identity: a recognisable From name, your physical business address where required, and a subject line that matches the content.
Section 6: Ongoing monitoring
Deliverability changes over time, so the final section is a routine rather than a one-off.
| How often | Check |
|---|---|
| Weekly | DMARC aggregate reports for new or failing sources |
| Weekly (bulk senders) | Spam complaint rate and reputation in Google Postmaster Tools; Microsoft SNDS for your own IPs |
| Per campaign | Bounce rate, complaint rate and unsubscribes compared with previous sends |
| Monthly | Blocklist status of sending IPs and domains |
| Whenever a new tool is adopted | SPF include, DKIM with your domain, DMARC alignment confirmed |
| Quarterly | Review SPF for services no longer in use; review DNS records with a DNS lookup |
When results suddenly drop
If open rates collapse or customers report missing mail, look for what changed: a new sending tool, a DNS edit, a large send to an old list, an expired domain on a linked service, or a compromised account sending spam. Real message headers from an affected recipient show which authentication checks failed, and they are the fastest way to the cause.
Key takeaways
- Authenticate every sending source with SPF, DKIM and aligned DMARC.
- Give your own servers proper reverse DNS, TLS and authenticated submission, or relay through a reputable service.
- Separate marketing from transactional mail, and send only to people who asked for it.
- Monitor DMARC reports, complaint rates and blocklists on a regular schedule.