Short answer: Reliable e-mail delivery rests on four groups of checks: correct DNS records (MX, SPF, DKIM, DMARC), authenticated sending systems (mailbox provider, website, shop and marketing tools all aligned with your domain), healthy list habits (consent, bounce removal, easy unsubscribing, low complaints) and ongoing monitoring (DMARC reports, header tests, alerts). Work through them in that order, because technical failures undermine everything else.
How to use this checklist
This checklist is written for small businesses, agencies managing client domains, and developers who inherit a website and its e-mail. Each item is a yes-or-no question with a short explanation. Go through it once completely, fix the “no” answers in the order given, and then repeat the monitoring section regularly.
You do not need to be an e-mail specialist. Most items require access to your DNS panel, your mail provider’s admin console and the settings of the tools that send mail for you. Where a fix needs more detail, the related articles at the end cover it step by step.
Keep notes while you work. The list of your sending systems, their DKIM selectors and who manages each one is valuable documentation for the next DNS change, the next new tool and the next person who takes over.
Part 1: DNS records (checks 1 to 6)
- MX records point only to your current mail provider. Leftover records from an old provider split incoming mail, including replies, bounces and DMARC reports.
- Exactly one SPF record exists at the root of the domain, starting with
v=spf1. Two records cause a permanent error. - SPF stays within ten DNS lookups when all includes are expanded, and ends with
~allor-all, never+all. - DKIM is published and active for your mail provider, signing with your own domain rather than the provider’s default domain.
- A DMARC record exists at
_dmarcwith aruareport address, and the report mailbox actually receives mail. - Unused domains are locked down with
v=spf1 -all, DMARCp=rejectand, if they receive no mail, a null MX record.
These six checks can be verified from outside the organisation in a few minutes, and they are the most common source of problems. An error here affects every message, however good the content and the list.
Part 2: sending systems (checks 7 to 11)
- You have a list of every system that sends mail as your domain: mailboxes, website forms, shop, newsletter, CRM, helpdesk, invoicing, booking, devices.
- Each system signs with DKIM for your domain, confirmed in the headers of a real message, not only in the tool’s settings.
- The website does not send mail directly from the web server; forms and notifications use authenticated SMTP or a transactional service.
- From addresses use your own domain, never a visitor’s address, with Reply-To used for replies.
- Self-hosted mail servers have correct reverse DNS (a PTR record that resolves back to the same IP) and use TLS.
Part 2 is where most businesses find surprises. The mailbox provider is usually configured correctly; the invoicing tool, the booking system and the website contact form are not. DMARC reports are the best way to find systems nobody listed.
Part 3: list habits and content (checks 12 to 17)
- Marketing contacts gave clear consent, ideally confirmed by clicking a link. Never use bought or scraped lists.
- Hard bounces are removed immediately, and addresses that repeatedly soft bounce are suppressed.
- Unsubscribing takes one click, with List-Unsubscribe headers in marketing mail and a visible link in the footer, and requests are honoured within two days.
- Long-inactive contacts are re-confirmed or removed rather than mailed indefinitely.
- Transactional and marketing mail are separated, ideally by subdomain and platform, so campaigns cannot delay receipts.
- Messages are honest and recognisable: consistent sender name, subject lines that match the content, links to your own HTTPS domain, and a plain-text version.
Mailbox providers learn from recipients. Complaints, deletions without reading and mail to dead addresses all lower your reputation over time, while replies and opens raise it. Part 3 is about sending mail that people recognise and want.
Part 4: monitoring (checks 18 to 20)
- Someone reads DMARC reports at least monthly, or a service summarises them, and new failing sources are investigated.
- Header tests are repeated after every change: new tool, DNS move, provider switch or website rebuild. Send to Gmail and Outlook.com and check SPF, DKIM and DMARC.
- Complaint and bounce rates are watched, through your sending platforms and, for larger senders, Google Postmaster Tools. Keep the Gmail spam rate below 0.1%.
E-mail setups break quietly. A DNS migration drops a DKIM record, a colleague adds a new tool, a provider changes its SPF include. Regular monitoring turns those silent failures into small, quick fixes.
The checklist at a glance
| Area | Checks | Where to verify |
|---|---|---|
| DNS records | 1 to 6 | DNS lookups or an outside domain check |
| Sending systems | 7 to 11 | Headers of real test messages, DMARC reports |
| List habits and content | 12 to 17 | Newsletter and CRM settings, message templates |
| Monitoring | 18 to 20 | DMARC reports, Postmaster Tools, platform statistics |
Quick wins you can do today
If the full checklist feels like a project for next month, a few items take less than an hour and remove the most common causes of trouble:
- Look up your SPF record and merge any duplicate records into one.
- Open the admin console of your mail provider and confirm that DKIM signing is switched on for your domain, not just published.
- Publish a DMARC record with
p=noneand a report address if you have none. It changes nothing for delivery and starts collecting data immediately. - Submit your own website contact form with a Gmail address and check “Show original”. If SPF or DKIM fail, you have found your first real fix.
- Remove old MX records left over from a previous provider.
Each of these is reversible and low risk, and together they often solve the “our mail goes to spam” complaint that started the whole exercise.
Why checks fail again later. Passing the checklist once does not mean it stays passed. The typical regressions are predictable: a website rebuild that reinstalls a form plugin with default mail settings, a DNS provider change that copies most records but not the long DKIM key, a new marketing tool added by a colleague without authentication, and a mailbox provider migration that leaves the old SPF include in place. Knowing these patterns makes it easier to spot them before customers do. Add a line to your change procedures: whenever the website, DNS or mail provider changes, run Parts 1 and 2 again the same day.
What to do after the checklist
Once all twenty checks pass, the natural next step is DMARC enforcement. With every legitimate sender authenticated and aligned, move the policy from p=none to p=quarantine, watch the reports for a few weeks, then move to p=reject. That protects customers and partners from mail that impersonates your domain, and it reinforces the trust you have built.
Beyond that, consider MTA-STS if you receive sensitive information, BIMI if you send consumer mail at scale and have enforced DMARC, and a proper warm-up plan before any large new sending programme.
If you manage domains for clients, keep a copy of the checklist per client with the date of the last review and the open items. It turns e-mail health from an emergency service into a routine one.
Finally, schedule the checklist. Twice a year is a reasonable rhythm for small businesses, plus a quick run of Part 1 and Part 2 after every infrastructure change.
Automating the DNS part
Checks 1 to 6 are exactly the kind of thing that is easy to verify automatically. Site AI Audit checks MX, SPF (including the lookup limit), DKIM and DMARC for a domain and reports problems in plain words, next to the website’s SEO, speed, SSL and security headers. Start with a free check; paid plans on the pricing page repeat the checks on a schedule and alert you when a record breaks, so Part 4 partly takes care of itself.
Related reading
- SPF vs DKIM vs DMARC: What Each One Does and Why You Need All
- Why Are My Emails Going to Spam? 12 Causes and Fixes
- Gmail and Yahoo Bulk Sender Requirements: A Practical Guide
- One-Click Unsubscribe: How List-Unsubscribe Headers Work
The bottom line
E-mail deliverability is not one setting but twenty small ones. Get the DNS records right, authenticate every system that sends as you, keep your lists clean and consensual, and monitor the results. Work through the checks in order, and repeat them whenever something in your setup changes.
SSS
What is the most important e-mail deliverability check?
Authentication: a single valid SPF record, DKIM signing with your own domain and a DMARC record. Without these, other improvements have limited effect.
How often should I review e-mail deliverability?
Run the full checklist about twice a year, and repeat the DNS and sending-system checks after any change such as a new tool, a DNS move or a website rebuild.
Do small businesses need DMARC?
Yes. It is free, protects your domain from impersonation and is expected by large mailbox providers. Start with p=none and reports, then move towards enforcement.
Can good content fix poor deliverability?
Not on its own. Content matters for engagement and complaints, but failing authentication or a poor list will keep mail out of the inbox regardless of wording.
How do I find all the systems that send e-mail as my domain?
Combine an inventory with DMARC aggregate reports. The reports list every source that sent mail using your domain, including ones nobody remembered.
What spam complaint rate is acceptable?
For Gmail, Google advises staying below 0.1% and never reaching 0.3%. Lower is always better.



