Skip to content
DNS audit

Your emails go to spam.
It's probably DNS.

Misconfigured SPF, DKIM, or DMARC records mean email providers don't trust your domain. We audit your setup and fix it.

Let's see what's actually configured.

Checks public SPF, DKIM, DMARC, and MX records. No email is sent.

Email authentication isn't optional anymore.

Every email you send gets checked by the receiving server. It looks at three things: SPF (is this server allowed to send?), DKIM (was this email tampered with?), and DMARC (what happens if either fails?).

If any are missing or misconfigured, your emails land in spam or get rejected. Doesn't matter how good your subject line is.

This isn't just a cold outreach problem. Misconfigured DNS affects transactional emails, customer communications, investor updates, even password resets.

Your Tools Changed. Your DNS Didn't.

01

Your cold outreach response rates dropped.

Before you rewrite copy or switch tools, check your DNS.

02

You set up company email and never touched DNS.

Your provider handles sending, but authentication needs to be configured at the domain level. Many companies skip this.

03

You use multiple tools that send email.

CRM, marketing automation, cold outreach, transactional email. Each needs authorization in your SPF record. If they're not all listed, emails fail silently.

04

You switched providers or added a tool.

Old DNS configuration is now incomplete. Authentication that used to work has quietly stopped passing.

Full audit and configuration. One-time fix.

01

Audit

We pull your current DNS records and check them against every service sending on your behalf. Gaps, conflicts, misconfigurations, all identified.

02

Fix

We configure or correct SPF, DKIM, and DMARC across all sending domains.

03

DMARC reporting

We set up DMARC in reporting mode so you get regular reports showing which emails pass and fail.

04

Documentation

Clear record of what was changed, why, and what each record does. If you add a new tool later, you'll know what to update.

Total turnaround: 2–3 business days.

Questions we hear a lot

How do I know if my DNS is the problem?

Send a test email to a Gmail account. Open the original message headers (three dots → Show original). Look for SPF, DKIM, and DMARC results. If any show 'fail' or 'none', your authentication needs work. Or talk to us, we can check in 5 minutes.

Will this fix my cold outreach deliverability?

DNS authentication is one piece. If your records are broken, fixing them helps. But deliverability also depends on domain reputation, warm-up, sending volume, and content. If you need the full infrastructure, we do that too.

I have a lot of domains. Does the scope change?

Depends on how many and how complex the setup is. Talk to us and we'll scope it.

Can I do this myself?

SPF, DKIM, and DMARC are public standards. In practice, it's easy to get wrong, especially with multiple sending services. A misconfigured SPF record (too many lookups, missing includes) can make things worse.

Do you offer ongoing monitoring?

The DMARC reporting we set up gives you ongoing visibility. If you want active monitoring and response, that's part of our managed outreach service.