Email Authentication & Deliverability

Get every legitimate email into the inbox. Keep every fake one out.

I audit, configure, and monitor SPF, DKIM, and DMARC for businesses, agencies, and SaaS senders — so your emails stop landing in spam and no one can spoof your domain.

No campaign work, no copywriting — technical authentication only.
DOMAIN STATUSBEFORE → AFTER
yourcompany.com
SPF recordtoo many lookups
DKIM alignmentnot signed
DMARC policyp=none
SPF recordpass
DKIM alignmentaligned
DMARC policyp=reject

The problem

Most domains are sending mail unprotected — and don't know it

01

Good emails land in spam

Gmail, Yahoo, and Microsoft now require proper authentication. One misconfigured record and your invoices, receipts, and outreach quietly go to junk.

02

Anyone can impersonate your domain

Without an enforced DMARC policy, attackers can send phishing emails that appear to come from you — putting your customers and your reputation at risk.

03

Nobody's watching the reports

Even when DMARC is turned on, the reports it generates are dense XML files. Most businesses never see who's failing, or who's spoofing them.

04

Enforcement feels risky to flip on

Moving from "monitor only" to actually blocking bad mail can break legitimate tools if it's done blind. It needs to be staged and verified.

What I do

Five ways to lock down how your domain sends email

Each engagement starts with an audit, and moves at the pace that's safe for your sending volume. Pricing is scoped to your domain count and complexity — get a quote after a short audit.

SPF, DKIM & DMARC audit and setup

Full review of current DNS records and sending sources, followed by correct implementation of all three — consolidated SPF, per-platform DKIM keys, and an initial DMARC record.

starting point

Alignment and authentication fixes

Resolving SPF-DKIM alignment mismatches, SPF lookup-limit errors, and misconfigured third-party senders like your CRM, helpdesk, or marketing platform.

per issue

DMARC report monitoring

Ongoing parsing of aggregate and forensic reports, with a monthly plain-language summary of who's sending on your behalf and whether they're passing.

monthly retainer

Unauthorized sender & failure investigation

When a report flags something unexpected, I trace it back to the source, confirm whether it's a forgotten tool or a genuine spoofing attempt, and recommend the fix.

as needed

Policy rollout: p=none → quarantine → reject

A staged, monitored path to full enforcement — validating every legitimate sender passes before tightening the policy, with a rollback plan at each stage.

4–12 week project
How it works

Four stages, from first scan to full enforcement

Stage 1

Audit

I scan your domain's current SPF, DKIM, and DMARC setup and map every service sending on your behalf.

Stage 2

Fix

I correct and publish the records, sign every legitimate sender, and confirm alignment across the board.

Stage 3

Monitor

DMARC reports start flowing. I watch them for a defined period to confirm nothing legitimate is failing.

Stage 4

Enforce

Once the data confirms it's safe, we move the policy to quarantine, then reject — blocking spoofed mail for good.


Why it matters

What proper authentication actually gets you

Better inbox placement

Authenticated mail is trusted mail — fewer of your emails get filtered to spam or promotions.

Protection from spoofing

An enforced DMARC policy stops attackers from sending phishing emails that look like they came from you.

A domain your customers can trust

Clean authentication protects the reputation you've built, especially for domains handling invoices or account access.

Compliance with sender requirements

Meets Gmail and Yahoo's bulk sender requirements, so your outreach and transactional mail aren't at risk of being blocked outright.

Visibility into who sends as you

Monthly reporting shows every service and server sending on your domain's behalf — no more blind spots.

A safe, staged rollout

No flipping a switch and hoping. Every step is validated against real data before the next one begins.

Scope of work

Technical authentication only — no campaigns, no copy

What I handle

  • SPF, DKIM, DMARC configuration
  • DNS record audits and fixes
  • Authentication & alignment troubleshooting
  • DMARC report monitoring
  • Spoofing & unauthorized sender investigation
  • Policy enforcement rollout

What I don't handle

  • Email campaign design or copywriting
  • List building or subscriber growth
  • Marketing automation strategy
  • Sending platform selection or setup unrelated to authentication

Results

What enforcement looks like in practice

These are illustrative placeholders showing the format your real case studies will take — swap in actual client results (with permission) once you have them.

sample case study
"We didn't know three different tools were sending as us until the audit turned it up."
p=rejectFINAL POLICY
9 wksROLLOUT TIME
Placeholder — Agency FounderMarketing agency, 4 sending domains
sample case study
"Inbox placement on our transactional emails improved almost immediately after DKIM was fixed."
+22%INBOX PLACEMENT
6 wksTO ENFORCEMENT
Placeholder — Head of GrowthB2B SaaS company
sample case study
"A phishing attempt using our domain was flagged and blocked within the first monitoring cycle."
3SPOOF ATTEMPTS CAUGHT
100%LEGIT MAIL PASSING
Placeholder — Operations LeadE-commerce brand
Questions

Before you reach out

What are SPF, DKIM, and DMARC, in plain terms?+

SPF lists which servers are allowed to send email for your domain. DKIM signs your emails so receivers know they weren't altered in transit. DMARC tells receiving mail servers what to do when a message fails those checks, and sends you reports on the results.

Will moving to enforcement break my email?+

Not if it's staged correctly. I monitor your DMARC reports first to confirm every legitimate sender is passing, then move the policy up gradually — with a rollback plan at each step if anything looks off.

How long does the whole process take?+

The audit and initial setup usually take 3–7 business days. Full enforcement rollout, from p=none to p=reject, typically runs 4–12 weeks depending on how many senders you have and how quickly issues surface.

Which email platforms and DNS hosts do you support?+

Any platform that sends email on your behalf — Google Workspace, Microsoft 365, and marketing, CRM, or transactional tools — and any DNS host, including GoDaddy, Cloudflare, Namecheap, and Route 53.

How does pricing work?+

Every engagement starts with a short audit so I can scope the work accurately. From there I'll send a fixed quote for setup, and — if you'd like ongoing monitoring or a staged enforcement rollout — a monthly retainer rate.

Do you manage email campaigns too?+

No — I focus purely on the technical authentication side. I don't write copy, build lists, or manage campaigns, so I pair well with your existing marketing team or agency.

Find out exactly where your domain stands

Request an audit

Tell me about your domain

Share a few details and I'll follow up with what I find and a scoped quote. No commitment required.

This form isn't connected yet — link it to your inbox, a form service, or your booking calendar before publishing.