About Expertise Work Projects
Hosted Monitoring & Dashboards Self-Hosted Observability Stack Bulk Document Data Extraction Email Deliverability Diagnosis & Repair
Free Tools
Website Health Check Email Domain Health Check DNS Health Check SSL Certificate Checker Redirect Chain Checker Robots.txt Checker XML Sitemap Validator Docker Compose Checker WordPress Security Check AWS IAM / S3 Policy Checker Domain Registration Lookup Uptime Monitoring Trial Downtime Cost Calculator AWS Cost Estimator Cloud Architecture Self-Assessment DevOps Engagement Builder Self-Managed VPS vs Managed AWS
Blog Certifications Hire Me

Your email is going to spam. First, find out why.

Usually it is a broken record you cannot see, and that is fixable in days. Sometimes it is reputation, and that takes weeks. Occasionally it is neither, and no amount of DNS will help. The audit tells you which — every time, before you spend a penny on a fix.

“Our invoices are going to spam”

A customer says they never got the invoice. It was in their junk folder all along. Then a quote goes missing, then a password reset. Nothing changed on your side, so nothing looks broken — and that is exactly what makes this so frustrating to chase.

Most people react by rewriting the email. They remove the word “free”, strip out images, shorten the subject line. It almost never helps, because the message content is rarely what is wrong. The problem is nearly always in DNS, in reputation, or in a rule that changed while nobody was watching.

There are five causes, and they are not equal

They need completely different work, and they carry completely different timelines. Selling a fix before knowing which one you have is guesswork with an invoice attached — so the first thing I do is find out.

Configuration Category AFixed completely
Domain or IP reputation Category BCause stopped, recovery takes weeks
Blocklists Category CDelisting is procedural once the cause is gone
Provider bulk-sender rules Category DRule violations with defined remedies
Behaviour, or the recipient’s own IT Category ENot fixable by me, and I will say so
Category A
A broken SPF record, or two of them. An SPF record over the ten-lookup limit. A DKIM selector that was never published. DMARC that does not align with what you actually send. No reverse DNS on your mail server. Forwarding that quietly breaks SPF on the way. This is the biggest single share of cases, and all of it is deterministic — the records are either right or they are not.
Category B
Complaints from recipients. A mailbox that was compromised and spent a weekend sending spam under your name. A volume spike that looked like a list purchase. The cause can be found and stopped quickly. The reputation itself then recovers on the receiving provider’s schedule, which is nobody’s to promise.
Category C
Spamhaus SBL, CSS or DBL. SURBL, URIBL, Barracuda, Proofpoint. Delisting is a form and a wait once the thing that caused the listing has actually stopped — and requesting delisting before then just burns the request.
Category D
Google, Yahoo and Microsoft all publish bulk-sender requirements now, and all three enforce them. These are rules with written remedies, which makes them among the more satisfying causes to find.
Category E
A bought list. A genuinely unwanted campaign. Or one recipient’s IT department blocking you at their own gateway, where no amount of DNS will help. If the audit lands here, I tell you in writing and the engagement ends. You will have paid for a diagnosis and got one.

“It worked fine last month”

It probably did. Then a rule changed. The big providers spent the last two years turning guidance into enforcement, and a domain that was merely untidy became a domain that gets refused.

What the providers now require

  • Google and Yahoo, since February 2024. Send over 5,000 messages a day to personal accounts and you need SPF and DKIM and DMARC — not one of the three. Below that volume, you still need at least SPF or DKIM.
  • Microsoft, since 5 May 2025. The same three records for consumer Outlook, Hotmail and Live addresses above 5,000 a day. Microsoft rejects rather than filters — non-compliant mail comes back as 550 5.7.15 Access denied and never reaches a junk folder at all.
  • One-click unsubscribe. Marketing and subscribed mail needs a working List-Unsubscribe header on RFC 8058, plus a visible link in the message.
  • Spam complaints under 0.30%. Google's own guidance is to stay below 0.10% and never reach 0.30% — so 0.3% is the ceiling you are already in trouble at, not the target.
  • TLS in transit, and valid forward and reverse DNS on the sending host. A missing PTR record is a surprisingly common single point of failure.

Search your bounce log for 550 5.7.15 before you do anything else. If it is there, you already know the category and it is one of the fixable ones.

The providers are not equally helpful, and you should know that up front

  • Google is the most transparent by a distance. Postmaster Tools reports domain reputation, spam rate, authentication pass rates and delivery errors. It is the best diagnostic that exists, it needs one DNS record to enable, and I set it up on every engagement whether or not Gmail is the problem.
  • Yahoo sits in the middle. Sender Hub plus a complaint feedback loop — enough to work with.
  • Microsoft is the hard one. SNDS and JMRP give partial visibility, and there is a mitigation form. Responses are often opaque, and a request can be refused with no usable reason given. I price for that and I do not pretend otherwise.

One more thing worth knowing before you worry: not every blocklist matters. A UCEPROTECT level 2 or 3 listing is largely ignored by the major receivers and is effectively pay-to-delist. Seeing your name on one is usually not your problem. A Spamhaus SBL, CSS or DBL listing is a different matter entirely. Telling those two apart is free, and it saves people from paying to fix something that was never affecting them.

It always has an answer

This is the part that makes the whole thing honest. The audit cannot fail to deliver, because naming the cause is the deliverable — including when the answer is one I cannot sell you a fix for.

What you get, in writing

  • Which category you are in, of the five above, with the reasoning.
  • The evidence. The actual records, headers, bounce codes and blocklist entries that led to the conclusion — not an assertion you have to take on trust.
  • What remediation would involve, in order, written against your configuration rather than as generic advice.
  • A realistic timeline, separating what is fixable this week from what recovers on a schedule nobody controls.
  • What is already correct. A report that only lists problems is a sales document, not a diagnosis.

Start free. The Email Domain Health Check on this site already tests SPF, DKIM and DMARC on your domain and shows you everything it finds. No signup, no email address. If it comes back clean, you are not category A — and you just narrowed it down for nothing.

Run the free check

Four ways in

Everyone starts with the audit. Where you go afterwards depends on what it finds — and if it finds nothing I can fix, you stop there and keep the report.

Deliverability Audit

$99 one-off

Everyone starts here. Always deliverable.

  • Full authentication and DNS review
  • Blocklist and reputation check
  • Header and bounce analysis
  • Written report with the evidence
  • The category, and what it means

Authentication Fix

$299 one-off

Category A, which is most cases. Deterministic work.

  • SPF rebuilt inside the ten-lookup limit
  • DKIM published and verified
  • DMARC to p=none, aligned
  • Reverse DNS and forwarding corrected
  • Postmaster Tools set up
  • Send and receive testing

Audit fee credited — you pay the difference, not both.

Most complete

Full Remediation

$599 one-off

Categories A to D together, when it is more than records.

  • Everything in the Authentication Fix
  • Blocklist delisting requests
  • Provider mitigation submissions
  • Staged DMARC rollout to p=quarantine
  • Report reading across 30 days
  • Sender inventory verified before enforcing

Audit fee credited — you pay the difference, not both.

DMARC Monitoring

$49 per month

After the fix, so it stays fixed.

  • Aggregate reports received and read
  • New or changed senders flagged
  • Monthly summary in plain English
  • Alignment failures caught early
  • Monthly in advance, cancel anytime

These are launch prices for a new practice, not a permanent position — they will go up once there are testimonials behind them. If your situation does not fit any of the four, say so in the form and I will tell you honestly whether it is worth doing at all.

What you have to supply

Listed openly, because it is the fastest part to get wrong and the slowest part to chase. If you cannot grant something below, say so — there is a workaround for nearly all of it.

Access — least privilege, always

  • DNS zone editing only. Not your registrar login. If your provider cannot separate the two, I send you a written list of exact record changes and you apply them yourself.
  • Temporary mail tenant admin on Google Workspace, Microsoft 365 or Zoho — and only if DKIM keys actually need generating. Revoked the moment the work is done.
  • One mailbox on the domain for send and receive testing.

Information — the part everybody skips

  • A written inventory of every legitimate sending source. Contact form, CRM, invoicing, marketing platform, helpdesk, e-commerce, anything a previous developer set up and nobody documented. Enforcing DMARC without this blocks your own real mail, which is the most common way a deliverability fix makes things worse.
  • Registrar, renewal date, and who holds the account.
  • Any previous deliverability work, and your existing SPF records — including the ones somebody added and forgot.

Protecting the work

  • The current zone is exported before anything changes. That is the rollback, and it exists before the first edit.
  • TTLs lowered 24 to 48 hours in advance, so a mistake is minutes to undo rather than a day.
  • Written authorisation naming the domain, the records to be changed and the rollback plan.
  • Written sign-off that the sender inventory is complete, before DMARC is ever moved off p=none.

What I will not promise you

Inbox placement is decided by the receiving provider and cannot be guaranteed by anyone. This engagement covers diagnosis, correction of authentication and configuration faults, blocklist delisting requests where applicable, and submission of provider mitigation requests.

A finding of category E ends the engagement. If the cause turns out to be a purchased list, genuinely unwanted mail, or one recipient's own IT blocking you, you get that in writing with the reasoning. The audit fee is earned. Nothing further is billed.

Reputation recovery runs on a timeline nobody controls. Typically weeks once the cause has stopped. You are hearing that before you pay, not after.

Saying this out loud costs me some sales. It is still the right way round: no mailbox provider gives anyone a delivery guarantee, so a competitor offering one is either misinformed or counting on you not checking. I would rather tell you what cannot be fixed than take money for pretending otherwise.

How payment works

Plainly, so nothing about it is a surprise later. There is no account to create, no portal to log into and no card stored anywhere.

  1. You apply through the form

    No payment at this point, and no commitment. Tell me the domain, where you send from and what is happening.

  2. I review it and confirm the scope

    If it is not worth doing, I say so here and it costs you nothing. If it is, you get the scope in writing before any invoice exists.

  3. An invoice arrives, payable within 48 hours

    It carries an invoice number and a due date. Unpaid past 48 hours, the application lapses and the slot is released to somebody else.

  4. Work begins once payment is received

    Not before. For one-off work there is nothing to suspend after delivery, so payment comes first — that is the standard arrangement and it runs both ways.

  5. Monitoring, if you take it, is monthly in advance

    Non-payment simply suspends report processing. Nothing is billed silently in the background and you can stop whenever you like.

Run the free check, then send me the result.

It takes about a minute and costs nothing. If it comes back clean, your problem is not authentication and I will tell you where to look instead. If it comes back with findings, paste them below and you have already done the first half of the audit yourself.

Prefer to talk? Book a free call ↗  ·  Or hire me on Upwork ↗  ·  Typical reply within one business day.

Questions

How long does this take?
The audit is a few days from the moment access and the sender list arrive. An authentication fix is days too, plus DNS propagation, which is why TTLs get lowered in advance. Reputation recovery is the one that is not on my schedule or anyone else’s — that is typically weeks, and I say so before you pay rather than after.
Do you need my domain registrar login?
No, and I will turn it down if offered. I need permission to edit DNS records, which is a narrower thing — most registrars and DNS hosts can grant it separately. If yours cannot, I send you a written list of exact record changes and you apply them yourself. Full registrar access carries the power to transfer or lose your domain, and that is not a liability I accept when the work does not require it.
What happens if you find something you cannot fix?
You get that in writing, with the evidence, and the engagement ends there. The audit fee is earned because the audit was delivered — knowing the cause is not a configuration fault is worth more than paying someone to keep editing DNS records that were already correct. It is the least common outcome, but it is a real one and you should hear about it before you buy, not after.
Can you guarantee my email reaches the inbox?
No, and nobody can. Inbox placement is decided by the receiving provider, using signals they do not publish in full and change without notice. What I guarantee is the work: the diagnosis, the correction of authentication and configuration faults, delisting requests where they apply, and provider mitigation submissions. Anyone selling you a delivery guarantee is either misinformed or hoping you will not check.
Why does my mail reach Gmail but bounce from Outlook?
Because Microsoft started rejecting rather than filtering. Since 5 May 2025, mail to consumer Outlook, Hotmail and Live addresses from domains sending over 5,000 messages a day must have SPF, DKIM and DMARC, and mail that does not is refused outright with 550 5.7.15 Access denied instead of being filed in junk. Search your bounce log for that string. If it is there, you have found your answer and it is a fixable one.
I already have an SPF record. Is that not enough?
Usually not, for two reasons. Every sender needs at least SPF or DKIM, but a bulk sender needs SPF and DKIM and DMARC together — one out of three fails the check. And SPF has a hard limit of ten DNS lookups, which a domain using a mail host, a CRM and a marketing platform blows through easily. Past ten, the record does not degrade politely. It fails, and it takes your authentication with it.
What is the sender inventory and why do you keep asking for it?
It is the written list of everything that legitimately sends mail as you — the website contact form, the CRM, the invoicing system, the helpdesk, the marketing platform, whatever a previous developer wired up years ago. It matters because enforcing DMARC without it blocks your own real mail. This is the single most common way a well-meaning deliverability fix makes things worse, and it is why I ask for the list in writing and get sign-off that it is complete.
I saw my IP on a blocklist. Should I panic?
Check which one first. A UCEPROTECT level 2 or 3 listing is largely ignored by the major receivers and is effectively pay-to-delist, so seeing your name there is usually not your problem. A Spamhaus SBL, CSS or DBL listing is an entirely different matter and does need dealing with. Confusing the two is how people end up paying to solve something that was never affecting them.
Can I just run the free checker instead?
Yes, and you should, before you contact me about anything. The Email Domain Health Check on this site tests SPF, DKIM and DMARC on your domain and shows you what it finds, free, with no signup. If it comes back clean, your problem is not category A and you have narrowed it down without spending anything. If it comes back with findings, send me the result — that is the fastest possible start.