Why your SPF record probably breaks above ten lookups
A short explanation of the DNS lookup limit, why include: chains blow through it, and what flattening actually costs you in maintenance.
Available on request — ask us for a copy
Home / Resources
Working documents from ten years of audits. We write these for clients first; if one is useful to you, ask and we will send the PDF. No form wall, no drip sequence.
A short explanation of the DNS lookup limit, why include: chains blow through it, and what flattening actually costs you in maintenance.
Available on request — ask us for a copy
Aggregate XML is not friendly, but it is not impossible either. Here is what the four fields that matter actually tell you.
Available on request — ask us for a copy
The pre-flight list we work through before any Microsoft 365 cutover, including the three items clients always forget.
Available on request — ask us for a copy
Sender data for Outlook.com and Hotmail traffic, and how to interpret the complaint-rate colour codes without panicking.
Available on request — ask us for a copy
The honest maths on when a dedicated sending IP is worth the warm-up effort — and the far more common case where it is not.
Available on request — ask us for a copy
How to write a retention schedule that legal counsel will accept and that your mail platform can actually enforce.
Available on request — ask us for a copy
A daily routine an office manager can run without technical training, and the two settings that make it possible.
Available on request — ask us for a copy
Cloud platforms queue on your behalf, so the case is weaker than it was — but not gone. Three scenarios where it still earns its keep.
Available on request — ask us for a copy
A four-week ramp schedule with daily volume ceilings, and the bounce thresholds that should make you stop and reassess.
Available on request — ask us for a copy
Reference
If you have been forwarded a report full of acronyms, start here.
| Term | What it means in practice |
|---|---|
| SPF | A public list of the servers allowed to send mail using your domain name. If a sender is not on the list, receiving systems get suspicious. |
| DKIM | A cryptographic signature added to each message. It proves the message really came from you and was not altered along the way. |
| DMARC | Your published instruction telling receiving systems what to do when SPF and DKIM fail: do nothing, quarantine, or reject. |
| MX record | The DNS entry that tells the world which server accepts mail for your domain. Change it wrong and inbound mail stops. |
| Blocklist | A public database of sending addresses believed to send spam. Landing on one can stop delivery to millions of mailboxes within hours. |
| Feedback loop | An arrangement where a mailbox provider tells you when recipients mark your mail as junk, so you can suppress those addresses. |
| MTA-STS | A policy that forces encrypted transport to your mail servers, preventing a downgrade to plaintext delivery. |
| Warm-up | Gradually raising sending volume from a new IP or domain so providers build trust rather than treating a sudden spike as an attack. |
| Bounce rate | The share of messages permanently rejected. Above roughly two percent, providers begin treating your mail as low quality. |
| Journaling | Capturing a copy of every message into an archive as it is sent or received, usually for legal or regulatory retention. |
Begin with the baseline audit. Fixed fee, one week, and the findings document is yours whether or not you hire us for the remediation.