Who this is for
Two kinds of operator. The first runs a small business whose mail started bouncing or landing in spam after Gmail and Yahoo began enforcing bulk-sender authentication in February 2024 and moved to permanent 550 rejections in November 2025, and after Microsoft followed in May 2025. The second runs cold outbound across 20 to 200 sending domains and needs every one of them checked before a campaign goes out, because a single misconfigured domain gets a sequence deferred.
In both cases the symptom is the same sentence, "our emails are going to spam", and the first thing worth ruling out is authentication, because it is the one part of the problem that DNS can both see and fix.
What you get, per domain
- SPFrecord syntax, the DNS lookup count against the limit, and the terminal qualifier
- DKIMselectors found, key length, and whether the public key resolves
- DMARCpolicy, alignment mode, rua and ruf addresses, and whether reports can actually be delivered
- MX / PTRMX records and whether the sending IPs have reverse DNS that resolves forward
- BIMI · TLS-RPT · MTA-STSpresent or absent, and whether what is present parses
- blocklistsstatus on the public RBLs at the moment of the check, with the list name and the time
- fix blockthe exact TXT, CNAME, and MX records to add or change, in the order to apply them
- scorea send-readiness score scoped to authentication
Multi-domain orders arrive as one spreadsheet with every domain's findings and block, plus a summary PDF. If you grant read access to Google Postmaster Tools we put its reputation readout beside the DNS findings, and say plainly that reputation is not something a DNS record changes.
# shape of a fix block (values are yours, not these) example.com. TXT "v=spf1 include:<your provider> -all" sel1._domainkey. CNAME <your provider's DKIM host> _dmarc. TXT "v=DMARC1; p=quarantine; rua=mailto:<your rua>; adkim=s; aspf=s" _smtp._tls. TXT "v=TLSRPTv1; rua=mailto:<your tls-rpt>" # apply in the order listed; the PDF says why each line is there and what the check saw
How it works
- You type the domain and your email. For multi-domain orders you paste or attach the list when we reply.
- We read DNS and the blocklists and write the block. The check is deterministic, so the free score comes back by email usually within the hour and paid fix blocks within one hour of the order.
- You paste the block into your DNS. We never log into your registrar, your mail server, or your sending platform. When propagation finishes, the records validate; if the block we gave you does not validate, the order is refunded.
Prices
| tier | price | what |
|---|---|---|
| free score | $0 | score and the first two findings by email |
| fix block, one domain | $19 | full per-domain check and the copy-pasteable DNS block, as a PDF |
| up to 25 domains | $199 | every domain checked, every block written, one spreadsheet plus a summary PDF |
| up to 150 domains | $499 | the same, for a cold-outbound fleet |
Refund condition on every paid tier: refund if the DNS block we give you does not validate. For multi-domain orders, refund if the block for any domain does not validate. Prices are in US dollars.
Why it costs what it costs
A deliverability consultant charges $3,000 to $15,000 and takes one to two weeks, because the engagement covers list, content, warm-up, and reputation as well as DNS. Inbox Communications sells a $500 audit as three sessions over about two weeks. On Fiverr, "fix SPF/DKIM/DMARC" gigs run $5 to $75 with one to three day turnarounds. MXToolbox and EasyDMARC will score a single domain for free, and DMARC monitoring services run $9 to $129 a month.
The free score here is the same thing the free checkers do, and we do not pretend otherwise. $19 is the price of the part they stop short of: the exact records to paste, written for your provider, with the order to apply them and a refund if they do not validate. The $199 and $499 tiers exist because nobody running 25 or 150 domains wants to paste them into a free checker one at a time, and the consultants are priced for a different problem.
What this is not
- This check covers authentication and DNS. It tells you whether a domain is authentication-ready, not whether your mail will reach the inbox. List quality, content, volume, and sender reputation are outside what DNS can show.
- We do not touch your DNS, your mail server, or your sending platform, and we do not send mail from your domain. You paste the block.
- Blocklist status is what each list returned at the moment of the check. It changes.
- Not legal advice. Compliance with CAN-SPAM, GDPR, CASL, or any other mail law is yours.
- Refund if the DNS block we give you does not validate.
Questions
Our emails are going to spam. Will this fix it?
It fixes the authentication part, which is the part a receiving server checks first and the only part DNS can change. If SPF, DKIM, or DMARC is missing or misaligned, mail is rejected or filtered before content is ever looked at, and the block fixes that. If authentication is already clean and mail still lands in spam, the cause is the list, the content, the volume, or the sending reputation, and the report will tell you that authentication is not your problem rather than selling you a block you do not need.
Gmail is returning 550 5.7.26. What is that?
Gmail's rejection for mail that is not authenticated to its bulk-sender standard: no passing SPF or DKIM aligned with the From domain, or no DMARC record, or both. The free score shows which of those is missing for your domain; the $19 block has the records that close it.
I can run MXToolbox for free. Why pay $19?
You can, and the free score here is the same information. The $19 is for the block: the records already written for your provider, in the order to apply them, with the reason for each line and a refund if it does not validate. If you are comfortable writing SPF with the lookup limit in mind and setting strict DMARC alignment yourself, you do not need us.
Do you need access to my DNS or my sending platform?
No. We read public DNS and public blocklists, and you paste the block yourself. The only optional access is read access to Google Postmaster Tools, if you want the reputation readout beside the findings.
I have 80 domains for cold outbound. How do I send them?
Put one domain in the box, leave your email, and when we reply, paste the list or attach a CSV. The $199 tier covers up to 25 domains and the $499 tier up to 150, so 80 domains is the $499 tier. You get one spreadsheet with a row per domain and a block per domain.
From the record
These are public asks and market facts that shaped the offer. They are not customer testimonials.
“Gmail and Yahoo began enforcing bulk-sender authentication requirements in 2024, and Microsoft added high-volume sender requirements in 2025.”Published sender-requirement timelines
“Fiverr SPF, DKIM, and DMARC fixes are listed from $5 to $75 with one-to-three-day delivery windows.”Offer research, current market