Skip to content
Fusion Technologies

Infrastructure · Assessment

Email & Domain Health Check

Find the DNS and authentication gaps that quietly send your invoices, quotes and notifications to spam — before a customer tells you they never received them.

Business email fails in ways that are easy to miss. Mail leaves your system, appears in the sent folder and never arrives. Almost always the cause is configuration: a sending service missing from SPF, DKIM signing never switched on, no DMARC policy at all.

This check inspects the public DNS surface of your domain and reports what is present, what is missing and what is inconsistent.

Enter the domain used in your email addresses — the part after the @. Public DNS records only.

Automated analysis is being connected. Until then a specialist runs the check manually and sends you the findings — no automated score is generated on this page.

Included in the check

  • MX records and mail routing
  • SPF record presence, syntax and included senders
  • DKIM presence where discoverable
  • DMARC policy, alignment and reporting setup
  • General DNS health and obvious misconfiguration
  • Common deliverability configuration gaps

What this check reviews

MX records

Whether mail routing is defined correctly and points at the provider you actually use, without stale leftovers.

SPF

Record presence and syntax, plus whether every legitimate sending service — CRM, helpdesk, invoicing, marketing — is authorised.

DKIM

Signing presence for common selectors, so receiving servers can verify messages have not been altered in transit.

DMARC

Whether a policy exists, how strict it is, whether alignment is plausible and whether reports are being collected.

DNS health

Nameserver consistency, conflicting or duplicated records, and configuration likely to cause intermittent failures.

Mail-domain alignment

Indicators of whether the visible sender domain aligns with the authenticated domain across your sending tools.

Sending surface

An inventory of the third-party platforms that appear to send on your behalf, including ones nobody remembers approving.

Configuration gaps

Common omissions such as missing subdomain policy, unprotected parked domains, or legacy servers still permitted to send.

What the report includes

  • A record-by-record view of your current email authentication setup.
  • Missing or misconfigured records, with what a corrected version should express.
  • The list of services that appear authorised to send as your domain.
  • A safe sequence for moving DMARC from monitoring towards enforcement.
  • Risks worth addressing first, such as unprotected domains used for spoofing.
  • Whether the issues are configuration-level or point to a platform change.

We report configuration facts, not promises. Correct authentication removes a major cause of rejection, but no check or provider can guarantee inbox placement — reputation, list quality and recipient-side filtering all remain factors.

How it works

  1. 1

    Submit the domain

    Tell us the domain and, if useful, which services you send business email through today.

  2. 2

    We inspect public DNS

    MX, SPF, DKIM where discoverable, DMARC and supporting records are reviewed for presence, syntax and consistency.

  3. 3

    You get a corrective plan

    Findings plus the order to fix them in, so enforcement can be tightened without blocking legitimate mail.

Frequently asked questions

What is an email domain health check?
It is a review of the DNS records that decide whether your business email is accepted, filtered or rejected: MX routing, SPF, DKIM where it is discoverable, DMARC policy and general DNS hygiene.
Why do legitimate emails still land in spam?
Usually because authentication is incomplete or inconsistent — an SPF record that omits a sending service, DKIM signing that was never enabled, or a DMARC policy that is missing or set to none while sources fail alignment.
Can DKIM always be detected from outside?
Not always. DKIM is published on a selector, and selectors are not listed in DNS. We can confirm common ones and identify signatures from received mail, but full verification may need a message header or admin access.
Does fixing DNS guarantee inbox placement?
No. Authentication removes a major reason for rejection, but placement also depends on sending reputation, list quality, content and recipient-side filtering. No provider can guarantee inbox delivery.
Is it safe to enable DMARC enforcement immediately?
Moving straight to reject can block legitimate mail from services you forgot about. The safer route is monitoring first, confirming every legitimate source aligns, then tightening the policy in stages.
Do we need to change email provider to fix this?
Rarely. Most issues are configuration, not platform. Where a migration does make sense — consolidating mailboxes or moving off an unmanaged server — that is a separate, planned exercise.

Get business email onto solid ground.

From authentication cleanup to consolidating mailboxes on a managed platform, we handle the implementation as well as the diagnosis.