Free PDF Report · 24h Delivery

Free Email Deliverability Audit, Ranked by What to Fix First
SPF · DKIM · DMARC · Blacklists

Enter your domain and receive a full deliverability PDF: every DNS record, blacklist and reputation signal a receiver sees, ranked by impact, each with a plain-language fix. Within 24 hours. No upsell, no obligation.

  • SPF / DKIM / DMARC validation with alignment + lookup-count check
  • Major blacklist scan: Spamhaus, Barracuda, Sorbs, SURBL, Invaluement
  • Sender-reputation review (Postmaster, SNDS) + MX / reverse-DNS / BIMI / MTA-STS
  • Plain-language remediation steps you can apply without me

Two fields, one PDF, within 24 hours. The audit reads public DNS only, no credentials or access needed.

Not just another scanner

You can scan your domain in seconds. This is the part the scanner skips.

Ranked, not just listed. Free tools return pass and fail rows. This returns a fix list ordered by impact, most damaging issue first, so you spend your time on the one thing actually hurting your inbox placement.

Read in context. A tool will not tell you that your SPF is one lookup from failing, that your 1024-bit DKIM key is overdue for rotation, or that flipping DMARC to reject today would bounce your own mail. The interpretation is the point.

One consolidated read. SPF, DKIM, DMARC, blacklists, reputation, MX, BIMI and MTA-STS in a single report, not eight browser tabs. Same public data every receiver sees, one place, plain language.

What's in the report

What the deliverability audit checks

A scanner runs these same checks and stops at pass or fail. The report goes one step further on each one: what the result means for your inbox placement, whether it is urgent or cosmetic, and the exact change to make.

SPF

Record syntax, lookup-count budget (10-DNS-lookup limit), `+all` / `~all` / `-all` policy review, alignment with the From header.

DKIM

Selector discovery, key length (RSA 1024 vs 2048), key rotation status, signature alignment with the visible sender domain.

DMARC

Policy (none / quarantine / reject), percentage rollout, aggregate (`rua`) and forensic (`ruf`) reporting destinations, subdomain policy.

Blacklists

Spamhaus (SBL, XBL, PBL, DBL, ZEN), Barracuda, Sorbs, SURBL, Invaluement, domain & sending-IP coverage with delisting links.

Sender reputation

Google Postmaster signals (where verifiable), Microsoft SNDS readiness, common reputation flags. No invented "sender score", only what receivers actually publish.

MX & reverse DNS

MX record health, PTR record matching the HELO string, common misconfigurations that quietly drop legitimate mail.

BIMI

Whether your DMARC posture is strong enough to qualify for BIMI, VMC requirements, and what your logo would need to look like.

MTA-STS & TLS-RPT

In-transit encryption posture, MTA-STS policy file, TLS-RPT reporting endpoint configuration.

Plain-language fixes

Each finding ranked by impact (high / medium / low) with a concrete remediation step a competent admin can apply without further consulting.

What you receive

A report you can act on, not a dashboard to decode

Findings are grouped by impact, high, medium, low, each showing the record as it stands now and the exact change to make. This is the layout you receive for your own domain.

Run by Lotfi, the engineer behind OLDEV, a solo WordPress, CRM and email-deliverability practitioner. The audit reads only publicly visible DNS and reputation data, so you hand over no credentials and no access to your systems.

FAILSPF: 11 DNS lookups, over the 10 lookup limit. Receivers can return permerror and ignore SPF. Flatten or trim included senders.
WARNDKIM: selector found, key is 1024-bit. Rotate to 2048-bit to meet current signing standards.
FAILDMARC: policy p=none. You get reports but no protection. Move to quarantine after reviewing aggregate data.
OKMX and reverse DNS: PTR matches HELO, mail flow healthy.
WARNBlacklists: listed on 1 of 9 checked. Delisting link included in the full report.
Why this matters

The cost of poor deliverability is silent

If even a quiet share of your transactional and marketing email lands in spam, the impact is rarely visible in your stats, bounces stay low, the dashboard stays green, but customers stop replying, password-reset emails get blamed on "the system", and onboarding sequences silently underperform.

Most fixes are configuration-only: a corrected SPF record, a properly aligned DKIM signature, a DMARC policy that reports rather than rejects until you trust the data. None of them require new infrastructure or vendor change. They just require knowing what to look at and in what order.

That's the audit. A flat, opinionated read of your domain's current state, ranked by what to fix first.

How it works

Three steps, one PDF

  1. 01

    Enter your domain

    Email + domain (no protocol, no path, just example.com). Optional name. That's the entire form.

  2. 02

    The audit runs against your domain

    Public DNS records, blacklist registries and reputation signals are pulled and checked against the priority rules an engineer applies, then compiled into a report ranked by impact.

  3. 03

    PDF in your inbox

    Within 24 hours. If it doesn't show up, peek in spam (a small irony when auditing deliverability) and add the sender to your contacts.

FAQ

Common questions

Why not just run a free scanner like mail-tester or MXToolbox?
Use them, they are good at what they do: telling you whether a record passes or fails right now. What they do not do is tell you which failure is actually hurting your inbox placement, what order to fix things in, or how to change a record without breaking the two next to it. This report reads the same public data and adds that layer: priority, context, and the exact fix. If you already read SPF lookup budgets, DKIM key rotation and DMARC rollout comfortably, the scanners are enough. If you want the read on top, that is this.
Is the audit really free? What is the catch?
No catch and no payment step. Running the audit is mostly automated on my side, so one more costs me little. It is also how people find out whether my paid work is any good without risking anything. If the report helps and you later want deliverability or CRM work handled, you know where to find me. If not, you keep the report and we are done.
How is my email used? Is my data safe?
Your email is used for one thing, sending you the report. It is not added to a newsletter, sold, or shared with third parties. The audit only reads publicly visible DNS and reputation data, the same records any receiving mail server sees, so you give me no credentials and no access to your systems.
How fast will I get it?
Within 24 hours of submitting the form. You receive an email with the PDF attached when it is ready.
Do I have to get on a call?
No. The report lands in your inbox and stands on its own. No call, no discovery session, no follow-up sequence. If you want to talk, you reach out. I do not chase.
Do I have to pay you to fix the issues?
No. Every finding comes with a plain-language step a competent admin can apply. If you would rather have it handled, the CRM Migration service includes a full deliverability audit and the fixes in the package, and standalone deliverability work can be quoted from a written brief on the contact page. Either way, the audit itself asks nothing of you.
What is the difference between SPF, DKIM, and DMARC?
SPF tells receiving servers which IPs are allowed to send for your domain. DKIM cryptographically signs each message so receivers can confirm it was not modified in transit. DMARC tells receivers what to do when SPF or DKIM fail and where to send aggregate reports. The three work together; none of them alone stops all spoofing.
What if my domain doesn't send email yet?
Auditing a not-yet-sending domain is actually the best moment, you get a clean baseline and a checklist before warm-up. The report flags what to set up before your first send.
Do you handle blacklist delisting?
The report identifies which lists you appear on and links to each list's delisting form. Most major lists accept self-service delisting once the underlying issue is fixed. Stubborn cases (Spamhaus, repeat offenders) can take a paid engagement to resolve.
Do you need access to my DNS or email account?
No. The audit only uses publicly visible DNS records and public reputation data. You do not give me any credentials, and I cannot read your email.
Chat on WhatsApp