Email Deliverability & Authentication
Getting legitimate email delivered
I help MSPs and businesses understand and improve email deliverability, including SPF, DKIM and DMARC configuration, Microsoft 365 and third-party senders, delivery failures and ongoing monitoring of email authentication.
Email authentication
The DNS records are the easy part
Creating an SPF, DKIM or DMARC record is not particularly difficult. The important part is understanding everything that sends email using your domain, how those messages are authenticated and what will happen when receiving systems evaluate them.
Microsoft 365 may be only one source of email. Websites, CRM systems, accounting software, marketing platforms, helpdesks, scanners, applications and other third-party services can all send messages using an organisation's domains.
Before enforcing a stricter DMARC policy, those legitimate senders need to be understood. Otherwise a change intended to improve email security can also stop genuine messages from being delivered.
Assessment & remediation
Understand what is sending before changing it
I can review the current email authentication configuration for a domain and investigate the systems that are legitimately sending email on its behalf.
That includes reviewing SPF, DKIM and DMARC, checking alignment, identifying sending services, looking for configuration errors and understanding what existing DMARC data tells us about the domain.
Where changes are required, I can work with the existing IT team or MSP to correct the configuration and move towards an appropriate DMARC policy without simply switching enforcement on and hoping nothing breaks.
Typical work
Authentication, delivery and investigation
SPF, DKIM & DMARC
Review, configuration and troubleshooting of email authentication, including sender identification, alignment and moving towards an appropriate DMARC enforcement policy.
Delivery Problems
Investigation of messages being rejected, classified as junk or failing authentication, including mail flow, DNS, sending configuration and information returned by receiving systems.
Third-Party Senders
Identifying and correctly configuring applications and services that send using your domains, rather than assuming all legitimate mail originates from Microsoft 365.
Troubleshooting
Why is my email going to junk?
SPF, DKIM and DMARC are important, but passing all three does not guarantee that a message will arrive in the recipient's inbox.
When email is rejected or repeatedly classified as junk, I can investigate the wider delivery path rather than treating an authentication result as the end of the diagnosis.
That can include DNS and authentication, message headers, mail flow, the sending service, reputation indicators and the response from the receiving system. The aim is to establish what is actually affecting delivery rather than repeatedly changing DNS records in the hope that something improves.
Case study
Three years of improving a complex email environment
One of my long-standing clients operates a complex, email-dependent business with high volumes of both transactional and person-to-person email. I have worked with the organisation for many years and was also responsible for its migration to Microsoft 365.
Email authentication became a much larger piece of work than simply publishing SPF, DKIM and DMARC records. Once DMARC reporting was introduced, it exposed the extent to which systems and third-party services had accumulated over the years and were sending email using the organisation's domains.
Some were known and business-critical. Others were examples of shadow IT that the central IT function had little or no visibility of. Each source had to be understood before deciding whether it should be correctly authenticated, changed, replaced or stopped.
While that work was underway, the requirements imposed by major receiving platforms also changed. The organisation's email volumes were high enough for strengthened bulk-sender requirements to matter directly, making correct authentication and the continuing clean-up increasingly important.
Improving the environment has therefore been a gradual process over approximately three years rather than a one-off DNS change. That approach has allowed legitimate mail flows to be identified and corrected while the requirements surrounding email authentication and deliverability have continued to evolve.
It is a good example of why I don't treat DMARC as a DNS-record exercise. The reporting provides ongoing visibility into how an organisation's domains are actually being used for email, including senders nobody knew were there.
Ongoing monitoring
Email authentication is not a one-off job
An email environment continues to change after SPF, DKIM and DMARC have been configured. New services are introduced, old services are retired, DNS changes and previously unknown senders can appear.
The requirements of the organisations receiving your email change too. What was sufficient when an environment was first configured may need to be revisited as providers tighten their requirements for authentication and bulk senders.
I can continue to monitor the environment after the initial assessment and remediation work, reviewing DMARC reporting and looking for changes, unexpected senders or authentication failures that deserve investigation.
This provides an ongoing check that legitimate mail continues to authenticate as expected and gives someone responsibility for looking at the information rather than simply collecting DMARC reports that nobody reads.
For MSPs
A specialist service for your clients
I can provide email authentication and deliverability work behind the scenes for MSPs, allowing you to offer the service to your own clients without needing to develop specialist knowledge internally.
That might be a one-off investigation for a client with a delivery problem, an SPF, DKIM and DMARC review for an existing customer, or ongoing monitoring after the initial work has been completed.
I can work with your engineers and remain behind the scenes, or work with the client as part of your technical team where that is more appropriate. The client relationship remains yours.
Microsoft 365 & Exchange
Part of the wider email environment
Email deliverability often overlaps with Microsoft 365 and Exchange. Mail flow, connectors, accepted domains, third-party filtering and applications can all affect how messages are sent and received.
I have specialised in Microsoft Exchange since 2006 and can follow a delivery problem beyond the DNS records when the investigation requires it.
Get in touch
Need to improve or investigate email delivery?
Whether you need SPF, DKIM and DMARC reviewed, have a specific delivery problem to investigate, or want someone to keep an eye on the environment once everything is correctly configured, tell me what you need help with.