Sanitized example · illustrative company · not a live-domain audit

See the action plan before you share a domain.

This example shows the level of specificity, evidence gates, and scope boundaries in the USD 99 Email Authentication Fix Sprint. Northstar Commerce and example.com are fictional. Every DNS value below is deliberately a placeholder—customers receive values verified against their actual providers.

MX AuditEmail Authentication Fix Sprint · action plan
SANITIZED SAMPLE

Northstar Commerce · example.com

Restore authenticated sending across three services.

Illustrative evidence: public DNS snapshot plus one sanitized received-message header per sender
Authorised domain1
Sending services3
Blocking findings3
Credentials shared0
Executive finding

The domain publishes authentication records, but the supplied evidence does not prove aligned SPF or DKIM for every legitimate sender.

Do not tighten DMARC policy yet. First establish one valid SPF record, enable provider-issued DKIM for each active service, and verify aligned passes from real messages. The customer’s administrator applies every change; MX Audit verifies the result.

01 · Sender inventoryEach claimed sender must have evidence
01

Primary mailbox platform

Microsoft 365 · user mail

BLOCKED
SPFReview

More than one SPF TXT record is indicated. The final record must be a single, provider-verified policy.

DKIMMissing evidence

No aligned DKIM pass appears in the supplied sanitized header.

DMARCHold policy

Keep the current monitoring policy until every legitimate sender is aligned.

Evidence gateRequired

Provider-issued selector targets plus a new received-message header after activation.

Exact-change format

Merge the root SPF policy into one TXT record containing <provider-issued SPF mechanism>. Enable DKIM in the tenant, then publish the two exact CNAME records shown by that tenant as <selector 1 host → provider target> and <selector 2 host → provider target>. Never copy these placeholders into DNS.

02

Transactional platform

Order and account email

PARTIAL
Finding

DKIM passes for the vendor domain, but the supplied header does not prove alignment with example.com. The bounce or return-path domain also needs confirmation.

Exact-change format

In the authenticated-domain screen, collect the provider-issued DKIM and custom return-path records. Publish only those verified values, send a fresh test, and confirm that either DKIM or SPF aligns with the visible From domain.

03

Marketing platform

Permission-based campaigns

UNVERIFIED
Finding

The service is listed as legitimate, but there is no sanitized header or provider verification screen to establish the correct selectors and alignment path.

Evidence needed

Supply the platform’s authenticated-domain screen and one sanitized header from a recent campaign. MX Audit then returns the exact host, record type, target, and verification test for the real account.

Verification gate 1

DNS is coherent

Exactly one SPF policy at the root; provider-issued DKIM selectors resolve; one syntactically valid DMARC record remains published.

Verification gate 2

Real messages align

A new sanitized Authentication-Results header proves an aligned SPF or DKIM pass for each included sender.

Verification gate 3

One correction is included

If an instructed record was applied incorrectly, the sprint includes one bounded correction round and repeat verification.

Outside the fixed scope: mailbox migration, DNS administration, credentials, reputation repair, list hygiene, bulk-sending strategy, ongoing monitoring, and any promise of inbox placement. Findings depend on the public DNS and sanitized evidence supplied at the time of review.

MXAUDIT.CH

Know what you will receive

Have an active authentication problem?

Describe the platform and symptom first. MX Audit confirms fit before sending seller details, terms, and private payment instructions.

Check fit for the USD 99 sprint