Email Authentication Remediation Plan
Build a prioritised remediation plan
Your prioritised plan will appear here.
From status to safe sequence
The tool does not award readiness because records merely exist. It puts sender discovery and rollback first, then SPF and DKIM verification, DMARC monitoring, evidence review and only then an enforcement decision.
What “evidenced” means
Use Yes only when the result is backed by current DNS values, provider configuration and received-message headers from every real sending route. Unknown is deliberately treated as work remaining.
Keep enforcement human-controlled
The report never changes DNS or recommends an automatic move to reject. A human must review legitimate sources, failures, business risk and an exact rollback route before increasing policy.
Authoritative references
Read the underlying standards and provider instructions before changing production DNS: RFC 7208 (SPF), RFC 9989 (DMARC), Google Workspace SPF guidance and your sending provider's current DKIM documentation.
Publish carefully
Always verify generated records against your email provider's official documentation. Never paste private DKIM keys, DNS passwords or API tokens into a public tool.
Editorial responsibility
Published by Acerville Sparks Limited. Software assists research, drafting and automated record testing. Internet standards, provider documentation, reproducible checks and limitations are shown so readers can inspect the work. No independent deliverability consultant review is claimed. Reviewed 4 September 2026.
What this site does not do
No inbox guarantee. No live DNS checks. No storage of entered data. No passwords or private keys requested.