Three Things We Cover on Our Initial Diagnostic Calls That Most Providers Don't Touch

November 5, 2025

Subscribe to our newsletter

Arrow
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

If you've had deliverability audits before, you probably got the same checklist: SPF exists, DMARC is set to something, bounce rate isn't alarming. Check, check, check. But that surface-level review misses the structural issues that quietly undermine everything else.

Here's what we dig into on every initial diagnostic call:

1. DNS Alignment Review (DKIM, SPF, DMARC)

We thoroughly examine the alignment between domains, subdomains, and sending sources to make sure each authentication method is configured correctly and consistently.

Most audits stop at "yes, DMARC is published." We want to know if it's actually aligned. Is your DKIM signing domain matching your From domain? Is SPF passing but DMARC failing because the envelope domain doesn't align? Are you using subdomains that aren't covered by your authentication setup?

Misalignment doesn't always break delivery immediately—but it creates fragility. One misconfigured tool or new sending source and suddenly nothing passes DMARC. Inbox providers notice.

What this looks like in practice: We pull your DNS records and map every sending source against your authentication setup. We verify that DKIM signatures, SPF records, and DMARC policies are all pointing at the right domains and actually aligned with how you're sending. If we find gaps—like a subdomain that's sending but not authenticating properly—we document exactly what needs to change and why.

2. Subdomain Separation Strategy

We look at how email traffic types are organized today—cold, marketing, transactional, product notifications—and identify where reputations are being blended in ways that could create fragility. We map out a cleaner approach that isolates risk and preserves trust.

Here's the issue: when everything sends from one domain, there's no firewall between use cases. A complaint spike from an outbound campaign affects your invoice emails. A deliverability issue in your newsletter drags down password resets. You lose control.

Most providers don't talk about this until something breaks. We address it upfront because separating reputations is easier before you have a problem than after.

What this looks like in practice: We review your current email inventory—every type of message you send and where it's coming from today. Then we design a subdomain architecture that creates clean separations: outbound prospecting on one subdomain, lifecycle marketing on another, transactional notifications on a third. Each gets its own reputation. If one channel has issues, the others stay protected. We also map out the warming plan so new subdomains build reputation gradually instead of starting cold at high volume.

3. DNS Record Cleanup and SPF Stability

We frequently find old records lingering from previous tools, pilots, and vendors. These can contribute to SPF lookup limits and create silent instability. We review which records are necessary, remove the rest, and ensure the authentication chain is both clean and resilient.

SPF has a hard limit: ten DNS lookups. Go over that and SPF fails—even if the record itself is technically correct. The problem is, most companies accumulate includes over time. Old ESPs, forgotten integrations, that tool you tested two years ago and never fully removed. Each one counts toward your limit.

We've seen records with fourteen lookups. Sixteen. Twenty. And nobody noticed until delivery started quietly degrading.

What this looks like in practice: We audit your SPF record line by line and identify every include, every redirect, every mechanism that triggers a DNS lookup. Then we verify which ones are still actively sending on your behalf. Anything that's not? Gone. We also flatten nested includes where possible and restructure the record to stay well under the ten-lookup limit with room to grow. The result is a stable, future-proof SPF setup that won't break the next time you add a new tool.

Bottom line: If your last audit gave you a green checkmark but didn't dig into these three areas, you probably have structural issues waiting to surface. We find them early.

We’d love to learn more about your business, email deliverability and outreach goals, and see if we might be able to help.

Whether you have questions about what we do, how Protocol works, or you’d just like to pick our brains on some of our best practices, we’d be happy to chat.

Schedule a call with our Revenue Director, Chrisley Ceme.

Talk To Chrisley

If you've had deliverability audits before, you probably got the same checklist: SPF exists, DMARC is set to something, bounce rate isn't alarming. Check, check, check. But that surface-level review misses the structural issues that quietly undermine everything else.

Here's what we dig into on every initial diagnostic call:

1. DNS Alignment Review (DKIM, SPF, DMARC)

We thoroughly examine the alignment between domains, subdomains, and sending sources to make sure each authentication method is configured correctly and consistently.

Most audits stop at "yes, DMARC is published." We want to know if it's actually aligned. Is your DKIM signing domain matching your From domain? Is SPF passing but DMARC failing because the envelope domain doesn't align? Are you using subdomains that aren't covered by your authentication setup?

Misalignment doesn't always break delivery immediately—but it creates fragility. One misconfigured tool or new sending source and suddenly nothing passes DMARC. Inbox providers notice.

What this looks like in practice: We pull your DNS records and map every sending source against your authentication setup. We verify that DKIM signatures, SPF records, and DMARC policies are all pointing at the right domains and actually aligned with how you're sending. If we find gaps—like a subdomain that's sending but not authenticating properly—we document exactly what needs to change and why.

2. Subdomain Separation Strategy

We look at how email traffic types are organized today—cold, marketing, transactional, product notifications—and identify where reputations are being blended in ways that could create fragility. We map out a cleaner approach that isolates risk and preserves trust.

Here's the issue: when everything sends from one domain, there's no firewall between use cases. A complaint spike from an outbound campaign affects your invoice emails. A deliverability issue in your newsletter drags down password resets. You lose control.

Most providers don't talk about this until something breaks. We address it upfront because separating reputations is easier before you have a problem than after.

What this looks like in practice: We review your current email inventory—every type of message you send and where it's coming from today. Then we design a subdomain architecture that creates clean separations: outbound prospecting on one subdomain, lifecycle marketing on another, transactional notifications on a third. Each gets its own reputation. If one channel has issues, the others stay protected. We also map out the warming plan so new subdomains build reputation gradually instead of starting cold at high volume.

3. DNS Record Cleanup and SPF Stability

We frequently find old records lingering from previous tools, pilots, and vendors. These can contribute to SPF lookup limits and create silent instability. We review which records are necessary, remove the rest, and ensure the authentication chain is both clean and resilient.

SPF has a hard limit: ten DNS lookups. Go over that and SPF fails—even if the record itself is technically correct. The problem is, most companies accumulate includes over time. Old ESPs, forgotten integrations, that tool you tested two years ago and never fully removed. Each one counts toward your limit.

We've seen records with fourteen lookups. Sixteen. Twenty. And nobody noticed until delivery started quietly degrading.

What this looks like in practice: We audit your SPF record line by line and identify every include, every redirect, every mechanism that triggers a DNS lookup. Then we verify which ones are still actively sending on your behalf. Anything that's not? Gone. We also flatten nested includes where possible and restructure the record to stay well under the ten-lookup limit with room to grow. The result is a stable, future-proof SPF setup that won't break the next time you add a new tool.

Bottom line: If your last audit gave you a green checkmark but didn't dig into these three areas, you probably have structural issues waiting to surface. We find them early.

Our Revenue Director, Chrisley Ceme, is leading the Triggered Outbound program.Chrisley’s gone deep on this strategy and can walk you through:

  • How Triggered Outbound fits with your outbound goals
  • What triggers are available (and what’s possible within our platform)
  • Pricing, onboarding, and getting started
Talk To Chrisley

Subscribe to our newsletter

Arrow
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Senders Case Studies

See All Case Studies

Momofuku

Founded by chef David Chang, Momofuku is a renowned culinary brand with a nation-wide presence, including restaurants and an online store with delicious goods. They ran into an issue with their email sending – high bounce rates and blocked sending. With hundreds of thousands of people on their email lists eager to stay informed, and an impeccable reputation to uphold, Momofuku wanted to nip this problem in the bud quickly.

  • Momofuku reached out to Senders to run a diagnostic test on their sending infrastructure and find the root cause
  • Senders deliverability experts discovered an issue with their DMARC, which was preventing emails from being sent, as their WordPress wasn't aligned with their SPF
  • Senders provided the most effective solution helping Momofuku restore safe sending, and suggested next steps to ensure everything keeps running smoothly on their end
  • The client reported that Senders helped identify the problem and got them back on track 

Andrew Yeung

Where many others see a problem, Andrew sees an opportunity. His work may center around product leadership at Google (and previously Meta), but his true calling is all about bringing brilliant change-makers together.

How it started: Andrew hosted small-scale dinners for a handful of people at the peak of the pandemic in NYC, to enable safe connections during the most isolating times. How it’s going: His events now count as many as 2,000 tech leaders each, and he has set up 100+ such parties for more than 15,000 people in the past couple of years. Andrew understands that if two minds are better than one, putting two thousand together, preferably in the same room, can make a profound difference.

Given the impact of his community-building efforts, people want him to be able to reach out – and email is often the best way to do so. So, we helped out a bit.

  • Andrew came across deliverability issues that prompted him to get in touch with Senders and look into the best possible solutions
  • The Senders team made the necessary domain configuration adjustments, with a focus on the domain’s email authentication settings to enhance security and deliverability
  • The SPF record was updated to include “Brevo” (Sendinblue) to strengthen authentication and reduce the chance of landing emails into spam
  • The DMARC policy update enabled better readability of DMARC reports for human analysts, which is essential for preventing email spoofing and phishing
  • Senders fixed the missing DKIM setup with Google, so that it now shows the email hasn’t been tampered with in transit
  • As a result, the client now has better, more stable email deliverability and security

Myrina.ai

Stands out as a trailblazer in empowering women entrepreneurs through technology and a supportive community.

Myrina.ai offers a cutting-edge range of AI-powered SaaS marketing and sales tools that cater specifically to female entrepreneurs and women-led businesses. Myrina.ai enables users to automate marketing and sales, while helping them scale their authentic selves while saving time and boosting conversions. Their Myrina’s Army community fosters a supportive platform that champions female entrepreneurs and their values, empowering them to conquer barriers and achieve their business goals. The company's dedication to providing not only top-notch technological solutions but also a platform for networking and mentorship underscores their commitment to fostering success among women in the entrepreneurial space.

Naturally, they wanted to make sure their email sending infrastructure was set up correctly to protect their reputation and successfully reach their recipients. Our deliverability team worked with the client’s team on:

  • Aligning the client’s three domains with Amazon to make sure they are compatible and optimized in order to integrate with Amazon’s system
  • Setting up a proper DMARC policy to protect their domains against unauthorized use and phishing scams
  • Enhancing email deliverability as well as security, so that each email sent from these domains can be properly authenticated and more likely to land in the right inbox
  • As a result, the client can protect the reputation of their business and domains, while safely sending out their email campaigns

Physician’s Choice

Sometimes the sheer number of options of any product can be daunting – how on earth do you pick the right one? This is especially true with supplements, as we can find them just about anywhere, but we can rarely understand a third of the ingredients listed. Unlike most, Physician’s Choice provides supplements with pure, potent ingredients that work. No fillers or “proprietary” blends with unidentified ingredients. They do the research, so you don’t have to.

  • The client’s team spotted issues with DMARC failures in Google Postmaster
  • The Senders deliverability team worked with the client to update the DMARC configuration to enable report collection
  • The client is now able to obtain detailed reports to diagnose the exact causes of the failures and prevent them in the future with proper DMARC setup