Skip to main content
email·digit
Deliverability

Authentication is our job,
not yours.

Authentication decides whether your email arrives, and it's the part every tool hands back to you as a documentation page. We run it as a service: rotation, policy progression and warm-up are ours, and your DNS is touched exactly once.

Start here

Check any domain, right now.

No account. SPF, DKIM, DMARC, MX and five major blocklists — and for every failure, the exact record to publish, not just a red X.

Setup

Three records.
That's the whole ask.

Two CNAMEs and one TXT. The CNAMEs point at names we control, which is exactly why we can rotate what's behind them without ever asking you to edit DNS again.

Record
Purpose
What you publish
Status
DKIM · CNAME
Signs every outgoing message so a receiver can verify it really came from your domain.
ed1._domainkey.acme.com CNAME → acme-com-a3f1b8.dkim.emaildigit.com
Live
DMARC · CNAME
Tells receivers what to do when SPF or DKIM fail, and where to send the aggregate reports.
_dmarc.acme.com CNAME → acme-com-a3f1b8.dmarc.emaildigit.com
Live
SPF · TXT
Tells receiving mail servers which senders are allowed to send for your domain.
acme.com TXT → v=spf1 include:_spf.emaildigit.com ~all
Live

We verify across several resolvers rather than one lookup that might be cached, and we verify you own the domain before we start monitoring it.

The stack

Rotation, progression
and warm-up are ours.

Key rotation with a grace window

Two selectors
  • One signing, one on standby.
  • New mail signs with the fresh key while the retiring one stays published long enough that mail already sent still verifies.
  • There's no window where your signatures fail.

DMARC progression on evidence

Not a calendar
  • Your policy moves from monitor-only toward quarantine and then reject based on what your aggregate reports actually show about alignment.
  • Advancing on a schedule instead is how legitimate mail gets rejected by its own domain.
  • If you're already at reject, we leave it — progression only moves forward.

Warm-up as a mechanism

Graduated daily ceiling
  • A new domain starts at a low daily ceiling and climbs, but only on days its bounce and complaint rates are healthy.
  • Volume above today's ceiling is held for tomorrow, never dropped.

We run our own authentication stack. No third-party branding appears in your DNS records, your message headers, or this interface. Your domain looks like your domain.

Why now

Non-compliant mail is refused, not filtered.

Gmail and Yahoo have required DMARC from bulk senders since February 2024. Microsoft phased the same requirements into Outlook, Hotmail and Live through 2025 and completed enforcement in November. Microsoft rejects rather than junks — 550 5.7.15 Access denied. Gmail's equivalent is 550 5.7.26. If either is in your logs, your mail isn't being filtered. It's being refused.

Isolation

One sender's bad campaign is not your delivery problem.

Bounces and complaints come back from the sending provider and are attributed to the workspace that sent the message. If one sender's complaint rate climbs, that sender is throttled. Most shared platforms can only respond across a whole account, which means a stranger's bad list becomes your problem.

Ongoing

Monitoring, and compliance that ships on by default.

Domains are re-checked on a schedule and you're alerted when something changes — a record edited, a policy weakened, a new blocklist entry.

One-click unsubscribe is in the header on every marketing send, because a hard-to-find unsubscribe link produces complaints, and complaints are what actually damage a sending reputation. Opt-outs and hard bounces land on a do-not-send list with two levels: opt-outs stop marketing and are reversible; hard bounces and complaints stop everything, including your app's email, and stay stopped. The list only ever gets stricter.

FAQ

DNS questions, answered.

Do I have to move my DNS to you?

No. Three records on your existing DNS. We never ask for nameserver delegation.

What if my DMARC policy is already reject?

Then we leave it. Progression only moves forward.

Can you guarantee inbox placement?

No, and nobody honestly can — the receiving provider decides. What we can do is make sure authentication, list hygiene and complaint handling are never the reason you were filtered.

Do you run your own mail servers?

No. We own the authentication stack — the keys, the records, the policy, the reports — and send over a commercial relay. Owning the DNS story is what lets your domain look like your domain; claiming to own the wires would be a different claim, and it wouldn't be true.

Deliverability

See where
your domain stands.

The checker is free and needs no account.