SPF, DKIM, DMARC. Graded.
A single grade per domain from A to F — with the record you have, the record you should have, and the diff between them.
“Something changed our SPF on Friday.”
A vendor was added, a legacy record was edited to fit, and by Monday your SPF is over the ten-lookup limit — so it silently fails. Nothing in your ESP dashboard tells you: mail keeps going, delivery keeps working, right up until Gmail starts marking as spam and Microsoft starts rejecting outright. You find out from a customer, not from a tool.
sendrules grades every domain you send from every 24 hours and alerts you the moment SPF, DKIM, or DMARC drops a grade — so the Friday change is a Friday alert, not a Monday incident.
Three records. Every clause that matters.
- SPF — record presence, mechanism count against the ten-lookup limit, include-chain resolution, redirect handling.
- DKIM — selector discovery for the sources we detect, key length, algorithm, canonicalization.
- DMARC — policy, SPF and DKIM alignment mode, coverage percentage, aggregate and forensic report destinations, subdomain policy.
One-shot when you need it. Continuous by default.
Any authenticated user can grade a domain on demand. Domains attached to a tenant are re-graded every 24 hours; a change in grade or record content triggers an alert on the channel you have configured — email, signed webhook, Slack, or Microsoft Teams.
The record you have, the record you should have, the diff.
Each failing check surfaces the raw DNS record, the specific clause that failed, a corrected record you can paste into your DNS provider, and a plain-English explanation your DNS admin can act on without a second meeting.