What we do not claim
Being precise about the limits of a diagnostic is part of the diagnostic.
Four different things
They get conflated constantly, and the distinction is the whole point:
- Authentication health. Whether receivers can verify a message really came from your domain. This is SPF, DKIM and DMARC. It is deterministic, readable from DNS, and entirely fixable. This is what we measure.
- Infrastructure health. Whether your mail exchangers resolve, and whether transport security is configured. Also readable from DNS. Also what we measure.
- Reputation. How receivers regard your sending history — volume, complaint rates, spam-trap hits. Not published in DNS. We do not measure it and we do not guess at it.
- Deliverability. Whether a specific message reaches a specific inbox. A function of all of the above plus content, engagement and each receiver’s own filtering, which changes without notice. Nobody can guarantee it.
What a perfect score means
That the records we checked are correct. It means a receiver evaluating your authentication will reach a favourable answer. It does not mean your mail will be delivered, and we will never tell you it does. Correct authentication is necessary but not sufficient — it is, however, the part that is actually in your control, which is why it is worth getting right.
Things we will not say
- That we can guarantee inbox delivery
- That your email will never be marked as spam
- That a score predicts a delivery rate
- That fixing a finding will produce a specific commercial outcome
Any vendor promising those is describing something they do not control. If your problem is reputation rather than authentication, we would rather tell you that than sell you a subscription that will not help.
Where our checks can be wrong
We report DNS as our resolvers see it at the moment of the check. Propagation delays, geographically split DNS views, and a nameserver that is rate-limiting us can all produce a result that differs from what another observer sees. When lookups fail we say the report may be incomplete rather than presenting a partial answer as a whole one.
Provider identification is an inference and is sometimes wrong. DKIM absence is only ever “not found at the selectors we checked”, because DNS cannot be enumerated.