P H O T O N

CONSOLE

Loading

Free Developer Tool • Limit: 5 Tests / Day (5/5 left today)

Email Deliverability & DNS
Authentication Checker

Scan your sending domain in 5 seconds. Identify SPF 10-lookup limits, missing DMARC policies, weak DKIM keys, and MX routing flaws before your emails hit the spam folder.

Real-time DoH DNS & Multi-RBL Query
Try Popular Domains:
Deliverability Standards

The Google & Yahoo 2024 Bulk Sender Requirements

Understanding the strict enforcement rules that dictate whether your transactional alerts land in the primary inbox or the spam folder.

Requirement Why ISPs Enforce It How PhotonRelay Handles It
Mandatory SPF & DKIM Confirms that the sending server has explicit authorization to dispatch mail on behalf of the domain, eliminating spoofed sender addresses. Automated Built-in SPF routing and automatic 2048-bit cryptographic DKIM key rotation on all outgoing messages.
DMARC Alignment Instructs receiving mail servers what action to take when emails fail SPF or DKIM checks, preventing brand impersonation. Included Guided DMARC progression from p=none monitoring to strict p=reject enforcement.
Spam Rate Below 0.3% Google Postmaster Tools strictly flags domains whose user-reported spam complaints exceed 0.10% (target) and 0.30% (blocking threshold). Reputation Shield Automated real-time bounce suppression and isolated IP routing protect your sending reputation.
Valid Forward & Reverse DNS (PTR) Receiving mail servers cross-check that sending IP addresses resolve back to the sender's verified hostname. Pre-Configured 100% of PhotonRelay Anycast edge nodes maintain synchronized rDNS PTR records.

The 4 Hidden Reasons Transactional Emails Land in Spam

Even with clean code, subtle DNS errors can silently destroy your domain reputation.

Exceeding 10 SPF Lookups

RFC 7208 limits DNS lookups to exactly 10. If third-party SaaS tools push your lookup depth to 11, mail servers return a PermError and reject messages automatically.

Weak 1024-bit DKIM Keys

Legacy 1024-bit RSA keys can be brute-forced with modern cloud computing. Major mailbox providers now favor or require 2048-bit keys for maximum trust.

Duplicate SPF Records

Publishing two separate TXT records starting with v=spf1 completely breaks authentication. RFC mandates that all includes must be combined into one single record.

Stuck on DMARC p=none

Leaving DMARC at p=none forever provides zero defense against bad actors spoofing your domain. Spammers can freely impersonate your brand without triggering spam filters.

Engineering FAQ

Frequently Asked Deliverability Questions

RFC 7208 restricts SPF resolution to a maximum of 10 DNS queries (such as include:, a, mx, and redirect) to prevent denial-of-service loops. If your domain exceeds 10 lookups, receiving mail servers trigger a PermError and reject messages. To fix this, you must "flatten" your SPF record or remove unused vendor includes.

SPF verifies the IP address of the sending relay, while DKIM cryptographically signs the email header and body to verify they weren't altered in transit. Because emails can be forwarded (which breaks SPF IP alignment), having valid 2048-bit DKIM signatures guarantees authentication survives forwarding.

Start with p=none and monitor aggregate feedback reports via the rua= tag for 2 to 4 weeks to identify all legitimate sending services. Once verified, graduate to p=quarantine; pct=25; and incrementally scale up to pct=100 before finally enforcing p=reject.

When you add your domain in PhotonRelay, our system provides turnkey DNS records with 2048-bit DKIM keys and guided SPF includes. We automatically maintain Anycast reverse DNS (rDNS), enforce TLS 1.3 encryption, and monitor real-time ISP feedback loops to protect your reputation.