Skip to content
EssentialSecurity, theme, and saved preferences.Always on

We do not send your name or email to affiliates.

Independent cold email launch QA

Catch infrastructure blockers before your client does.

Check every sending asset before launch. Get one verdict, exact fixes, and proof your client can inspect.

No mailbox credentials Works with any stack
Harbor Health
monitoring
Do Not Launch 4 blockers
MX record Google Workspace
SPF record 7 of 10 lookups
DMARC policy not found
Tracking SSL certificate expired
SMTP PTR generic NAT name
HELO alignment banner mismatch

Verdict

Do Not Launch

4 blockers

75

deterministic checks

4

asset types

14 days

Launch Report rechecks

Scheduled

Continuous QA

The independent signoff layer.

Sending, placement testing, and launch QA answer different questions. OutboundQA complements the rest of the stack by making the launch decision inspectable.

Sending platform

Smartlead, Instantly

Builds sequences, rotates mailboxes, and runs campaigns.

Can the campaign send?

Placement test

GlockApps, Mail-Tester

Samples where a specific test message lands.

Where did this message land?

Independent launch QA

OutboundQA

Checks the workspace infrastructure and records the decision.

Should this setup launch?

Infrastructure breaks quietly.

The workflow breaks before anyone sees it. One expired tracking certificate, missing DMARC record, or renamed cloud NAT PTR can sit unnoticed until the campaign is live.

Many workspaces and domains

No standard launch signoff

No proof when someone asks

launch board 2 blockers

Harbor Health

links.harbor-mail.com

SSL expired

Winslow Dental

_dmarc.winslow-mail.com

record missing

Cityline Roofing

cityline-outreach.com

12 days old
3 infra layers

Silent infrastructure breaks become visible before the campaign goes live.

From assets to a launch decision.

A pre-flight checklist for cold email infrastructure. CSV in, evidence out.

workspace-assets.csv normalized

CSV in

Sending domains, inboxes, tracking domains, and tool names.

deduped grouped by workspace ready to check
01

Upload the CSV

Domains, inboxes, tracking domains, SMTP egress paths, and sending tools go into one import.

02

Run the checks

Domain + Email + Links evidence resolves across mail, authentication, tracking, receiver requirements, reputation risk, and SMTP egress identity. Add one sent .eml when you need message-surface evidence.

03

Fix with evidence

Copy exact records or preview and confirm eligible Cloudflare changes. Provider tokens are never stored.

04

Verify and share

Run fresh checks, share the verdict, and keep the approved baseline watched.

Try it live

Run a check on your domain.

Three of the 57 domain checks, running live in your browser against real DNS. No signup, no sending-tool access. Click any result to see the exact fix.

MX, SPF, and DMARC checked instantly

The same pass, warning, and blocker model used in the full report

No domain handy? .

A free lookup finds a record. Paid QA owns the launch.

Free tools answer one question for one domain. OutboundQA connects every asset, prioritizes one fix per root cause, records the verdict, and keeps watching after approval.

Capability Free tool Paid QA
Scope One signal Whole workspace
Decision Lookup result Ready / Needs Fix / Do Not Launch
Remediation Generic guidance Grouped root cause and exact fix
Proof Browser result Shareable evidence report
After launch Run it again manually Daily or hourly monitoring
Operations No history Alerts, incidents, summaries, webhooks

The checklist

75 checks.
One verdict.

Each result shows status, evidence, and the fix. Every sending domain runs up to 57 checks. An inbox inherits those checks and adds 3 native probes. Tracking domains add 8 checks and SMTP egress paths add 7. Conditional evidence runs only when the required data is available.

Mail and DNSAuthenticationWebsiteRisk and senderSender historyInboxTracking domainSMTP egress
evidence view Winslow Dental
MX record google.com
SPF DNS lookups 7 of 10
DMARC record not found
Tracking SSL expired
blocker

DMARC record missing

Add a TXT record at _dmarc.winslow-mail.com before launch.

v=DMARC1; p=none; rua=mailto:dmarc@winslow-mail.com
Northstar Labs running checks

Mail and DNS

MX record google.com
Mail provider Google Workspace
DNS host Cloudflare
Nameserver redundancy 2 nameservers
MX connectivity port 25 reachable
MX STARTTLS advertised
MX TLS certificate valid identity
Zone transfer exposure AXFR closed
Wildcard DNS not exposed
DNSSEC chain consistent
CAA records 1 issuer allowed

Authentication

SPF record 1 record
Single SPF record 1 found
SPF DNS lookups 7 of 10
SPF syntax valid
SPF enforcement -all hardfail
SPF record length 42 bytes
DMARC record found
DMARC reporting rua set
DMARC report authorization authorized
Live DMARC report routing receiver evidence on
Subdomain DMARC coverage covered
Subdomain lockdown policy enforced
DMARC alignment SPF or DKIM aligned
Live DMARC alignment receiver-confirmed
Observed sending sources 3 authorized
DMARC pass-rate trend stable
DKIM key strength 2048-bit
BIMI readiness prerequisites met
DANE and TLSA configured
MTA-STS record found
MTA-STS policy mode enforce
TLS-RPT record found

Website

Root domain resolves A record ok
Root domain HTTPS valid
HTTP to HTTPS redirect 301 ok
Root redirect target primary site
Parked domain risk real site
Root SSL expiry 74 days left

Risk and sender

Domain expiry 345 days left
Registrar lock transfer lock on
Blacklist status clean
Safe Browsing status no warning
SPF-declared senders 3 discovered
Undeclared egress IPs all declared

Sender history

Abuse events none found
Incident severity low
Reputation trend stable
Neighbor risk clean neighborhood
Network owner risk low
Shared pool exposure dedicated
Infrastructure risk score 12 of 100

Inbox

Recipient acceptance RCPT accepted
Catch-all behavior not catch-all
Role mailbox coverage expected roles found

Tracking domain

Tracking domain resolves CNAME found
Tracking CNAME target points at ESP
Tracking SSL valid cert
Tracking SSL expiry 60 days left
Tracking HTTP status 200 ok
Redirect chain 2 hops
Tracking blacklist clean
Tracking Safe Browsing no warning

SMTP egress

SMTP PTR smtp01.acme-mail.com
Expected PTR match matches mail host
Generic NAT name none detected
Forward-confirmed rDNS IP matches PTR
HELO alignment smtp01.acme-mail.com
SMTP banner expected identity
Sending IP blacklist clean

Verdict

Needs Fix

3 to resolve

See the host your recipient sees.

DNS can look right while the sent message still loads an open pixel or sends a click through a shared provider host. Upload one test email to compare the observed hosts with the tracking domain in your workspace.

01 Send one test email to yourself

02 Save the message as a .eml file

03 Upload it for host-level evidence

No mailbox password, sender connection, or DNS access. The original message is discarded after analysis. Only normalized host-level findings remain.

Message-surface preflight Observed

Configured tracking host

links.harbor-mail.com

External host observed

shared-tracking.example

Review whether the sending setup can use the workspace tracking domain.

This is observed message evidence. It does not prove an inbox-placement outcome or change the launch verdict.

A clear go, or a clear no.

Deterministic rules, current public evidence, and no hidden AI score. Unknown evidence stays unknown instead of becoming a misleading pass.

verdict engine same inputs, same result
Ready

Cleared to launch

0 blockers

  • Authentication present
  • Tracking SSL valid
  • Blacklist clean
Needs Fix

Fix before sending

2 warnings

  • DKIM selector unknown
  • Domain under 30 days
  • DMARC at p=none
Do Not Launch

Hold the campaign

2 blockers

  • Missing DMARC
  • Tracking SSL failed
  • SPF over 10 lookups

Proof you can stand behind.

The check becomes evidence: verdict, passed checks, blockers, exact fixes, and a link that turns invisible infrastructure work into something people can inspect.

Observed evidence and check source Exact fix and verification rerun Shareable link or PDF via browser print Honest disclaimer, no inbox-placement claims

Launch QA report

Harbor Health

Prepared June 26, 2026

Do Not Launch

D+E+L

evidence run

11

passed

2

blockers

Authentication

SPF and DKIM present

pass

DMARC policy

TXT record not found

fail

Tracking SSL

certificate expired

fail

Domain age

12 days old

warning

Exact fixes

Add DMARC, reissue the tracking SSL certificate, then rerun the launch check.

outboundqa.com/r/harbor-launch

This report checks technical infrastructure readiness. It does not guarantee inbox placement.

Clear it once. Watch it hourly.

Launch Reports recheck daily for 14 days. Continuous QA schedules the complete deterministic suite and records the latest successful run, coverage, alert freshness, and regression evidence. It is polling, not event-driven DNS monitoring.

Daily, weekly, or monthly portfolio summary

Severity-routed email and Slack alerts

Signed JSON webhooks for incident workflows

Monitoring reliability is not a promise on this page. Delivery, forced-regression detection, and recovery timing are published only after a controlled production drill. Read the verification method.

14 day monitor daily recheck

Day 0

Launch check

Ready verdict saved

Day 3

Daily recheck

No changes found

Day 8

SSL changed

Tracking domain failed

Day 14

Final digest

Report history retained

Immediate alert

Harbor Health moved from Ready to Do Not Launch: tracking domain SSL failed.

email digest Slack webhook

Built for serious outbound. Not every sender.

Use OutboundQA if
  • You run cold email for your company or for clients
  • You manage 10+ inboxes or 3+ sending domains
  • Operators, contractors, or founders set up infrastructure under deadline pressure
  • Clients, cofounders, or sales leads ask you to prove the setup is healthy
Skip it if
  • You only need a free one-off DNS lookup
  • You want warmup or guaranteed inbox placement
  • You want unconfirmed access to registrar or mailbox settings
  • You send from one inbox and do not need launch signoff

Pricing

Simple pricing for launch QA.

Start with a free check, buy a one-time launch report, or keep Continuous QA running across repeated outbound launches. Paid plans add shareable reports, monitoring, alerts, and history.

Free Check: one workspace, up to 10 assets, launch verdict, exact fixes, and one verification rerun. Paid plans add launch reports, monitoring, alerts, and history.

Free Check

$0

For checking one outbound setup before buying a launch report.

  • One outbound workspace
  • Up to 10 assets across domains, inboxes, tracking domains, and SMTP egress
  • Launch verdict
  • Exact fixes for blockers and warnings
  • Guarded Cloudflare apply for eligible DNS records
  • One verification rerun to confirm your fix
  • No shareable report, monitoring, alerts, or history
Run free check

Launch Report

$49 once

For one outbound workspace that needs a documented verdict before launch.

  • One outbound launch workspace
  • Up to 50 assets across domains, inboxes, tracking domains, and SMTP egress
  • Full 75-type infrastructure catalog
  • Shareable launch report with blockers, warnings, and fixes
  • 20-minute findings debrief after your first verdict
  • Preview, confirm, verify, and roll back eligible Cloudflare fixes
  • 14 days of daily drift monitoring
  • One remediation rerun after fixes
  • Email alert if the verdict changes
Create a launch report
Recommended

Continuous QA

$79 / month

For teams and agencies that need a repeatable launch QA workflow across multiple workspaces.

  • Up to 100 monitored assets
  • Unlimited workspaces for companies, brands, or clients
  • Scheduled deterministic checks with cadence shown in the workspace
  • Email and Slack destinations with visible test freshness
  • DNS baseline, incident history, and recovery rechecks
  • Audited Cloudflare DNS remediation
  • Daily, weekly, or monthly portfolio summaries
  • Agency-branded reports with public-open activity
  • Signed JSON webhooks for incident workflows
  • Report history for every launch
  • Standard workflow for repeated launch QA
Start monitoring

What counts as an asset?

Sending domain

acme-mail.com

DNS, authentication, web, reputation, and registration evidence.

Inbox

alex@acme-mail.com

Mailbox and sending-domain evidence for an outbound address.

Tracking domain

links.acme-mail.com

CNAME, TLS, HTTP, redirect, reputation, and expiry evidence.

SMTP egress

203.0.113.10

Sending-IP PTR, forward DNS, HELO, banner, and blacklist evidence.

A workspace can represent one company, brand, or client. OutboundQA checks technical infrastructure readiness; it does not guarantee inbox placement. Monitoring delivery and recovery performance are published only after a controlled production drill.

Partner program

Help your audience launch with proof. Earn 30%.

Refer outbound agencies, consultants, and founders that need an independent infrastructure verdict. Approved partners receive a tracked link and earn commission on eligible customer payments.

Straight answers.

No. OutboundQA checks technical infrastructure readiness before launch. It does not guarantee inbox placement, and the report says so in plain language.

It can confirm visible infrastructure failures and keep provider incidents, recipient-domain mix, and external placement results in separate evidence classes. If the available evidence does not establish a cause, OutboundQA says Unknown and identifies the next controlled test instead of guessing.

Smartlead and Instantly operate campaigns and deliverability workflows. MXToolbox combines free diagnostics with paid delivery monitoring, while GlockApps specializes in placement evidence. OutboundQA is the independent launch acceptance layer across those tools: it checks the infrastructure for the whole client workspace and returns one evidence-backed launch verdict.

It starts as a launch check: it verifies the setup before a campaign goes live, then rechecks it daily for 14 days so a silent break gets caught early. Continuous QA runs the complete infrastructure pass hourly for as long as the subscription is active.

No. Upload a CSV with sending domains, inboxes, tracking domains, SMTP egress paths, and sending tool from inside the workspace. The audit never needs mailbox passwords or a sending-platform API key. Eligible Cloudflare DNS fixes are optional: you provide a zone-scoped token for preview and confirmation, and OutboundQA never stores it.

A sending domain is the domain used for outbound email, like harbor-mail.com or the domain behind alex@harbor-mail.com. A tracking domain is usually a branded subdomain used for tracked links and opens, like links.harbor-mail.com or click.harbor-mail.com.

Yes. When you provide the SMTP egress path, OutboundQA checks PTR/rDNS, generic cloud NAT names, forward-confirmed rDNS, HELO/EHLO alignment, and the live SMTP banner without authenticating or sending mail.

Yes. OutboundQA is independent of the sending tool, so it works across Smartlead, Instantly, Salesforge, or a mixed stack. Cloudflare DNS fixes can be previewed and applied separately without sharing sending-platform credentials.

MX, mail provider, DNS host, and nameserver redundancy, SPF including the 10-lookup limit and enforcement, DMARC policy and reporting, DKIM selector and key strength, MTA-STS and TLS-RPT, root domain resolution, HTTPS, redirect, and parked-domain risk, domain age, current blacklist status, SPF-declared sender discovery, historical sender risk from OutboundQA monitoring, optional IP abuse history, Google and Yahoo sender requirements, the tracking domain end to end (CNAME target, SSL, HTTP status, redirect chain, blacklist), and SMTP egress identity signals such as PTR, forward-confirmed rDNS, HELO/EHLO, and banner alignment.

Yes. Every check produces a clean report at a shareable link, and you can export it to PDF with browser print.

Don't launch outbound blind.

Run the pre-flight check on your next campaign. Get the verdict, the fixes, and a report people can trust.

Product tour

See the launch QA flow.