# Cold email infrastructure audit template

Use one audit ID per client launch. Add one row per check and asset. Do not mark a row Ready without observed evidence and a capture time.

## Audit summary

| Field | Value |
|---|---|
| Client or workspace | |
| Audit ID | |
| Planned launch date | |
| Agency QA lead | |
| Client signoff owner | |
| Sending tool | |
| Mailbox provider | |
| DNS owner | |
| Overall verdict | Ready / Needs Fix / Do Not Launch |
| First pass completed UTC | |
| Final rerun completed UTC | |

## Asset inventory

| Asset | Type | Provider or tool | Technical owner | Included in audit | Notes |
|---|---|---|---|---|---|
| | Sending domain | | | Yes | |
| | Inbox | | | Yes | |
| | Tracking domain | | | Yes | |
| | SMTP egress IP | | | If known | |

## Findings register

Duplicate rows until every asset and check is represented.

| Asset | Check | Expected state | Observed evidence | Evidence URL or path | Captured UTC | Verdict | Blocker | Required fix | Owner | Due date | Rerun status | Rerun evidence | Rerun UTC |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| | MX routing | Expected mailbox provider is present | | | | Unknown | | | | | Not started | | |
| | SPF authorization | One valid record authorizes the active sender | | | | Unknown | | | | | Not started | | |
| | DKIM selector | Published selector resolves and matches the active sender | | | | Unknown | | | | | Not started | | |
| | DMARC record | Valid record is published and understood | | | | Unknown | | | | | Not started | | |
| | Send and reply path | Inbox can send and receive through the intended path | | | | Unknown | | | | | Not started | | |
| | Tracking CNAME | Target matches the active tracking service | | | | Unknown | | | | | Not started | | |
| | Tracking HTTPS | Certificate is valid and the redirect reaches the intended destination | | | | Unknown | | | | | Not started | | |
| | PTR and forward DNS | Known SMTP egress identity resolves in both directions | | | | Unknown | | | | | Not started | | |
| | Public blocklist check | Checked sources and unavailable lookups are recorded | | | | Unknown | | | | | Not started | | |
| | Receiver requirements | Applicable current requirements are checked against DNS and message evidence | | | | Unknown | | | | | Not started | | |

## Blocker queue

| Priority | Asset | Blocker | Required fix | Owner | Due date | Dependency | Status |
|---|---|---|---|---|---|---|---|
| Critical | | | | | | | Open |

## Rerun log

| Rerun UTC | Asset | Check | Previous verdict | New verdict | Evidence | Run by | Notes |
|---|---|---|---|---|---|---|---|
| | | | | | | | |

## Launch signoff

- [ ] Every sending domain, inbox, tracking domain, and known SMTP egress path is in scope.
- [ ] Every finding has evidence and a capture time.
- [ ] Every blocker has a named owner and required fix.
- [ ] Every completed fix has fresh rerun evidence.
- [ ] Unknown results are resolved or accepted in writing.
- [ ] The overall verdict matches the remaining findings.
- [ ] The client or accountable launch owner approved the decision.

| Decision | Name | Role | UTC time | Notes |
|---|---|---|---|---|
| Ready / Hold | | | | |

This template records observable infrastructure readiness. It does not predict or guarantee inbox placement.
