Skip to content
EssentialSecurity, theme, and saved preferences.Always on

We do not send your name or email to affiliates.

Back to OutboundQA

Anonymized recovery record

From blocker to verified recovery.

This composite example uses reserved names and representative evidence. It shows the decision trail a Launch Report is built to preserve.

Recovery verified
  1. 1. Baseline

    Assets captured before launch

    Sending domain, inboxes, tracking domain, and SMTP egress added to one workspace.

  2. 2. Blocker discovered

    DMARC and DKIM were missing

    The first verdict stopped launch and recorded the exact DNS and provider actions required.

  3. 3. Fix applied

    Authentication records published

    The operator enabled DKIM, published its selector, and added the recommended DMARC record.

  4. 4. Fresh verification

    Recovery confirmed by a new run

    A fresh full check observed both records and preserved the final Ready verdict with timestamps.

Initial blocker snapshot

Harbor Health

Checked Aug 24, 2026 . harbor-mail.com

Do Not Launch

17

checks

11

passed

4

warnings

2

blockers

Fix before launch

  • DMARC record. Add a DMARC TXT record at _dmarc.harbor-mail.com. Start at p=none, then move to quarantine once reports look clean.
  • DKIM selector. Turn on DKIM in your sending tool and publish the key it generates, then re-run to confirm the signature passes.

Mail and DNS

MX record google.com Pass
Mail provider Google Workspace Pass
DNS host Cloudflare Pass

Authentication

SPF record 1 record Pass
Single SPF record 1 found Pass
SPF DNS lookups 5 of 10 Pass
SPF enforcement -all hardfail Pass
DMARC record not found Fail

Add a DMARC TXT record at _dmarc.harbor-mail.com. Start at p=none, then move to quarantine once reports look clean.

DMARC policy no record to enforce Warning

Once the DMARC record exists, raise the policy from p=none to p=quarantine so unauthenticated mail is filtered, not just reported.

DKIM selector none at common selectors Fail

Turn on DKIM in your sending tool and publish the key it generates, then re-run to confirm the signature passes.

MTA-STS enforce mode Pass

Website

Root domain resolves A record ok Pass
Root domain HTTPS no valid cert Warning

Serve the root domain over valid HTTPS so it looks legitimate to recipients and filters.

HTTP to HTTPS redirect no redirect Warning

Redirect all HTTP traffic to HTTPS so every visit lands on the secure page.

Risk and sender

Domain age 192 days Pass
Blacklist status clean on Spamhaus, SpamCop, Barracuda Pass
Google and Yahoo checklist 2 gaps: DMARC, DKIM Warning

Close the gaps: a valid DMARC record and a confirmed DKIM signature both satisfy the Google and Yahoo bulk-sender requirements.

This report checks technical infrastructure readiness. It does not guarantee inbox placement.

Launch Report · $49 once

Want this decision trail for your next launch?

Get the first verdict, exact remediation steps, one recovery rerun, a shareable report, 14 days of daily monitoring, and a 20-minute findings debrief.