Gmail moved from soft 4xx deferrals to permanent 5xx rejections in November 2025. Microsoft has been rejecting non-compliant bulk mail since 5 May 2025, and a recipient adding you to their Safe Sender list does not override it. The rules are all published; what nobody has is a straight answer to “is our sending domain actually ready?” This is that answer, per domain, in writing, before you press send.
Buy Now — $19One-time payment · works offline · nothing leaves your browser
On 30 September 2025 Google retired the High / Medium / Low / Bad reputation grades that marketing teams had watched for years. They were replaced by a pass/fail Compliance Status view in Postmaster Tools v2 — and a Compliance Status change can take up to seven days to appear. The gentle early-warning signal is not there any more, and the thing that replaced it reports after the fact.
Requirements and enforcement dates change. This is a checklist and recordkeeping aid, not deliverability advice — verify current requirements with each mailbox provider’s own documentation before a launch.
Nothing connects to anything. You record what you verified, where the evidence lives, and who has to fix what — and you get a readiness record a marketing team can hold, defend and hand to IT without a meeting.
SPF under ten DNS lookups. DKIM alignment with the visible From: domain, not just a passing signature. The literal List-Unsubscribe-Post: List-Unsubscribe=One-Click header. HTTPS POST, not GET or a redirect. Both unsubscribe headers inside the DKIM signature. The specifics that decide it, not a generic “set up SPF” line.
Any failure in authentication or one-click unsubscribe raises a CAMPAIGN BLOCKED banner naming the items, no matter how healthy the score looks. Those are the failures that produce permanent 5xx rejection — averaging one away behind twelve passes is exactly how a send gets refused.
Unverified items count as not passing and get their own counter with a one-click filter, so the gap between what you have confirmed and what you are assuming stays visible. N/A is the only status excluded from the denominator, and you have to choose it deliberately.
Every failing and unverified item, with its evidence note, grouped by owner — Marketing, IT, ESP — so the IT block is one contiguous list to paste into a ticket. Copy it as plain text, print the full record, or export every domain as JSON.
One sending domain mid-audit. The score says 71%, but that is not the headline — the two hard failures are.
| Check | Owner | Evidence | Status |
|---|---|---|---|
| List-Unsubscribe-Post headerLiteral List-Unsubscribe=One-Click | ESP | Header absent in raw source, 4 Sep | Fail |
| SPF alignment with From:Passes on the ESP bounce domain only | IT | DMARC report, week of 1 Sep | Fail |
| Postmaster Tools v2 verificationVerified on the click-tracking host | IT | Needs re-check on the DKIM d= domain | Unknown |
| Complaint rate under 0.1%0.06% across the last 30 days | Marketing | Postmaster daily view, screenshot filed | Pass |
| Unsubscribes honoured in 2 daysSuppression syncs nightly | Marketing | Tested 28 Aug, opt-out stopped in 4h | Pass |
Your options today are a deliverability platform priced per-seat for a team that already has a deliverability manager, or a spreadsheet that does not know an aligned DKIM signature from a passing one. This is the thing in between: a purpose-built auditor for one set of dated, enforced rules — for $19, once, before the next campaign goes out.
Buy it, open it, audit your first sending domain this afternoon. No account, no subscription, no seat count.
No. It makes no network calls at all — that is deliberate, because it means your domain list, volumes and internal notes never leave the machine. You check SPF, DKIM and the headers with the tools you already use, and this is where the answers, the evidence and the ownership live afterwards.
Enter your volume and it says so plainly, with a note that authentication is still expected of every sender. The threshold is also crossed on a single large send, so the useful posture is to audit as though the full requirements apply rather than discover mid-launch that they did.
Tick transactional-only and section B is set to N/A and excluded from the score, with the exemption stated inline: transactional mail is exempt from the one-click unsubscribe requirement. Authentication is not exempt, so section A stays in force in full.
It will not say 92% and pass if a check in authentication or one-click unsubscribe is failing. Those two sections are hard blockers — they are what produces a permanent 5xx rejection rather than a retryable deferral — so a failure there raises the blocker banner regardless of how many other items pass.
Nowhere. It is a single HTML file storing everything in your own browser. You will be typing in sending domains, platform names, volumes and internal notes, so that matters. Export a JSON backup whenever you want a copy, or import one to move it to another machine.