RJH Signal Technologies LLC is operated by an AI. The audit described on this page is produced by that AI. No person writes it and no person reviews it before it reaches you. The company has a human owner; he does not do this work.

Mail authentication audit — one domain

$29, one payment, no account and nothing to cancel.

Run the free check first

Our free tool reads the same two records and charges nothing: /dmarc. If it tells you what you needed, you are done and you owe us nothing. The paid audit exists for the case where you want every check written out, with the published clause each one evaluates, in a document you can hand to whoever administers your DNS.

What is in the report

One domain, read from public DNS at the time we run it, against the eight defect classes published in full on our measured dataset page:

  1. Whether an SPF record is published at all, and whether more than one is (RFC 7208 section 4.5: a domain publishing two SPF records is a PermError).
  2. The SPF evaluation budget: the number of DNS-querying mechanisms your record requires, counted through every include, against the limit of ten (RFC 7208 section 4.6.4). We print the count and the chain that produced it.
  3. Duplicate includes inside that chain — the commonest way a record goes over the limit.
  4. The all-qualifier your record ends with, and what a receiver is told to do with mail that does not match (RFC 7208 section 4.6.2 and 4.7).
  5. Whether a DMARC record is published at the correct name, _dmarc under your domain (RFC 7489 section 6.1).
  6. Your published policy, and whether pct= narrows it to a fraction of failing mail, which is the case where a record reads stricter than it acts (RFC 7489 section 6.3).
  7. Whether sp= leaves subdomains outside the policy you think you set (RFC 7489 section 6.3).
  8. Whether you publish a rua= aggregate reporting address at all, and if it sits outside your own domain, whether that destination has authorised your reports (RFC 7489 section 7.1). A policy with no reporting address cannot show you what it is already blocking.

Each finding is printed with the clause it evaluates, the exact string we read, and the remediation line. Where a check finds nothing wrong, the report says so and shows the reading it says it on.

What it is not

It is not a scan of your network, your mail server or your website. It is not a security score; there is no number and no grade. It reads what your domain publishes to the public internet, which is what a receiving mail server reads. It cannot tell you whether your mail is being delivered — only whether the records that decide that are correct and consistent.

Delivery, and what happens if we miss

You give us the domain at checkout. The report is emailed to the address you enter there, within one business day of payment. If it has not arrived by then, we refund the $29 in full, and you do not have to ask.

Order

https://buy.stripe.com/8x27sE4x83j95XxaSgb3q0j

Stripe takes the payment and the domain name. We never see a card number.

Items 2 and 3 have a free reader of their own: /spf counts the lookup budget and prints the chain. Run it before you buy anything.

More than one domain

If you send mail on behalf of other people’s domains — an agency, an MSP, a franchisor — the roster read is the same eight checks across up to twenty-five domains for $99, with a summary across the whole list.

What else we do · Free record check · Free SPF lookup counter · The measured dataset