Email infrastructure problems do not announce themselves. They develop quietly: a misconfiguration introduced during an ESP migration. This SPF record has exceeded its lookup limit, a DKIM key that has not been rotated in three years, a subdomain that was used for one campaign and never properly decommissioned.
These problems accumulate unnoticed until they cause a deliverability issue. By that point, they have often been silently degrading email performance for months.
Why Infrastructure Audits Matter More Than Campaign Audits
Most email teams invest significant time in campaign audits reviewing performance metrics, A/B test results, subject line performance, and content quality. These reviews are valuable, but they measure outputs, not the infrastructure that produces those outputs.
Infrastructure determines whether campaigns can succeed at all. An email with a perfectly written subject line, brilliant content, and precise audience segmentation still hits the spam folder if the sending domain has an SPF misconfiguration, a DKIM alignment failure, or a reputation problem that pre-dates the campaign.
Infrastructure problems also have compounding effects. A broken SPF record does not just affect one campaign; it affects every send from that domain until it is fixed. A domain that gradually accumulates negative reputation signals affects campaign performance for months before the effect is visible in the data.
Quarterly audits catch these compounding problems at an early stage, before they require recovery.
Authentication Audit: SPF, DKIM, and DMARC
SPF Check
Tool: MX Toolbox SPF Lookup (mxtoolbox.com/spf.aspx)
What to check:
- Does an SPF record exist for your sending domain and all sending subdomains?
- Is the SPF record syntactically valid?
- How many DNS lookups does the record require? Must be below 10.
- Does the record include all current sending sources: your ESP, CRM, transactional ESP, billing system, support tools?
What to do if the lookup count exceeds 10: Use an SPF flattening service to convert dynamic includes to static IP ranges. Recount after flattening.
What to do if a sending source is missing from SPF: Add its include or IP range. Verify with MX Toolbox after DNS propagation (allow 24–48 hours).
DKIM Check
Tool: Send a test email to mail-tester.com and review the DKIM result. Or use a DKIM lookup tool with the specific selector.
What to check:
- Is DKIM signing enabled and configured for your sending domain in your ESP?
- Is the DKIM key size 2048 bits? (1024-bit keys are no longer considered sufficient)
- Has the DKIM key been rotated in the past 12 months?
- Do all third-party sending tools that use your domain in the From address have DKIM signing configured with your domain’s keys?
What to do if DKIM key is 1024 bits: Generate a new 2048-bit key in your ESP. Publish the new public key in DNS. Configure the ESP to use the new key. Decommission the old key record after 7 days.
DMARC Check
Tool: MX Toolbox DMARC Lookup (mxtoolbox.com/dmarc.aspx)
What to check:
- Does a DMARC record exist at _dmarc.yourdomain.com?
- What is the current policy level (p=none, p=quarantine, p=reject)?
- Is a valid rua= reporting address configured?
- Have you reviewed the DMARC aggregate reports recently?
What to do if still at p=none after 6+ months: Review recent DMARC aggregate reports to confirm all legitimate sending sources pass authentication. If confirmed, move to p=quarantine. Set a 4-week review checkpoint before considering p=reject.
Sending Domain and Subdomain Audit
Over time, sending domains and subdomains accumulate. A campaign from 18 months ago used a dedicated subdomain. A temporary domain was registered for a product launch. A test environment used a subdomain for automated sends.
Inventory Check
List every domain and subdomain associated with email sending activity. Include:
- Primary business domain
- Email-specific subdomains (mail., hello., newsletter., news., updates.)
- Product or service-specific subdomains
- Domains used by third-party tools that send email on your behalf
For each domain and subdomain, verify:
- Is it still in active use?
- Does it have current SPF, DKIM, and DMARC records?
- Is it registered in Postmaster Tools?
- What is its current blacklist status?
Decommission Dormant Domains
Domains and subdomains not currently in active use should be decommissioned. Remove their MX records and email authentication records to prevent them from being used for phishing. If the domain is no longer needed, do not renew the registration; expired domains with email infrastructure history are sometimes exploited.
Blocklist Monitoring Audit
Current Status Check
Tool: MX Toolbox Blacklist Check (mxtoolbox.com/blacklists.aspx)
Run a blacklist check for:
- Your primary sending domain
- All sending subdomains
- Your primary sending IP address(es)
Record the results. A clean result now is your baseline for next quarter’s comparison.
Setting Up Ongoing Monitoring
Do not rely solely on quarterly manual checks. Set up automated blocklist monitoring:
- MX Toolbox offers automated monitoring with email alerts
- Many ESPs include blacklist monitoring in their platform (check your ESP’s deliverability features)
- Google Postmaster Tools provides domain-level signals that often correlate with blacklist events
Automated monitoring should alert you within 24 hours of a new listing. A blacklist listing discovered during the quarterly audit may have been present for weeks and costing you deliverability during that entire window.
ESP and Platform Configuration Audit
Sending Infrastructure Review
What to check:
- Are all sending domains and subdomains using the correct From/Return-Path configuration for DMARC alignment?
- Is your dedicated IP (if applicable) correctly warmed and showing a healthy reputation in Postmaster Tools?
- Are there any active campaigns or automated sequences using deprecated or migrated From addresses?
- Are feedback loop configurations current, and are your ESP’s feedback loop registrations still active with Gmail, Microsoft, and Yahoo?
Automated Sequence Audit
Review all active automated sequences: onboarding, drip, re-engagement, win-back, behavioural triggers. For each:
- Is the From address current and authenticated?
- Is the unsubscribe link functional?
- Is the content still relevant (not referencing deprecated features, discontinued promotions)?
- Is the sequence still enrolled to the correct audience segment?
Abandoned automated sequences that continue sending to stale audiences are a common source of gradual reputation damage.
Suppression List Audit
Cross-System Sync Check
What to check:
- Does your ESP suppression list match your CRM suppression database?
- Has there been any suppression sync failure in the past quarter?
- Are hard bounces from the past quarter properly reflected in both systems?
Verification method: Export the suppression list from your ESP. Export the suppressed/invalid contacts from your CRM. Compare the two lists. Any address in one but not the other indicates a sync gap.
Suppression List Growth Rate
Track the number of suppressed contacts added per quarter. Sudden growth in the suppression list indicates a list quality event: a new import with high invalid rates, or an unverified segment reaching a campaign send.
Gradual suppression growth (reflecting natural address decay at expected rates) is normal. Unexpected spikes warrant investigation.
List Quality Audit
Invalid Rate Assessment
If the full list has not been verified in the past 90 days, run a sample verification of 5,000 contacts representative of the full list composition to estimate the current invalid rate. A sample invalid rate above 8% indicates that a full list verification is overdue and should not wait for the next scheduled cycle.
Engagement Rate by Acquisition Cohort
In your ESP, segment the contact list by the quarter in which each contact was acquired. Calculate the click rate for each cohort. Cohorts with significantly lower click rates than more recent cohorts are aging out of engagement and should be run through the sunset process.
Postmaster Tools and SNDS Review
Google Postmaster Tools (Gmail)
What to check quarterly (beyond the weekly review):
- Spam Rate trend over the past 90 days — is it stable, trending up, or trending down?
- Authentication pass rates — any declines from previous quarter?
- Domain Reputation consistency — any periods of Medium or below over the quarter?
- Delivery Errors — any error types appearing that were not present last quarter?
Microsoft SNDS
What to check:
- IP reputation colour code — Green, Yellow, or Red?
- Complaint rate data — any increase over the past quarter?
- Trap hits — any indication of spam trap activity in Microsoft’s data?
Audit Cadence and Ownership
A quarterly audit means 4 times per year. For most programmes, this is appropriate. For high-volume programmes sending more than 5 million emails per month, a monthly audit is warranted.
Assign ownership explicitly: one person is responsible for completing the quarterly infrastructure audit. Without named ownership, the audit defaults to everyone’s responsibility and becomes nobody’s priority.
Time requirement: a complete audit takes 3–4 hours for most programmes. The majority of that time is reviewing and interpreting results, not running the checks themselves.
Key Takeaways
- Email infrastructure problems develop quietly and compound over time. A quarterly audit catches them before they cause deliverability crises.
- The authentication audit (SPF lookup count, DKIM key size, DMARC policy level) catches the most common and most impactful infrastructure problems. SPF exceeding 10 lookups and DKIM at 1024-bit keys are both silent but significant issues.
- The sending domain inventory audit often reveals abandoned subdomains and deprecated From addresses that are generating signals without being monitored. Decommission dormant sending entities.
- Suppression list cross-system sync verification prevents the recurring problem of suppressed contacts re-entering active sends through unsynchronised systems.
- Postmaster Tools and SNDS quarterly review provides a longitudinal view of reputation trends that weekly checks do not reveal.
- Assign explicit ownership for the quarterly audit. Without a named responsible person, infrastructure maintenance defaults to reactive (when something breaks) rather than proactive.
Frequently Asked Questions
The SPF lookup count check. An SPF record that exceeds 10 DNS lookups causes SPF evaluation failure silently. The email is not rejected, but SPF fails, which degrades DMARC alignment and contributes to domain reputation erosion. Most teams discover their SPF lookup count only after a deliverability problem prompts investigation.
Take a known suppressed contact one that you deliberately added to the suppression list and check whether they appear as suppressed in your ESP, your CRM, and your marketing automation platform. If they are suppressed in all three systems, the sync is working. If they are suppressed in one but not the others, you have a sync gap.
Post-migration: verify that SPF was updated to include the new ESP’s sending infrastructure, verify that DKIM signing is active with the new provider, verify that DMARC aggregate reports still flow to the rua= address, verify that the new ESP’s IP addresses are not pre-listed on any major blocklists, and register the sending domain in Postmaster Tools for the new sending context.
Conclusion
Email infrastructure is the foundation your entire programme runs on. Campaign optimisation, content strategy, and audience segmentation all operate on top of this foundation. When the foundation is unstable, authentication is misconfigured, suppression lists are unsynchronised, and abandoned subdomains are generating signals, everything built on it underperforms relative to its potential.
The quarterly audit is the maintenance practice that keeps the foundation stable. Three to four hours, four times per year, prevents the categories of problem that take months to recover from. The time investment is orders of magnitude smaller than the time required to recover from a preventable infrastructure failure.
Schedule it. Own it. Document the results. Fix what the audit finds. The email programme that runs on well-maintained infrastructure outperforms the one running on neglected infrastructure every quarter, compounding over years.
