Engineering capabilities
- Sending-source discovery across apps, CRM and marketing tools
- Record authoring within the ten-lookup limit
- Flattening and consolidation of nested includes
- Staged move from softfail to hard fail
Security & DNS
Sender Policy Framework records that declare exactly which hosts may send mail for a domain, built from a verified inventory of sending sources rather than guesswork.
A record is only as good as the sending inventory behind it. Sources are discovered first, then declared, then enforced.
Every system that sends as the domain is found before the record is written.
The ten-DNS-lookup limit is respected; nested includes are consolidated where a provider allows it.
Published with a short TTL during change, then raised once behaviour is stable.
Hard fail only after DMARC reports confirm no legitimate source is missing.
Most often the ten-lookup limit has been exceeded by stacked includes, or a sending platform was added without updating the record. Both show up immediately in DMARC aggregate reports.
No. A domain must publish exactly one SPF TXT record; multiple records cause a permanent error and mail starts failing authentication.
No. SPF breaks on forwarding, so DKIM signing and a DMARC policy are needed for the domain to be genuinely protected.
Send the environment details and get an engineered proposal with assumptions, risks and a rollback path.