InboxRatio
Check your domain

The email deliverability checklist: setup, per-campaign and monthly checks

Keep this page open, or work through it once and copy the items into wherever your team tracks recurring work. It's organized by frequency, because that's how deliverability work actually divides: a setup layer you build once and verify on change, a short pre-send ritual, and a monitoring loop that catches decay while it's still cheap to fix. Each item links to the tool or guide that executes it, and none of it requires anything beyond DNS access, your sending platform's settings and a free Postmaster Tools account.

If checklists without context frustrate you, the map of why these items matter is our pillar guide, what is email deliverability. Everyone else: top to bottom.

Part 1: one-time setup (verify again on every change)

The foundation layer. Done properly once, these only need re-verification when DNS, platforms or sending services change.

  • [ ] SPF record published and valid. One record only — duplicates are a permanent error — including every service that sends for your domain, within the 10-DNS-lookup limit. Verify with the SPF checker; build a clean one with the SPF generator.
  • [ ] DKIM signing with your own domain. Your platform must sign as your domain, not its own — check the d= value in a real message's signature. Confirm the published key resolves with the DKIM checker; if you can't find your selector, the selector guide shows where to look.
  • [ ] DMARC record published, reports flowing. At minimum p=none with a rua address someone actually reads; the DMARC generator builds it correctly. Plan the staged move to enforcement per how to set up DMARC.
  • [ ] Full authentication pass. The email authentication checker runs SPF, DKIM, DMARC, MX and reverse DNS in one sweep — the single most efficient item on this list.
  • [ ] MX and reverse DNS sane. MX records resolving (MX lookup); PTR in order if you run your own infrastructure (reverse DNS checker).
  • [ ] Provider requirements met. Bulk senders: one-click unsubscribe headers, TLS, spam-rate ceiling. Check your setup against the Gmail, Yahoo and Outlook requirement pages.
  • [ ] Google Postmaster Tools registered. It only accumulates data forward — register before you need it.
  • [ ] Subdomain strategy decided. Marketing on its own subdomain (or at least its own DKIM identity) so a campaign incident can't taint transactional mail.
  • [ ] New domain or IP warmed before full volume. Domains: warm-up guide. Dedicated IPs: IP warming guide.
  • [ ] Signup flow filters at the door. Confirmed opt-in (double opt-in) or at minimum form-level validation; expectations (content, frequency) stated at signup.

Part 2: before every campaign

Two minutes, every send. The point is catching self-inflicted problems while they're still hypothetical.

  • [ ] Seed-send and read the headers. Send the real campaign to a mailbox you control; paste raw source into the email header analyzer and confirm spf=pass, dkim=pass (your domain in d=), dmarc=pass.
  • [ ] Segment sanity. Engaged recipients; suppression list respected; no imported or resurrected old lists sneaking in.
  • [ ] Unsubscribe works. Visible, functional, no login wall.
  • [ ] No phishing tells. Link text matches destinations; a plain-text part exists; images support text rather than replacing it; subject describes content.
  • [ ] Volume within pattern. No unplanned spikes; planned peaks ramped in advance. Receivers model your normal cadence and treat sharp deviations as anomalies.

Part 3: the monthly monitoring loop

Decay is the default state of a sending program — lists age, DNS gets edited, reputation drifts. A monthly half-hour catches it.

  • [ ] Postmaster Tools review. Domain and IP reputation bands; spam-rate trend against Google's published lines (under 0.3%, ideally under 0.1%). Any upward complaint trend is an incident, not a curiosity.
  • [ ] Bounce rates split hard/soft. Trend across campaigns, per the bounce rate guide; read actual bounce texts on anything anomalous.
  • [ ] Blocklist check. Sending domain and IPs through the blacklist checker — especially if you operate a dedicated IP.
  • [ ] DMARC aggregate reports scanned. New sources failing alignment mean someone added a service without telling you — the reports guide shows what to look for.
  • [ ] List hygiene executed. The sunset policy actually ran: re-permission at the inactivity edge, non-responders suppressed.
  • [ ] Placement spot-check. Real sends observed in real mailboxes at Gmail, Outlook and Yahoo — dashboards report acceptance, only mailboxes show placement.

Part 4: quarterly and on-change

  • [ ] Full setup re-verification — the Part 1 tool passes again, plus after any DNS edit, platform migration or new sending service. Working setups break through unrelated changes far more often than through decay.
  • [ ] DMARC enforcement progress. If you're still at p=none with clean reports, schedule the step to quarantine — the staged path is in the policy warning guide.
  • [ ] Volume/provider requirement re-check. Crossing the 5,000-a-day Gmail threshold moves you into the bulk-sender requirement set; growth changes obligations.
  • [ ] Platform review. Whether your ESP's infrastructure and policy enforcement still fit your volume and needs — the comparison our deliverability rankings are built to answer.

Scaling the list to your operation

The checklist above is written for a sender with real volume and a team. Two honest adaptations. A solo sender with a modest newsletter can run Part 1 once, keep the per-campaign seed-send, and compress the monthly loop to a quarterly half-hour — the setup layer doesn't care about your size, but monitoring frequency can follow risk. A high-volume operation should go the other way: the monthly items become weekly, placement spot-checks become systematic seed testing, and someone's name goes next to each recurring item, because a checklist without an owner is a document, not a practice.

What's deliberately not on this list

Spam-trigger word audits (folklore — reputation and recipient reaction dominate word choice), inbox-placement guarantees (nobody controls the receivers' verdict), and filter-evasion tactics (training data for the filters, and against our editorial rules to publish). The checklist's theory of the case is simpler: prove identity, keep the record clean, send what people want, verify continuously.

Related guides

About this guide

Written by InboxRatio Editorial. Items earn their place on this checklist by being enforced provider requirements or widely documented causes of placement loss, and each links to the tool or guide that executes it. Provider thresholds cited come from the providers' published documentation. No vendor sponsorship influences this guide.

Methodology

InboxRatio measures deliverability by sending real campaigns through the platforms we review to a controlled seed list and recording where messages land. The monitoring items in Part 3 mirror the checks our own test operations run. The protocol is documented in how we test; source rules in sources.

Last updated

8 September 2026. Checklist items and provider requirements reviewed quarterly.

Frequently asked questions

What should an email deliverability checklist include? Three layers: one-time setup (SPF, DKIM, DMARC, reverse DNS, provider requirements, warm-up), per-campaign checks (header verification, segment sanity, working unsubscribe), and recurring monitoring (reputation, bounce and complaint trends, blocklists, list hygiene).

How do I check my email deliverability setup? Run your domain through the email authentication checker for the DNS layer in one pass, or the email deliverability score for the same audit as a scored report with prioritized fixes.

How often should I check deliverability? Setup: on every change plus quarterly. Campaign hygiene: every send. Monitoring (Postmaster Tools, bounces, blocklists, hygiene): monthly. The frequencies matter less than their being scheduled — decay is quiet by nature.

What's the most important item on the checklist? If forced to one: the seed-send with header verification before each campaign. It catches broken authentication, the wrong sending domain and platform misconfigurations — the highest- frequency causes of sudden placement loss — for two minutes of effort.

Do I need all of this for a small newsletter? The setup layer, yes — authentication requirements apply at every scale, and Part 1 is mostly one-time. The monitoring loop can thin out at low volume, but the per-campaign seed-send and an occasional hygiene pass remain worth their minutes.

Does completing the checklist guarantee inbox placement? No — placement is the receivers' verdict on your identity, history and content, and no checklist controls it. What the checklist does is eliminate every self-inflicted cause and give you the monitoring to catch the rest early.

Start at the top: the setup pass takes one afternoon, and the first item — your domain through the email authentication checker — takes under a minute.