Email Fix Pack: yourcompany.com
Generated 2026-10-01 from your live DNS · order SAMPLE
Current score: 42/100. Email provider: Google Workspace. DNS host: GoDaddy.
Step 0: Open your DNS settings
GoDaddy → My Products → your domain → DNS → Add New Record.
Before changing anything, screenshot your current records. That is your rollback.
Step 1: SPF (who may send as you)
Replace your current SPF record (v=spf1 include:sendgrid.net ?all) with:
- Type TXT · Host @ · Value:
v=spf1 include:sendgrid.net include:_spf.google.com ~all
Step 2: DKIM (a tamper-proof signature on every email)
Google Admin console → Apps → Google Workspace → Gmail → Authenticate email → choose your domain → Generate new record (2048-bit, prefix google) → publish the TXT record it shows → back in Admin, click Start authentication.
Step 3: DMARC (tells Gmail and Outlook what to do with fakes)
- Today: add a TXT record with host
_dmarcand value:v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com; adkim=r; aspf=r
This is monitor mode. It never blocks mail, and you start receiving daily reports.
- In 2–4 weeks, once reports show your real mail passing, change the record to:
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@yourcompany.com; adkim=r; aspf=r - 2–4 weeks after that, change it to full protection:
v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourcompany.com; adkim=r; aspf=r - Reports go to
dmarc-reports@yourcompany.com. Create that mailbox or alias first, or replace it with an address you already read.
Step 4: Verify (10 minutes after saving)
- Re-run the free check. The HIGH issues should be gone.
- Send an email from your domain to any Gmail address, open it → ⋮ → Show original. SPF, DKIM and DMARC should each say PASS.
- If anything fails, reply to your receipt email with a screenshot and we'll tell you exactly what to change.
Step 5: Other tools that send as you
Your SPF already includes: SendGrid. In each tool, open its domain authentication page and publish the DKIM records it shows, so those emails pass DMARC too.
If newsletters, invoices, CRM or helpdesk emails go out from your domain, each tool has a domain authentication page. Complete it before moving DMARC past p=none.
Optional: CAA
Add a CAA record only for the certificate authority your website uses. Check the padlock in your browser to see the issuer, e.g. 0 issue "letsencrypt.org". If unsure, skip this: it's low risk either way.
Rollback
Restore the records you screenshotted in Step 0. DMARC p=none never blocks mail, so Steps 1–3 are safe to apply today.
Issues found
- HIGH: No DMARC record. Gmail, Yahoo and Microsoft require DMARC for bulk senders, and without it anyone can spoof your domain.
- MEDIUM: SPF is neutral (?all). It provides no protection.
- MEDIUM: No DKIM key found on common selectors. Your mail may be unsigned. Your provider may use a custom selector, which the pack shows how to confirm.
- LOW: No CAA record. Any certificate authority may issue SSL certificates for your domain.
_Based on public DNS at generation time. DKIM keys on custom selectors can't be seen from outside._