← Email Fix Pack · Sample pack for a fictional domain (Google Workspace + GoDaddy + SendGrid). Yours is generated from your live DNS.

Email Fix Pack: yourcompany.com

Generated 2026-10-01 from your live DNS · order SAMPLE

Current score: 42/100. Email provider: Google Workspace. DNS host: GoDaddy.

Step 0: Open your DNS settings

GoDaddy → My Products → your domain → DNS → Add New Record.

Before changing anything, screenshot your current records. That is your rollback.

Step 1: SPF (who may send as you)

Replace your current SPF record (v=spf1 include:sendgrid.net ?all) with:

Step 2: DKIM (a tamper-proof signature on every email)

Google Admin console → Apps → Google Workspace → Gmail → Authenticate email → choose your domain → Generate new record (2048-bit, prefix google) → publish the TXT record it shows → back in Admin, click Start authentication.

Step 3: DMARC (tells Gmail and Outlook what to do with fakes)

This is monitor mode. It never blocks mail, and you start receiving daily reports.

Step 4: Verify (10 minutes after saving)

  1. Re-run the free check. The HIGH issues should be gone.
  2. Send an email from your domain to any Gmail address, open it → ⋮ → Show original. SPF, DKIM and DMARC should each say PASS.
  3. If anything fails, reply to your receipt email with a screenshot and we'll tell you exactly what to change.

Step 5: Other tools that send as you

Your SPF already includes: SendGrid. In each tool, open its domain authentication page and publish the DKIM records it shows, so those emails pass DMARC too.

If newsletters, invoices, CRM or helpdesk emails go out from your domain, each tool has a domain authentication page. Complete it before moving DMARC past p=none.

Optional: CAA

Add a CAA record only for the certificate authority your website uses. Check the padlock in your browser to see the issuer, e.g. 0 issue "letsencrypt.org". If unsure, skip this: it's low risk either way.

Rollback

Restore the records you screenshotted in Step 0. DMARC p=none never blocks mail, so Steps 1–3 are safe to apply today.

Issues found

_Based on public DNS at generation time. DKIM keys on custom selectors can't be seen from outside._

Check your own domain free →