Email deliverability is a DIY and Tech job: you have the AI check your domain records, clean your list, plan a warm-up and read your drafts for spam signals, and a small business can finish it in an afternoon. The first pass is a checklist, and after that a free tool keeps watching it for you. Most mail that lands in spam gets there for a plain reason: a missing record on the domain, old addresses that bounce, or people who do not remember signing up. The AI is good at reading records, bounce exports and drafts. The fixes in your domain settings, and the choice of who stays on your list, stay with you.
- Shape
- DIYTech
- Sitting
- an afternoon
The shape: DIY and Tech
This job is DIY because nobody else holds your list or your domain login. Only you know which addresses came from real signups, which came from a trade show sheet, and which came from somewhere you would rather not say. Only you can log in to your domain registrar and your email platform.
It is Tech because the core of it is three short text records on your domain, called SPF, DKIM and DMARC. They prove to Gmail, Yahoo and the rest that your mail really comes from you. They are strict: one extra character can break a record, and a broken record fails quietly. Google and Yahoo began requiring authentication from senders in February 2024, and Google's email sender guidelines spell out what it expects.
What that means for you: the work is front-loaded. The records take the most care, and once they pass they rarely change. List cleaning repeats after every send. Warm-up only matters when you start a new domain, a new sending service or a much bigger volume.
What you give the AI
Start a new chat and give it these, by name:
- Your domain records. Look up your domain in a free DNS lookup tool such as MXToolbox and copy the TXT records that start with v=spf1 and v=DMARC1, plus the DKIM record your email platform told you to add. If one is missing, say so.
- Every service that sends mail as your domain. Your mailbox provider (Google Workspace or Microsoft 365, for example), your newsletter platform, your booking or invoicing tool, your website's contact form, and anything else that sends from your address. A forgotten sender is the most common reason an SPF record fails.
- A message header from a recent send. Send one of your newsletters to a personal Gmail address, open it, choose "Show original", and copy the lines that say SPF, DKIM and DMARC with their pass or fail result.
- Your last three sends' numbers. Sent, delivered, opened, clicked, bounced (hard and soft separately), unsubscribed and marked as spam, as your platform reports them.
- A bounce and inactivity export. The list of addresses that hard bounced, and the list of people with no opens or clicks in the last six months, if your platform can export them. Strip names if you prefer; the AI only needs the pattern.
- Where your list came from. One honest line per source: website signup, customers at checkout, an event sign-in sheet, an old export from a previous tool.
- Your next email draft. The subject line, the preview text and the full body, including the link addresses.
- Your sending plan. How many people you plan to mail, how often, and whether the domain or platform is new.
What comes back
You get four things, in this order: a verdict on each record with a corrected version where one is needed, a list-cleaning rule set, a warm-up schedule if you need one, and a short note on the draft. Ask for them in one chat, but read them one at a time.
Paste this brief, then your inputs underneath it:
You are checking the email deliverability of a small business that sends its own newsletters and customer emails.
Work only from the inputs below.
Never guess a record, a sending service or a number that is not given.
Part 1: Authentication.
For SPF, DKIM and DMARC, say pass, fail or missing, and why, in one line each.
Check that the SPF record includes every sending service listed, that there is only one SPF record, and that it stays under ten DNS lookups.
If a record needs a change, write the corrected record in full and name the exact field it goes into.
If DMARC is missing, propose a starting record with p=none and a reporting address at the owner's own domain (ask for the address if it is not given), and explain when to move it to quarantine.
Compare the message header results with the records and flag any mismatch.
Part 2: List cleaning.
Using the bounce, inactivity and source inputs, write rules for who to remove now, who to send one re-permission email to, and who to keep.
Treat event sign-in sheets, old tool exports and any address the owner cannot explain as higher risk.
Write the one re-permission email: plain text, under 80 words, one clear yes link.
Part 3: Warm-up.
Only if the domain, the sending platform or the volume is new.
Write a schedule that starts with the most engaged people and grows step by step, with a rule for when to hold or step back.
Part 4: The draft.
Flag only real spam signals: all-caps or pushy subject lines, a body that is mostly one image, link text that hides a different address, link shorteners, a missing unsubscribe link, or a missing physical mailing address.
Do not flag ordinary words on their own.
Return the four parts as headed sections, then a five-line checklist of what the owner does next, in order.
An editorial example, with a plainly invented business: say you run a two-person dog grooming shop called Tidy Paws, with a monthly newsletter on a standard email platform and a booking tool that sends reminders. The AI looks at the pasted records and finds the SPF record lists the email platform but not the booking tool, so reminders fail SPF. It writes one corrected SPF record that includes both and tells you to delete the old one rather than add a second. There is no DMARC record, so it proposes a starting record with p=none and a reporting address at the shop's own domain. In the list, it flags the 2022 adoption-day sign-in sheet as the source of most hard bounces and drafts a three-sentence email asking those people whether they still want the newsletter. The draft's subject line is fine; it flags a "Book now" button that links through a shortener and suggests the plain booking address instead. Every detail of Tidy Paws is invented to show the shape of the answer, not a result.
How to judge it
You can reject a bad answer in a minute. Look for these:
- Invented records or services. An SPF include for a platform you never named, or a DKIM key the AI made up. DKIM keys come from your email platform, never from a chat. Throw the answer out and run the brief again.
- Two SPF records. If the fix adds a second record instead of replacing the first, it is wrong. A domain gets one SPF record, and two make both fail.
- A strict DMARC policy on day one. A record that starts at p=reject before you have read any reports can block your own mail from a sender you forgot. Start at p=none, read the reports for a few weeks, then tighten.
- A spam-word list. If Part 4 comes back as a list of words to avoid ("free", "save", "offer"), the AI has fallen back on old advice. Ask it again to flag only the signals in the brief.
- A cleaning rule that keeps everyone. If nothing gets removed from a list with known bounces, the rules are too soft.
- A warm-up that jumps. A schedule that goes from a few dozen to your full list in a day or two is not a warm-up.
- Certainty about things it cannot see. The AI cannot see your domain reputation, your platform's shared reputation or what happened in a reader's inbox. An answer that claims to know them is guessing.
A good answer is plain. It names each record's state, shows the exact text to paste, removes the addresses that hurt you, and leaves the subject line alone if the subject line is fine.
After you publish a changed record, look up the domain again and send a fresh test to Gmail. "Show original" should read pass for SPF, DKIM and DMARC. If it does not, paste the new header back into the same chat.
What stays with you
The AI reads and writes text. Four things stay with you.
The changes themselves. Someone has to log in to the registrar or the DNS host and paste each record into the right field. A record change can take a while to spread, so test it again later the same day before calling it done.
Who stays on the list. The AI can sort addresses by risk. Only you know that a quiet address belongs to your best customer, who reads every email in a mail app that hides opens. Removing people is a judgment call, and it is yours.
Consent. Every address on the list should belong to someone who agreed to hear from you. A bought or borrowed list hurts deliverability for everyone else on it, and in many places it breaks the rules for commercial email. No record fixes that. Signup forms that set the right expectation keep the list clean from the start; the forms job covers that.
The watching. This is the "tool that watches it" half of the job. Google offers free Postmaster Tools, which shows your domain's spam rate and authentication results once you verify the domain and send enough mail to Gmail addresses. Google's guidelines ask senders to keep the spam rate it reports below 0.1% and never let it reach 0.3%. Your DMARC reports and your email platform's bounce and complaint numbers do the rest. Put a monthly reminder on your calendar to open all three, and paste them back into a chat with the brief above when a number moves.
Which fix comes first
| What you see | Likely cause | Do this first |
|---|---|---|
| Mail to Gmail or Yahoo goes to spam from every send | Missing or failing SPF, DKIM or DMARC | Part 1 of the brief, then a fresh test |
| One kind of mail fails (reminders, invoices, form replies) | A sending service missing from SPF or not signing with DKIM | Add that service to the records |
| Bounces climb on one send | Old or imported addresses | Part 2, remove hard bounces now |
| Spam complaints rise | People who do not remember signing up | Re-permission email, then remove the silent |
| Everything broke after a platform or domain move | No warm-up | Part 3, step back to your most engaged readers |
Doing it in one afternoon
- Look up your domain and copy the three records, or note that one is missing.
- List every service that sends mail as your domain.
- Send yourself a test and copy the authentication lines from "Show original".
- Export your bounces, your inactive readers and your last three sends' numbers.
- Run the brief, then fix the records first and test again.
- Remove hard bounces and send the re-permission email to the risky group.
- Verify your domain in Postmaster Tools and set the monthly reminder.
That is the whole job. The records are done once, the cleaning repeats after each send, and the watching takes ten minutes a month. If your mail also goes out with a signature, the email signature job is a good one to finish the same day.
Of every job on this list, social media is the one that comes back every week, and Boomp is software that does that one for you. See ten posts made from your website, free
