Use this as a discussion aid: It is not a substitute for provider-specific instructions or professional incident response. Record evidence and obtain approval before changing production DNS.
1. Confirm ownership and access
- Record the domain registrar and DNS provider.
- Confirm that more than one authorised person can recover access.
- Enable strong multi-factor authentication where available.
- Document who approves DNS and email-platform changes.
- Record renewal dates and billing ownership.
2. Inventory every legitimate sender
- Main employee email platform
- Website contact and enquiry forms
- Accounting and invoicing systems
- Customer support software
- Marketing and newsletter platforms
- Booking, e-commerce and notification services
- Monitoring devices or legacy applications
For each service, record the owner, sending domain, envelope domain, DKIM signing domain and whether the service is still required.
3. Review authentication
- Confirm there is one effective SPF policy for each relevant hostname.
- Check that current senders are authorised and old services are removed.
- Verify DKIM is enabled both in DNS and in each sending platform.
- Check whether SPF or DKIM aligns with the visible From domain.
- Confirm DMARC reports reach a controlled and monitored destination.
- Record the current DMARC policy and rollout plan.
4. Review sending practice
- Confirm recipients understand why they receive messages.
- Process bounces, complaints and unsubscribes promptly.
- Protect forms and accounts from automated abuse.
- Investigate sudden changes in volume or destination.
- Keep transactional messages distinguishable from bulk marketing.
- Review current guidance from major mailbox providers.
5. Prepare a response plan
- Name the person who receives authentication and reputation alerts.
- Keep provider support and escalation details available.
- Record how to pause a compromised sending source.
- Preserve logs, headers and timestamps during an incident.
- Maintain a rollback plan for DNS changes.
- Schedule a periodic review of senders and records.
Make the checklist repeatable
A dated quarterly or biannual review is more useful than a one-off clean-up. Ownership, platforms and provider requirements change.