SenderCompass guide

A practical business email review checklist

Use this structured review to understand ownership, authentication, sending services and monitoring before making enforcement changes.

Use this as a discussion aid: It is not a substitute for provider-specific instructions or professional incident response. Record evidence and obtain approval before changing production DNS.

1. Confirm ownership and access

  • Record the domain registrar and DNS provider.
  • Confirm that more than one authorised person can recover access.
  • Enable strong multi-factor authentication where available.
  • Document who approves DNS and email-platform changes.
  • Record renewal dates and billing ownership.

2. Inventory every legitimate sender

  • Main employee email platform
  • Website contact and enquiry forms
  • Accounting and invoicing systems
  • Customer support software
  • Marketing and newsletter platforms
  • Booking, e-commerce and notification services
  • Monitoring devices or legacy applications

For each service, record the owner, sending domain, envelope domain, DKIM signing domain and whether the service is still required.

3. Review authentication

  • Confirm there is one effective SPF policy for each relevant hostname.
  • Check that current senders are authorised and old services are removed.
  • Verify DKIM is enabled both in DNS and in each sending platform.
  • Check whether SPF or DKIM aligns with the visible From domain.
  • Confirm DMARC reports reach a controlled and monitored destination.
  • Record the current DMARC policy and rollout plan.

4. Review sending practice

  • Confirm recipients understand why they receive messages.
  • Process bounces, complaints and unsubscribes promptly.
  • Protect forms and accounts from automated abuse.
  • Investigate sudden changes in volume or destination.
  • Keep transactional messages distinguishable from bulk marketing.
  • Review current guidance from major mailbox providers.

5. Prepare a response plan

  • Name the person who receives authentication and reputation alerts.
  • Keep provider support and escalation details available.
  • Record how to pause a compromised sending source.
  • Preserve logs, headers and timestamps during an incident.
  • Maintain a rollback plan for DNS changes.
  • Schedule a periodic review of senders and records.

Make the checklist repeatable

A dated quarterly or biannual review is more useful than a one-off clean-up. Ownership, platforms and provider requirements change.

Continue your email review

Use the practical checklist to map ownership, senders, authentication and monitoring before making changes.