Catch a broken SPF, DKIM or DMARC record before your mail does
Re-check your sending domain’s SPF, DKIM, DMARC and MX records on a schedule, and alert on a drop in the result rather than a fixed threshold, because a change is something you can trace and fix. In Email Digit, a monitored domain that loses 10 or more points between two checks fires a domain.drift webhook and notifies your workspace’s admins.
How DNS breaks without anyone noticing
Authentication records are set up once, checked once, and then left in a DNS zone that other people edit. The breakages are ordinary:
- Someone adds a new tool and pastes its SPF record as a second record instead of merging it into the first. Two SPF records is an error, and receivers can treat both as invalid.
- A DNS provider migration copies most records but not the DKIM key.
- The
_dmarcrecord is deleted as “something nobody uses”. - A policy is moved back from quarantine to none while debugging, and never moved forward again.
None of these raises an error anywhere you would look. Mail keeps sending. The first sign is usually a gradual slide into spam folders, days later, which is hard to connect back to an edit nobody remembers making.
Why alert on a drop, not a threshold
A threshold alert (“tell me when the score is under 80”) fires forever on a domain that has always been 75, and teaches everyone to ignore it. A drop alert asks a different question: did something change since the last check? A domain that scored 95 yesterday and 80 today has had an edit, and an edit has a time, an author and an undo.
What the score measures
Email Digit’s domain check is the same one behind the free domain checker. It starts at 100 and takes points off for what it finds:
| Finding | Points off |
|---|---|
| No SPF record | 25 |
| No DKIM record found at the common selectors | 25 |
| No DMARC record | 25 |
| No MX record | 10 |
DMARC policy is p=none | 10 |
Each SPF problem (more than one SPF record, a weak or missing all, too many includes) | 5 |
DMARC has no rua address for reports | 5 |
| Each listing on one of five blocklists | 5 |
So a 10-point drop catches a removed SPF, DKIM, DMARC or MX record, a DMARC policy moved back to p=none, two new SPF problems at once, or listings on two blocklists. It does not catch a single 5-point change on its own, including the second SPF record from the list above. Run a manual check after any DNS edit to see those.
Setting up a monitor in Email Digit
- Add the domain as a monitor and choose how often to re-check it, from every hour to once a week. The default is once a day.
- Each check runs once its interval has passed, so treat the interval as the minimum gap between checks rather than an exact time. “Check now” runs one immediately.
- Each new score is compared with the previous one. A drop of 10 points or more fires
domain.driftto any webhook subscribed to it, adds a notice to the dashboard, and emails your workspace admins, with a limit so a record that flips back and forth does not send the same email every time.
The webhook’s data looks like this:
{
"type": "domain.drift",
"data": {
"domain": "example.com",
"previous_score": 95,
"new_score": 70,
"drop": 25,
"check_id": "00000000-0000-0000-0000-000000000000"
}
}Point it at a channel someone reads, such as your on-call alerts or a team chat, rather than a log. The check id lets you open the full result and see which record changed.
Scheduled checks and drift alerts apply to domains verified in your workspace, and to their subdomains. You can add a monitor for any other domain, but it stays an on-demand check: no schedule, no webhook and no alert. That keeps the feature from becoming a way to watch someone else’s DNS.
When the alert fires
- Open the check. Compare it with the previous result to see which record changed: SPF, DKIM, DMARC, MX or a blocklist.
- Look at the DNS change history. Most DNS providers keep an audit log. The edit that caused the drop will be shortly before the check that caught it.
- Restore, then talk. Put the record back first, then find out what the person who changed it was trying to do. Usually they were adding a tool, and its record needs merging, not replacing.
- Check again. “Check now” confirms the fix instead of waiting for the next scheduled check.
Limits of the check
- DKIM is looked up at common selector names. A key published under an unusual selector reads as missing. That costs the same 25 points on every check, so it will not cause a false drift alert, but it will not catch that key disappearing either.
- Blocklists are five lists, checked against the IP of the domain’s first mail server. That is the server that receives your mail, which may not be the one that sends it.
- The score is about records, not placement. A perfect score does not mean mail reaches the inbox; a falling score means something you control has changed.
If you consume the event in code, see which email webhook events to subscribe to for the rest of the setup and health events.