Observed signal
The specific public signal we found — quoted or described precisely, so you can verify it yourself.
Methodology & sample report
A sender readiness audit is only as useful as its discipline. Every finding follows the same six-field structure, so the report stays honest about what the evidence shows and what it doesn't. Below: the method, then fictional examples of the findings, the risk register, and the remediation order you'd receive.
All domains, records and findings on this page are fictional or redacted and exist only to demonstrate format and judgement. They are not real client data, and they are not advice for your domain.
Sender Audit & Action Plan · redacted
The anatomy of a finding
Consistency is what makes a report trustworthy. Whether a finding is trivial or serious, it carries the same six fields — so nothing important is asserted without its evidence, and nothing is overstated.
The specific public signal we found — quoted or described precisely, so you can verify it yourself.
What this signal means for sender readiness, in plain language a non-specialist can follow.
The explicit limit — what this evidence cannot tell us, including anything about inbox placement.
A severity rating, judged against the whole picture rather than a single record in isolation.
What we'd need to confirm the finding, and how confident we are without it.
The most careful next move — never "change everything," always a sequenced, reversible step.
Sample finding · 01
PUBLISHED RECORD — REDACTED DOMAIN
Sample finding · 02
VISIBLE RECORDS — REDACTED
Sample finding · 03
Every audit consolidates its findings into a single register: one row per finding, one view of the whole. A fictional sample, three rows. Each row stands on its own; together they form one view of risk.
| ID | Finding | Public evidence | Severity | Confidence | Recommended action |
|---|---|---|---|---|---|
| F-04 | DMARC posture set to p=none | DMARC record published with p=none; no enforcement signal sent to receivers | Medium–High | High | Move to p=quarantine in stages after 14 days of rua aggregate reporting confirms alignment |
| F-07 | SPF alignment fails for marketing subdomain | Mail headers show return-path on a third-party subdomain not aligned with header-from | Medium | Medium | Switch ESP to custom return-path under the sending subdomain; re-test alignment before any DMARC tightening |
| F-11 | Orphaned MX record on legacy subdomain | MX record present on a subdomain no longer used for sending; resolves to retired infrastructure | Low | High | Remove the record after confirming no inbound mail relies on it; document the rollback note before edit |
SEVERITY × CONFIDENCE — EVERY ROW CARRIES BOTH. A LOW-SEVERITY, HIGH-CONFIDENCE FINDING IS STILL RECORDED, BECAUSE A CLEAN SIGNAL IS EVIDENCE TOO.
Sample finding · 04
The difference between clarity and chaos is sequence. The audit lists changes in a safe order, each with a rollback note. Fictional sample below.
Sequenced & reversible
Before editing anything, gather sample headers per sending path and confirm which authentication mechanism aligns where. Rollback: none required — this step changes nothing.
Reduce nested includes to stay clear of the lookup limit, keeping the existing qualifier. Rollback: restore the previous TXT value, retained verbatim before the change.
Publish a new 2048-bit selector, verify signing on each tool, then retire the old selector once confirmed. Rollback: revert signing to the prior selector, which stays published until cutover is verified.
Only after the above are verified, review aggregate reports and move policy from p=none toward p=quarantine in measured steps. Rollback: return policy to the previous value; the change is a single TXT edit.
The Sender Audit & Action Plan ends with written recommendations. Infrastructure Setup & Repair adds a separately approved implementation scope, time-bound access where required, a recorded change sequence, rollback notes, post-change verification, and a written handover.
From finding to approved change
Technical changes are handled as a controlled sequence, not a collection of isolated fixes. The client remains the owner and approver throughout.
Capture relevant DNS values, authentication paths, provider settings, and available message evidence before a material edit is proposed.
Confirm what changes, who approves it, what access is required, what sits outside scope, and how the prior state can be restored.
Check the new state against the agreed target, document the result, remove temporary access, and leave the owner a maintainable record.
Reference standards
The Presida's audit methodology is grounded in the same authentication and sender-readiness standards that mailbox providers publish and enforce. These are the primary references.
Why a written audit beats a score
Dashboards and scanners are useful inputs. But a number on a screen doesn't tell a CTO what to change, in what order, or what the change won't fix. That judgement is the deliverable.