Email deliverability
Email that lands, not mail that disappears.
We built our own tools for this. A check that reads a domain in about fifteen seconds and tells you what the internet already knows about your mail, and a message audit where you send one real email and we show you exactly what the receiving server saw. Both are ours, built here, not a reseller's dashboard with our name on it. Invoices, password resets, proposals, and the one message that had to get through.
SPF, DKIM and DMARC are the three records that decide whether your email is trusted. Most firms have never heard of them.
The ladder
Start where it hurts.
Each rung stands on its own, priced before anything starts, and none of them needs you to change who runs your IT.
The check
A reading of your domain's mail records and your website, with the record behind every finding, and a full report yours to keep.
Email Deliverability Investigation
When a real message is already going missing, the answer is not a record, it is a case. Real-send testing with a control sender against the affected one, the message audit run on real mail, the true sending IP and the route it took, the headers the receiving server actually saw, and a written case that stands on its own, independent of whoever runs your IT today. It is the baseline everything after it is measured against.
The first month of monitoring is included when you start within 60 days of the audit.
DMARC, SPF and DKIM setup
First domain. $79 each additional domain. Three records, published properly: one that lists every system allowed to send as you, one that signs each message so it cannot be altered on the way, and one that tells other mail servers what to do with anything that fails. Every system you actually send from is found first, and it is watched for three months until the policy can be tightened safely. Three months of Watch are included.
Business email on your own domain
For a firm still sending from gmail.com, yahoo.com or comcast.net. We set up Google Workspace or Microsoft 365 on your own domain, move the mail across, publish the records so it is trusted from the first message, and turn on multi-factor authentication. Your address becomes your business rather than your internet provider's.
Watch
A weekly DMARC digest in plain English, blocklist alerts, new-sender alerts, a monthly rescore, and five message audits a month, the same audit used in the investigation. The three months included with the setup are this plan.
Watch plus Fix
Everything in Watch, unlimited fair-use message audits, up to two DNS record changes a month done for you, and a quarterly written re-check.
Monitor and Manage
For a firm with several domains, an incumbent IT provider to coordinate with, or a decision maker who wants the monthly reading written for them rather than a dashboard to log into. Monitor is the human monthly review; Manage adds the changes made inside your tenant.
What the setup does
Three records, every sender, and three months of proof.
A DMARC record on its own blocks nothing. The work is finding everything that sends as you, getting each one signed and listed, and then watching the reports long enough to know the real senders pass before the policy tightens. That is why three months of Watch come with the setup.
The monitoring is the part most people have never seen. It shows every system sending as your domain, which is usually two or three more than anyone expects: the invoicing tool, the website form, a sequencer somebody signed up for last spring.
- SPF published, and kept under the ten-lookup limit that quietly breaks it.
- DKIM switched on at Microsoft 365 or Google Workspace and at up to three third-party senders in use.
- DMARC published at monitor first, with reporting on, so nothing legitimate is refused by surprise.
- A written plan to move to quarantine, a 30-day report review, and the move to quarantine or reject when the reports say it is safe.
- Three months of Watch included, so the reports keep coming after the records are in.
- Your records, applied from a guided page or by us with DNS access, whichever you prefer. Two business days from the intake.
What we look at
The path a message takes, not only the records you publish.
Authentication as received
SPF, DKIM and DMARC, including whether they align with the From domain. Published DNS can pass while the message that arrives does not.
The sending IP
About forty blocklists, plus whether the sending server's name and address match. The domain can be clean and the IP can still be the reason.
Content and headers
Wording, links, and List-Unsubscribe. Filters score the body, not only the envelope.
Every route that sends as you
Microsoft 365, Google Workspace, a sales sequencer, a website form, a billing system. One passing route does not vouch for the others.
Who this is for
Firms that live in email.
Recruiting, staffing, agencies, brokers
A day of outbound mail is the business. A record that fails or a sender nobody listed is a quiet leak in every reply rate you watch.
Firms sending from more than one system
Invoicing from one place, website forms from another, a sequencer from a third. Each one has to be allowed to send as you, and the one nobody remembers is the one that breaks the policy.
Firms with an IT provider already
An independent reading, then the work, then a watch. Not a request to replace anyone; the findings go to whoever runs mail today, and we will coordinate with them.
Questions
Before you ask.
Do you need access to our Microsoft or Google tenant?
Not to start. The check reads public records. The setup can be done from a guided page where you paste the records yourself, or with DNS access if you would rather we did it. Test messages for an investigation go to addresses we supply.
Is this just an SPF check?
No. Checking published DNS is useful and it is a different job. The setup gets every sender signed and listed and then watches the reports for a month; the investigation reads how real messages travel and what the receiving server saw. A record that passes is where the work starts, not where it ends.
Do we need the setup or the investigation?
If the check shows records missing or DMARC sitting at monitor-only, the setup is the answer and it is priced above, with three months of Watch included. If your records already pass and mail is still going to spam, that is a case, and the investigation is how it gets solved. If you are not sure, the free check tells you which one you are looking at.
We already have an IT company.
That is fine and common. The reading is independent, the findings are written so they can be handed to whoever runs mail today, and we coordinate with them rather than around them. Nothing here asks you to change providers.
Can we just forward you the bounce?
Forwarding rewrites the parts that matter, so a forwarded message tells us about the forwarder, not the sender. For an investigation we ask for a fresh copy of the same message sent to an address we supply. It takes a minute and it is the difference between a guess and a reading.
Do we have to change who does our IT?
No. Every rung here stands on its own and none of them needs you to move your IT to us. We publish the records, hand you the written case, or watch the domain, and your provider carries on doing what they do. Firms often bring us in precisely because an independent reading is worth more than one written by the people who built the thing.
What happens after the three months?
Watch carries on at its monthly price if you want to keep the digests and the alerts, or it stops. Either way you get a note on whether the policy is ready to tighten. It is yours to cancel whenever you like.
Get in touch
Tell us what the mail is doing.
Say what is happening and where it is happening, or run the free check first and send us the report. A person replies from hello@matanoit.com with the next step and, where there is one, the fixed price.