Hosting · All systems operational Melbourne time AEDT

Free check

What is your domain telling the world?

Put your domain in and we’ll read the records Google and Microsoft check on every message. It takes a few seconds.

Looked up with public DNS, straight from your browser. Nothing is stored.

  1. MX Who receives your mail
  2. SPF Who is allowed to send as you
  3. DKIM Proof each message is really yours
  4. DMARC What happens to mail that fails

Or skip it and tell us what’s happening.

Email problems we sort out.

They often look unrelated, but most trace back to how your domain proves its email is genuine: the authentication set up across your mail provider and every tool that sends as you. Most businesses have it half done, if at all, and Google, Yahoo, and Microsoft now check it on every message. If something else is behind it, like a blocklisted server or a tool sending badly, we’ll find that too.

  • Mail not arriving

    • Invoices and quotes landing in spam
    • Replies that never come
    • Bounce messages from Gmail or Outlook
  • Someone using your name

    • Customers getting phishing emails “from” you
    • Fake invoices sent from your domain
    • Bounce-backs for mail you never sent
  • Tools complaining

    • A newsletter tool saying your domain isn’t verified
    • DMARC report emails nobody can read
    • A new tool asking for DNS records
  • Something changed

    • A move to Google Workspace or Microsoft 365
    • A new booking, invoicing, or CRM tool
    • A new website or email provider

How we fix your email.

We work through it in a set order: find every service sending as you, set each one up properly, confirm it’s working with real reports, then lock the domain down so nobody else can use it.

  1. Find every service that sends as you

    Your mail provider is one. The newsletter tool, the website’s contact form, invoicing, the booking system, the CRM: each one sends email with your name on it, and each one needs to be allowed to. We list them all, check which are passing and which aren’t, and look for anything else getting in the way, like a blocklisted server or a forwarding rule gone wrong.

  2. Set up authentication properly

    Set up SPF and DKIM so every service can prove its mail is genuine, and fix the settings inside the services themselves, not just the DNS. Then publish a DMARC policy in report-only mode, so nothing changes yet but we start seeing what’s happening.

  3. Watch the reports

    For a few weeks, the big mail providers send back reports on every message claiming to be from your domain. That’s where the surprises are: the tool nobody mentioned, the forwarding rule, the old system still sending, and sometimes someone else using your name. We read them and fix what turns up.

  4. Lock it down

    Once every real sender passes, we tighten the DMARC policy step by step until the major mail providers refuse or junk anything faking your domain. Your own mail is already passing by then, so the stricter policy leaves it alone, and it carries proof it’s really yours.

What we can promise, and what we can’t.

We can promise that every service sending as your domain will be properly authenticated, and that mail faking your domain will be refused or junked by the major mail providers.

We can’t promise every email lands in every inbox. That also depends on what’s in the message, who it’s going to, and the receiving mail provider’s own rules, and none of that is ours to control. What we can do is take away the most common reason it goes wrong, and show you the evidence.

Every job is quoted at a fixed price, once we know how many services send email as your domain.

Email not behaving?

Fill in the blanks and send. Add anything else you know, like which tools send from your domain. We’ll scope it and come back with a fixed quote.

Send us a message

To Chris Anderson <chris@brightspire.com.au>

Our email is , and it’s hosted with .