“Our open rates dropped and nobody knows when.” That sentence describes an erosion, not an incident — which is why nobody caught it. Deliverability degrades gradually through list imports, half-finished authentication and sending to people who stopped caring two years ago.
What this package fixes
- SPF, DKIM and DMARC configured and verified — the entry ticket, not the whole game.
- A dedicated sending subdomain, so a bad campaign cannot damage the domain your sales team emails from.
- Engagement-based sending: the highest-return change most senders never make.
- Hard bounces and spam traps dealt with permanently, not swept up after each send.
- Monitoring, so the next problem is visible in days rather than quarters.
Authentication is 30 minutes. Reputation is the job.
The DNS side genuinely is quick for someone with access: publish the SPF include, publish the DKIM records, publish DMARC at p=none with a reporting address, verify each one.
What takes the rest of the two weeks is everything above it. Mailbox providers judge you on complaint rate, bounce rate, engagement signals and spam-trap hits — and no amount of correct DNS compensates for mailing people who do not want to hear from you.
Never start DMARC at reject
Almost every organisation has forgotten senders: an invoicing system, an HR tool, a regional office’s mail server. A p=none monitoring period exists to find them. Skipping it means discovering them when a director asks why a supplier never received the contract. This package stages it properly.
The change most senders resist
Engagement-based sending means mailing your active audience at full frequency, reducing frequency for the cooling, running a proper win-back for the dormant, and then suppressing the inactive.
The objection is always the same: we are throwing away reach. In practice, mailing dormant contacts depresses your aggregate engagement rate, which lowers your standing with providers, which reduces inbox placement for the people who do want your mail. Sending less to the wrong people is how you reach more of the right ones.
What you get
| Deliverable | Detail |
|---|---|
| Authentication | SPF (watching the ten-lookup limit), DKIM at 2048-bit, DMARC staged none → quarantine with a rollout plan to reject |
| Sending domain | Dedicated subdomain configured, with a consistent sender identity |
| List audit | Hard bounces suppressed permanently, role addresses and known trap patterns removed |
| Engagement tiers | Active / cooling / dormant / inactive, with a sending rule per tier |
| Win-back sequence | Run once, properly, before anything is suppressed |
| Monitoring | DMARC report parsing, provider postmaster tools, blocklist checks, seed-list placement testing |
| Written policy | The sunset rule and the frequency cap, so this does not erode again |
Check your automations for hidden open dependencies
Privacy protections that pre-fetch images have made open rate unreliable. Sunset policies, win-back triggers and engagement scores frequently have an open-based condition buried in them from years ago — they quietly stopped working as intended. Auditing and re-deriving those is included.
Best for
- Teams whose open rates dropped and nobody can say when
- Anyone who has never verified their authentication actually passes
- Orgs sending from their root corporate domain
- Teams who have just imported a large list and want to not regret it
Price and duration
From €2,900. One to two weeks. Fixed scope, fixed price.
Recovery from a damaged reputation takes weeks of consistently good sending, not days. There is no way to accelerate it — which is the argument for doing this before you need it.
Sound like your org?
Thirty minutes, free, no slides. Bring your questions about scope, timing or whether this package is even the right one — you will get straight answers.