The short answer
| Run | Score | Verdict | Rules tested | DMARC |
|---|---|---|---|---|
| Before, 2026-10-08 | 80 | almost | 10 | fail: no record at _dmarc.openkrill.app |
| Latest run | 96 | ready | 12 | pass |
The record we added is one line: v=DMARC1; p=none; rua=mailto:support@openkrill.app. Anyone can read it with dig +short TXT _dmarc.openkrill.app.
The check now tests 2 more rules than before. The rules about the DMARC policy and its report address only apply once a record exists.
Why DMARC moved the score so much
Google asks every sender for SPF or DKIM, and adds DMARC for anyone who sends more than 5,000 messages a day to Gmail. Yahoo asks bulk senders for a DMARC policy of at least p=none.
Domain Mail Check marks rules like these as standard, because a mailbox provider or an RFC states them. Standard rules carry the most weight. Cold email is bulk sending by design, so a missing DMARC record is the first thing to fix.
What the check still flags
- DMARC policy.
p=noneasks for reports but does not stop spoofed mail. The tool's advice: read the reports for 2 to 4 weeks, then move top=quarantine. - DKIM: unknown. The check tried 10 common selector names and found no key. Your sending service may use its own selector name, which you can pass to the tool.
- SPF. Our record uses 1 of the 10 DNS lookups SPF allows, so it has room for another sending service.
- Blocklists. The domain is clear on the 1 public domain blocklist the check reads. Gmail and Outlook do not publish which lists they use.
The policy rule is an opinion in the tool's terms, so it never blocks the verdict. The answers on mail setup checks explain how standards and opinions differ.
What a DNS check cannot tell you
A domain score reads public DNS and the public registry record. It cannot see your sending IP's reputation, your bounce rate or the quality of your list.
So a ready verdict means the setup providers ask for is in place, not that mail will land in the inbox. The two posts we credit below say the same from the sender side: domain age and warm-up matter, naming details matter less.
Picking a domain for cold email
The check also scores the name itself, as opinions. It asks whether the name reads like a chosen word, avoids words such as login or verify, and avoids endings where Spamhaus finds many bad domains.
Register a sending domain early, since domain age is one of the rules. Then run the Domain Mail Check install guide for Claude steps and check again before the first send.
Try it: run the same check yourself with Domain Mail Check, with no key, or read every post on the Agent Tools blog.
Sources
- @NickAbraham12 on X: argues that branded domains and sender names matter less than people think, and that most split tests are noise.
- @atishayhyperke on X: shares a domain checklist from sending millions of emails a month: plain names, common endings, domains older than 90 days, warm-up on.
- Google, Email sender guidelines: SPF or DKIM for every sender, and DMARC on top for anyone who sends more than 5,000 messages a day to Gmail.
- Yahoo, Sender best practices: bulk senders must publish a valid DMARC policy of at least p=none, and DMARC must pass.
- RFC 7489, DMARC: the DMARC record format, the p= policy and the rua= report address.
- RFC 7208, SPF: the SPF record and its limit of 10 terms that cause DNS lookups.
- RFC 6376, DKIM: DKIM signatures and the selector name that tells a receiver where the public key is.
- Our own runs: Domain Mail Check and the other tools named above, on 2026-10-08. A timer runs the same calls again every 7 to 30 days.
Change log
We measure the numbers in this post again every 7 to 30 days and check that every source still loads. A new line appears here only when something in the post really changed.
- 2026-10-08. Published. Why: First version, with the numbers we measured with our own tools on 2026-10-08.