An email deliverability audit is a diagnostic of why your messages are reaching spam folders, being throttled, or not arriving at all. It is one of the few marketing engagements with a genuinely technical core, which is why the quality range among vendors is so wide: the work involves domain authentication records, sending infrastructure, reputation signals at the receiving side and the behaviour of your own list, and only some of that is visible from inside an email platform's dashboard. This page describes what a competent audit actually inspects, the problems it most often finds, what it should cost relative to the alternatives, and how to tell a real technical review from a report generated by a tool.
The authentication layer, and why it comes first
Almost every serious deliverability problem starts here. SPF, published as a DNS record, tells receiving servers which hosts may send on behalf of your domain, and the specification is public in RFC 7208, including the lookup limits that quietly break records as a company adds tools over the years. DKIM signs messages cryptographically so a receiver can verify they were not altered in transit. DMARC, specified in RFC 7489, ties the two together by telling receivers what to do when a message fails and by requesting reports so you can see who is sending in your name. Major mailbox providers now expect all three from bulk senders, and a missing or misconfigured record is the most common single cause of a campaign vanishing. A good audit starts by reading your actual DNS, not by asking what you think is configured, because the answers frequently differ.
Reputation, infrastructure and the sending domain question
After authentication comes reputation, which attaches to your sending domain and your sending addresses and is built from how recipients react to your mail. Complaint rates, spam folder placement, engagement over time and the presence of spam traps in your list all feed it, and it recovers slowly once damaged. An audit should examine whether marketing, transactional and cold outreach are separated onto different subdomains, because mixing them means a poor performing campaign can damage delivery of the receipts and password resets your business depends on. It should look at whether a shared or dedicated sending pool is appropriate for your volume, at how new domains or addresses are warmed, and at whether your unsubscribe mechanism is honoured promptly. The CAN-SPAM Act sets the legal floor on that last point, requiring an honest header, a clear opt out and prompt processing of opt out requests, and the FTC publishes a plain compliance guide for it.
The list problems no technical fix will solve
The most expensive finding in most audits is not a record, it is the list. Purchased or scraped addresses, an old list mailed after a long silence, sign up forms with no confirmation step, and the absence of any suppression for long term non openers will all sink deliverability regardless of how clean the authentication is. Receivers weight engagement heavily, so mailing people who never open teaches the receiver that your mail is unwanted, and that judgement then applies to the people who do want it. A serious audit will therefore recommend segmenting by engagement, suppressing dormant recipients, and in the worst cases abandoning a portion of the list entirely. That is an unwelcome recommendation and a reliable sign the vendor is being honest, since the easy report is one that lists DNS changes and never mentions the list.
How to buy an audit without overpaying
Ask what the deliverability audit produces as an artefact: a written report with prioritised findings, the specific DNS records to publish, a list hygiene plan and a re engagement sequence, or just a dashboard export. Ask whether implementation is included or quoted separately, because publishing DNS changes usually requires access you may not want to grant and coordination with whoever runs your domain. Ask for the audit to be repeated after remediation, since the value is in the confirmed fix rather than the diagnosis. Where the underlying problem turns out to be programme design rather than plumbing, a full engagement with one of the email marketing agencies you are already considering may be the cheaper path, and a good auditor will tell you so rather than selling you a monitoring retainer for a problem that was solved in a fortnight.
Questions people ask about email deliverability audit
How often should we audit deliverability?
Annually as a baseline, and immediately after any change to sending infrastructure, a domain migration, the addition of a new sending tool, or a visible drop in open rates. Continuous monitoring of DMARC reports covers most of the gap between formal audits.
Can our email platform tell us the same thing?
It sees what it sends and how recipients engage, which is valuable but partial. It cannot see mail sent through other tools on your domain, it cannot read your DNS the way a receiver does, and its deliverability figures usually exclude the messages that never arrived.
Will fixing authentication get us out of the spam folder?
It removes a common cause and is a prerequisite, but placement is driven mostly by reputation and engagement. If you have been mailing an unengaged list for months, correct records alone will not restore inbox placement without list and cadence changes.
Is a dedicated sending domain always better?
Not always. A dedicated setup gives you control over your own reputation but requires enough consistent volume to sustain it, and a low volume sender is often better served by a well managed shared pool. Ask an auditor to justify the recommendation with your actual send volumes.