| Domain and sender coverage |
How many organizational domains, active sender domains, parked domains, subdomains, delegated zones, and monthly messages must be monitored? |
Domain inventory, mail-flow diagrams, sender register, M&A pipeline, volume baseline, and treatment of inactive domains. |
Licensing or technical limits make full domain coverage impractical. |
| Source identification |
Can the platform consistently translate IPs and authentication data into recognizable services while preserving the raw evidence? |
Side-by-side results for known SaaS, on-premises relays, dedicated IPs, shared platforms, forwarders, and unknown sources. |
Opaque classifications cannot be traced back to report fields or corrected. |
| Alignment and remediation |
Does it distinguish SPF or DKIM authentication from relaxed or strict DMARC alignment and explain the corrective action? |
Test cases for aligned DKIM, aligned SPF, indirect mail, subdomains, custom Return-Path, selector failure, and SPF permerror. |
Dashboard labels passing SPF/DKIM as DMARC-compliant when neither identifier aligns. |
| Policy and DNS control |
Will the organization monitor records only, delegate record management, or use hosted SPF, DKIM, DMARC, MTA-STS, TLS-RPT, or BIMI features? |
DNS architecture, delegation model, change approvals, DNSSEC compatibility, validation behavior, rollback, and outage design. |
Vendor-managed records create an undocumented dependency or cannot be restored promptly. |
| Identity and administration |
Are SSO, MFA, role-based access, tenant separation, service accounts, API tokens, audit logs, and lifecycle automation available in the required plan? |
Role matrix, SAML/OIDC design, audit export, token scopes, session controls, provisioning/deprovisioning test, and support-access controls. |
Shared administrator accounts, no MFA, excessive API scope, or inadequate tenant isolation. |
| Data protection |
Where are reports processed and retained; which subprocessors, regions, encryption, deletion, backup, incident, and legal terms apply? |
DPA, subprocessor list, architecture, certifications, retention controls, deletion evidence, breach terms, and RUF privacy design. |
Required residency, contractual, privacy, or deletion obligations cannot be met. |
| Operations and integration |
Can alerts, reports, tickets, API data, and change events reach the SIEM, PSA, ITSM, email, chat, and executive reporting systems? |
Live API and webhook test, retry behavior, rate limits, native integration scope, log samples, and failure notifications. |
Critical events are available only through manual dashboard review. |
| Support and exit |
What expertise, onboarding, response targets, escalation, export, transition assistance, and post-termination deletion are included? |
Support plan, SLA, sample export, ownership of DNS records, offboarding runbook, renewal terms, and migration test. |
Data or DNS control cannot be exported or recovered without the provider. |