Publishing SPF, DKIM, DMARC and MTA-STS once is the easy half. Infrabox queries them back on a schedule, watches every domain and IP against the public blocklists, and seed-tests placement while your campaigns are still running.
- 0.0%
- Average inbox placement across monitored domains
- 0h
- Re-verification interval for every auth record
- 0
- Blocklist entries tolerated before an alert fires
Four records have to agree before a receiver trusts you.
Authentication is not a checkbox, it is a handshake. SPF, DKIM, DMARC and MTA-STS all have to line up on the same visible from address before a receiving server is willing to spend inbox space on you.
SPF says which servers may speak for you
A TXT record at the root lists the authorized senders (v=spf1 include:_spf.infrabox.software ~all): one include, one lookup, well inside the ten-lookup limit.
DKIM proves nobody touched the message
The signature is verified against the public key at your selector subdomain, so if a hop rewrote the body in transit, the receiver finds out rather than guessing.
DMARC binds both to the address a human sees
Published at _dmarc, it tells receivers what to do (quarantine or reject) when the authenticated domain and the visible from domain fail to match.
MTA-STS stops a silent downgrade
A policy file plus a _mta-sts TXT record keep mail from falling back to an unencrypted connection when a receiving server offers one.
What is checked, and how often.
The actual schedule sitting behind the word continuous.
SPF & DKIM alignment
- Frequency
- Every send
- Trigger
- Alert on repeated failure
DMARC aggregate reports
- Frequency
- Daily
- Trigger
- Policy recommendation if alignment holds
Blocklist status
- Frequency
- Every 15 min
- Trigger
- Immediate alert on listing
Inbox placement seed test
- Frequency
- Every 6 hours
- Trigger
- Alert if primary placement drops below 90%
MTA-STS policy validity
- Frequency
- Every 6 hours
- Trigger
- Alert on expired or unreachable policy
| Check | Frequency | Trigger |
|---|---|---|
| SPF & DKIM alignment | Every send | Alert on repeated failure |
| DMARC aggregate reports | Daily | Policy recommendation if alignment holds |
| Blocklist status | Every 15 min | Immediate alert on listing |
| Inbox placement seed test | Every 6 hours | Alert if primary placement drops below 90% |
| MTA-STS policy validity | Every 6 hours | Alert on expired or unreachable policy |
The questions that decide an evaluation
The blocklist check runs every 15 minutes. A listing pulls that sender out of rotation immediately, raises an alert, and shows the delisting path for that specific list. The rest of the fleet keeps sending, because reputation is not shared across a workspace boundary.
Domain reputation follows the domain and the records on it, and both are yours. IP reputation does not travel: a new sending IP anywhere means a new ramp, with us or with anyone else. Treat a vendor who says otherwise carefully.
A new domain starts at p=none so alignment can be observed without risking real mail. Once aggregate reports show alignment holding cleanly, Infrabox recommends p=quarantine and then p=reject, and the move is yours to approve.
Yes. Seed accounts on the major mailbox providers receive scheduled sends and report which folder they landed in. If primary placement drops under 90%, the alert fires the same day rather than at month end.
The policy is validated before enforcement tightens, and a transport failure raises an alert instead of dropping the message quietly. Nothing in this path is allowed to fail silently.
Set it up once is a myth. All of this re-checks.
A record that was correct in March is not evidence that it is correct today. Every one of these runs on a clock instead of on a memory.
The zone writes itself once
SPF, DKIM, DMARC, MTA-STS and BIMI publish the moment a domain attaches, so a missing record is never the reason a launch slips a week.
Reputation Radar
Every domain and IP is checked against the major public blocklists every 15 minutes. You hear about a listing from us, not from a client asking why the replies stopped.
Placement sampled while you are sending
Seed sends reach real accounts across the major providers on a schedule, so a folder change surfaces the day it happens rather than at the end of the quarter.
The record somebody edited last quarter
Every record is re-queried on a six-hour clock with a timestamp attached, which caps how long a change made outside Infrabox can stay invisible.
Four checks that never stop running.
None of these are onboarding steps. They run for as long as the domain does.
Step 1: The zone goes live
SPF, DKIM, DMARC and MTA-STS publish the moment a domain attaches, with no manual DNS work anywhere in the path.
Step 2: Alignment is watched per send
SPF and DKIM alignment is checked on every send, and DMARC policy only tightens as a clean history accumulates behind it.
Step 3: Placement is sampled on a clock
Seed sends land across the major providers every six hours, not only during the week you onboarded.
Step 4: Blocklists checked every 15 minutes
Reputation Radar queries every domain and IP you own against the major public lists around the clock.
Hear it from us, not from a bounced campaign.
Every record, every alignment check and every blocklist query runs on a clock. Point it at your own domains and watch it work.
