Audit multi-domain authentication
Review authentication across a domain portfolio.
Objective
Audit an existing domain
Assess current authentication posture and gaps.
Starting state
Multiple sending domains/brands with uneven SPF/DKIM/DMARC posture
Prerequisites
- Domain portfolio list
- Access to DNS and DMARC reporting for each domain
Estimated time
1–2 hours
Difficulty
intermediate
Required access
- DNS
- ESP or MTA admin
Inputs
- Domain inventory
- Owner/team map
- Current policy expectations
Step-by-step instructions
- Build the portfolio matrixFor each domain, record SPF, DKIM selectors, DMARC policy, reporting, and active sending platforms.
- Score riskFlag missing DMARC, p=none with no monitoring, lookup-limit SPF, and domains still sending without DKIM.
- Remediate in priority orderFix high-risk production domains first using the configure SPF/DKIM/DMARC workflows.
- Schedule re-auditSet a recurring review so new ESP includes and brand domains cannot drift untracked.
Verification
- Every in-scope domain has a recorded posture
- Critical gaps have owners and due dates
Common mistakes
- Auditing without fixing production domains that are actively spoofable
- Centralize DMARC reporting across the portfolio?
- Which domains can stay at p=none temporarily?
Rollback / recovery
- N/A — audit activity; revert any mistaken DNS edits per domain
Expected outcome
A clear portfolio-wide authentication posture with prioritized remediation.
When to escalate
- Production mail impacted unexpectedly