Email-domain change and monitoring checklist
A DNS-control checklist for SPF, DMARC, explicit DKIM selectors, change ownership and recovery verification.
How to use it
Copy, assign owners, then attach real evidence.
A checklist is useful only if each item has an owner and a verifiable state. Do not mark an item complete because a tool returned a green badge.
- [ ] Authoritative domains and DNS owners listed - [ ] SPF record parsed and lookup risk reviewed - [ ] DMARC policy and reporting addresses verified - [ ] DKIM selectors supplied by the operator, never guessed - [ ] Change/recovery alerts assigned to an owner - [ ] Post-change DNS state rechecked after propagation
Checklist
What complete should mean.
Authoritative domains and DNS owners listed
SPF record parsed and lookup risk reviewed
DMARC policy and reporting addresses verified
DKIM selectors supplied by the operator, never guessed
Change/recovery alerts assigned to an owner
Post-change DNS state rechecked after propagation
Primary / official source basis
Keep the checklist tied to the current source.
Reviewed 2026-08-31. Source owner: IETF / RFC Editor.
RFC 7208 — Sender Policy Framework (SPF)
RFC Editor / IETF
Standards-track SPF protocol reference for published sending-domain authorization state.
RFC 6376 — DomainKeys Identified Mail (DKIM)
RFC Editor / IETF
Standards-track DKIM reference for selector/domain public-key verification.
RFC 9989 — DMARC
RFC Editor / IETF
Current May 2026 DMARC protocol specification, which obsoletes RFC 7489 and RFC 9091.
The template is an operating aid, not certification.
Use the checklist to structure evidence, ownership and review. It does not replace the authoritative system, regulator, specialist audit, legal advice or professional judgement that may apply to the underlying job.
- DKIM selectors are never guessed
- No automatic DNS mutation
- No guarantee of inbox placement, sender reputation or provider certification