How we score your domain — infrastructure-based analysis, not guesswork. Every check we run, every point we assign, explained transparently.
DNS authentication is the foundation — these four capabilities are the deliverability infrastructure stack on top of it.
Every outbound send is scored before it leaves your domain. Pre-send gates surface risk before a campaign goes out.
Track your deliverability trend across major providers, updated on a live cadence.
Auto-protect rules can throttle volume and tighten send-pair limits when risk climbs, with a recovery mode for reputation drops.
Deliverability is not DNS alone. Humerly scores and manages all five behavioral dimensions — content patterns, send timing, volume curves, engagement signals, and sender reputation — as one integrated layer.
We check 7 email authentication standards defined by IETF and major inbox providers. These form the foundation of your domain's technical reputation.
Does your domain have mail servers configured? Without MX records, you cannot receive email at all. We query DNS for your MX records and verify at least one valid mail server is declared.
Which servers are authorized to send email for your domain? A strict SPF policy (-all) tells Gmail: "reject any email not from my approved servers." A soft-fail (~all) is weaker but still positive.
Are your emails digitally signed? DKIM adds a cryptographic signature proving the email genuinely came from your domain and wasn't modified in transit. We test the most common selectors via DNS lookup.
What should happen when an email fails SPF or DKIM? A strong DMARC policy (p=quarantine or p=reject) tells providers to block fake emails. We parse the full DMARC record and evaluate the enforcement level.
Is email transport to your domain encrypted? MTA-STS publishes a policy forcing sending servers to use TLS when delivering mail to you, preventing man-in-the-middle attacks on incoming email.
Do you receive reports about email transport security failures? TLS-RPT lets mail servers notify you when TLS connections to your domain fail, helping you identify delivery problems early.
Does your brand logo appear next to your emails in the inbox? BIMI requires a valid DMARC enforcement policy and a verified mark certificate (VMC). It signals strong sender legitimacy to providers like Gmail and Yahoo.
Each check contributes a fixed number of points to your Authentication Score. Points are additive and capped at 100.
Beyond authentication records, our audit pulls additional signals that affect real-world deliverability.
We believe in transparency. Our audit checks your domain infrastructure — not your email content.
Our audit is entirely infrastructure-based. We use public DNS lookups on the client side and our own backend for DKIM and blacklist checks. We do not access your email platform, inbox, or sending history.
We assign a confidence level to every audit. Your score is always accurate — but confidence tells you how predictive it is of real inbox placement.
Domain is 5+ years old with full authentication and clean blacklist status. Score is highly reliable and strongly predictive of real-world inbox placement.
Domain has partial signals or is between 1–5 years old. Score is directionally accurate but providers may apply additional caution to newer senders.
New domain (under 1 year) or missing critical authentication. Score may not reflect actual inbox placement until sending reputation is established.
Last updated: April 2026 · Humerly Scoring Engine v2.0