Methodology

How Humerly Scores Email Deliverability

Bot warmup is dying.
Humerly isn't.

How we score your domain — infrastructure-based analysis, not guesswork. Every check we run, every point we assign, explained transparently.

Deliverability Infrastructure

Four Things We Do

DNS authentication is the foundation — these four capabilities are the deliverability infrastructure stack on top of it.

01
Pre-send risk scoring

Early access. Sends on Humerly's own infrastructure are scored before they leave. This does not apply to domains you send from elsewhere.

02
Deliverability trend monitoring

Early access. Placement is sampled on seed mailboxes Humerly owns. That is a sample of our own mailboxes, not a measurement of where your production mail lands, and not a provider-by-provider trend.

03
Auto-protect rules

Early access. Volume throttles and send-pair limits apply to sending on Humerly's infrastructure.

04
What the audit does not measure

The audit scores DNS and authentication. It does not measure recipient engagement, and Humerly does not manage engagement as a dimension: engagement belongs to your recipients, and manufacturing it is the practice this product exists to replace.

Section 01

How We Score Your Domain

We check 7 email authentication standards defined by IETF and major inbox providers. These form the foundation of your domain's technical reputation.

01
MX Records DNS

Does your domain have mail servers configured? Without MX records, you cannot receive email at all. We query DNS for your MX records and verify at least one valid mail server is declared.

02
SPF Sender Policy Framework

Which servers are authorized to send email for your domain? -all declares a fail result for every other sender, and ~all declares softfail (RFC 7208 §8.4, §8.5). Both are statements you publish about your own domain; what a receiver does with either is its own policy and is not specified by SPF.

03
DKIM DomainKeys Identified Mail

Are your emails digitally signed? DKIM adds a cryptographic signature proving the email genuinely came from your domain and wasn't modified in transit. We test the most common selectors via DNS lookup.

04
DMARC Domain-based Message Authentication

What do you ask receivers to do when a message fails SPF and DKIM alignment? p=quarantine and p=reject are the two enforcement values a domain owner can publish (RFC 7489 §6.3). DMARC is a request, not an instruction: the receiver decides whether to honour it. We parse the full record and report the enforcement level you published.

05
MTA-STS Mail Transfer Agent Strict Transport Security

Is email transport to your domain encrypted? MTA-STS publishes a policy forcing sending servers to use TLS when delivering mail to you, preventing man-in-the-middle attacks on incoming email.

06
TLS-RPT Reporting

Do you receive reports about email transport security failures? TLS-RPT lets mail servers notify you when TLS connections to your domain fail, helping you identify delivery problems early.

07
BIMI Brand Indicators for Message Identification

BIMI publishes a location for your logo and, where required, a Verified Mark Certificate. It requires DMARC at enforcement. Whether any mailbox provider displays the logo is that provider's decision; publishing the record does not oblige anyone to show it.

Section 02

Scoring Formula

Each check contributes a fixed number of points to your Authentication Score. Points are additive and capped at 100.

Being reconciled, 2026-09-08. The table below is the published formula. The audit API currently returns a different number from the grade the report renders for the same domain, so which of the two this table describes is not settled. Until it is, read this as the intended model rather than a guarantee of the number you saw. The reconciliation is tracked and this note comes down when it lands.

Authentication Score 0 – 100 points
MX valid
+15 pts
SPF exists
+15 pts
SPF strict policy (-all)
+10 pts
DKIM valid
+25 pts
DMARC exists
+10 pts
DMARC strict policy (quarantine / reject)
+10 pts
MTA-STS configured
+5 pts
TLS-RPT configured
+5 pts
BIMI configured
+5 pts
Maximum possible score 100 pts
DKIM carries the most weight (25 pts) because it is the only check that proves a message was signed by a key published in your DNS. A domain with no DKIM cannot produce that proof for any receiver that asks for it. What a given receiver then does is theirs to decide and we do not claim to know it.
Section 03

What We Also Check

Beyond authentication records, our audit pulls additional signals that affect real-world deliverability.

Blacklist Status
Checked against 25 DNS blocklists, 22 IP and 3 domain, including Spamhaus, SURBL and Barracuda
Domain Age & Registration
Fetched via RDAP protocol — new domains carry higher spam risk with inbox providers
SMTP Reachability
We test whether your mail server responds to SMTP handshakes, confirming it can accept email
DNS Configuration Health
Overall DNS integrity — checking for misconfigured, contradictory, or missing records
Section 04

What We Don't Check

We believe in transparency. Our audit checks your domain infrastructure — not your email content.

Our audit is entirely infrastructure-based. We use public DNS lookups on the client side and our own backend for DKIM and blacklist checks. We do not access your email platform, inbox, or sending history.

  • Analyze email subject lines or body text
  • Track your sending history
  • Test individual email deliverability
  • Access your Gmail or Outlook account
  • Store or sell your domain data
Section 05

Confidence Levels

We assign a confidence level to every audit. It says how complete the evidence behind the score is, not how any receiver will treat your mail.

✓ High Confidence

Domain is 5+ years old with full authentication and clean blocklist status. Every check returned an answer, so the score rests on complete evidence.

~ Medium Confidence

Domain has partial signals or is between 1–5 years old. Score is directionally accurate but providers may apply additional caution to newer senders.

⚠ Low Confidence

New domain (under 1 year) or missing critical authentication. Some checks had little history to read, so the evidence behind the score is thinner.

Why does domain age matter? Registration age is one of the signals the audit reports, because a domain with no sending history carries none of the evidence a receiver could weigh. We do not state what any receiver does with it: that decision is theirs, it is not published, and we cannot measure it from here.

See your domain's score now

No signup. No card. Results in 10 seconds. We check every authentication standard and return your Email Setup Score with the specific records that need fixing.

Check Your Domain → View Pricing

Last updated: April 2026  ·  Humerly Scoring Engine v2.0