Methodology

How Humerly Scores Email Deliverability

Bot warmup is dying.
Humerly isn't.

How we score your domain — infrastructure-based analysis, not guesswork. Every check we run, every point we assign, explained transparently.

Deliverability Infrastructure

Four Things We Do

DNS authentication is the foundation — these four capabilities are the deliverability infrastructure stack on top of it.

01
Pre-send risk scoring

Every outbound send is scored before it leaves your domain. Pre-send gates surface risk before a campaign goes out.

02
Deliverability trend monitoring

Track your deliverability trend across major providers, updated on a live cadence.

03
Auto-protect rules

Auto-protect rules can throttle volume and tighten send-pair limits when risk climbs, with a recovery mode for reputation drops.

04
Content, timing, volume, engagement, reputation.

Deliverability is not DNS alone. Humerly scores and manages all five behavioral dimensions — content patterns, send timing, volume curves, engagement signals, and sender reputation — as one integrated layer.

Section 01

How We Score Your Domain

We check 7 email authentication standards defined by IETF and major inbox providers. These form the foundation of your domain's technical reputation.

01
MX Records DNS

Does your domain have mail servers configured? Without MX records, you cannot receive email at all. We query DNS for your MX records and verify at least one valid mail server is declared.

02
SPF Sender Policy Framework

Which servers are authorized to send email for your domain? A strict SPF policy (-all) tells Gmail: "reject any email not from my approved servers." A soft-fail (~all) is weaker but still positive.

03
DKIM DomainKeys Identified Mail

Are your emails digitally signed? DKIM adds a cryptographic signature proving the email genuinely came from your domain and wasn't modified in transit. We test the most common selectors via DNS lookup.

04
DMARC Domain-based Message Authentication

What should happen when an email fails SPF or DKIM? A strong DMARC policy (p=quarantine or p=reject) tells providers to block fake emails. We parse the full DMARC record and evaluate the enforcement level.

05
MTA-STS Mail Transfer Agent Strict Transport Security

Is email transport to your domain encrypted? MTA-STS publishes a policy forcing sending servers to use TLS when delivering mail to you, preventing man-in-the-middle attacks on incoming email.

06
TLS-RPT Reporting

Do you receive reports about email transport security failures? TLS-RPT lets mail servers notify you when TLS connections to your domain fail, helping you identify delivery problems early.

07
BIMI Brand Indicators for Message Identification

Does your brand logo appear next to your emails in the inbox? BIMI requires a valid DMARC enforcement policy and a verified mark certificate (VMC). It signals strong sender legitimacy to providers like Gmail and Yahoo.

Section 02

Scoring Formula

Each check contributes a fixed number of points to your Authentication Score. Points are additive and capped at 100.

Authentication Score 0 – 100 points
MX valid
+15 pts
SPF exists
+15 pts
SPF strict policy (-all)
+10 pts
DKIM valid
+25 pts
DMARC exists
+10 pts
DMARC strict policy (quarantine / reject)
+10 pts
MTA-STS configured
+5 pts
TLS-RPT configured
+5 pts
BIMI configured
+5 pts
Maximum possible score 100 pts
DKIM carries the most weight (25 pts) because it provides the strongest cryptographic proof of domain ownership. A domain missing DKIM is at significant deliverability risk regardless of all other checks passing.
Section 03

What We Also Check

Beyond authentication records, our audit pulls additional signals that affect real-world deliverability.

Blacklist Status
Checked across 50+ databases worldwide including Spamhaus, SURBL, and Barracuda
Domain Age & Registration
Fetched via RDAP protocol — new domains carry higher spam risk with inbox providers
SMTP Reachability
We test whether your mail server responds to SMTP handshakes, confirming it can accept email
DNS Configuration Health
Overall DNS integrity — checking for misconfigured, contradictory, or missing records
Section 04

What We Don't Check

We believe in transparency. Our audit checks your domain infrastructure — not your email content.

Our audit is entirely infrastructure-based. We use public DNS lookups on the client side and our own backend for DKIM and blacklist checks. We do not access your email platform, inbox, or sending history.

  • Analyze email subject lines or body text
  • Track your sending history
  • Test individual email deliverability
  • Access your Gmail or Outlook account
  • Store or sell your domain data
Section 05

Confidence Levels

We assign a confidence level to every audit. Your score is always accurate — but confidence tells you how predictive it is of real inbox placement.

✓ High Confidence

Domain is 5+ years old with full authentication and clean blacklist status. Score is highly reliable and strongly predictive of real-world inbox placement.

~ Medium Confidence

Domain has partial signals or is between 1–5 years old. Score is directionally accurate but providers may apply additional caution to newer senders.

⚠ Low Confidence

New domain (under 1 year) or missing critical authentication. Score may not reflect actual inbox placement until sending reputation is established.

Why does domain age matter? Gmail and Outlook treat new domains as high-risk by default regardless of technical setup. A perfect SPF/DKIM/DMARC configuration on a 3-month-old domain will still land in spam more often than a 5-year-old domain with the same setup. This is what Humerly's deliverability infrastructure resolves.

See your domain's score now

No signup. No card. Results in 10 seconds. We check every authentication standard and return your Email Setup Score with the specific records that need fixing.

Check Your Domain → View Pricing

Last updated: April 2026  ·  Humerly Scoring Engine v2.0