How we score your domain — infrastructure-based analysis, not guesswork. Every check we run, every point we assign, explained transparently.
DNS authentication is the foundation — these four capabilities are the deliverability infrastructure stack on top of it.
Early access. Sends on Humerly's own infrastructure are scored before they leave. This does not apply to domains you send from elsewhere.
Early access. Placement is sampled on seed mailboxes Humerly owns. That is a sample of our own mailboxes, not a measurement of where your production mail lands, and not a provider-by-provider trend.
Early access. Volume throttles and send-pair limits apply to sending on Humerly's infrastructure.
The audit scores DNS and authentication. It does not measure recipient engagement, and Humerly does not manage engagement as a dimension: engagement belongs to your recipients, and manufacturing it is the practice this product exists to replace.
We check 7 email authentication standards defined by IETF and major inbox providers. These form the foundation of your domain's technical reputation.
Does your domain have mail servers configured? Without MX records, you cannot receive email at all. We query DNS for your MX records and verify at least one valid mail server is declared.
Which servers are authorized to send email for your domain? -all declares a fail result for every other sender, and ~all declares softfail (RFC 7208 §8.4, §8.5). Both are statements you publish about your own domain; what a receiver does with either is its own policy and is not specified by SPF.
Are your emails digitally signed? DKIM adds a cryptographic signature proving the email genuinely came from your domain and wasn't modified in transit. We test the most common selectors via DNS lookup.
What do you ask receivers to do when a message fails SPF and DKIM alignment? p=quarantine and p=reject are the two enforcement values a domain owner can publish (RFC 7489 §6.3). DMARC is a request, not an instruction: the receiver decides whether to honour it. We parse the full record and report the enforcement level you published.
Is email transport to your domain encrypted? MTA-STS publishes a policy forcing sending servers to use TLS when delivering mail to you, preventing man-in-the-middle attacks on incoming email.
Do you receive reports about email transport security failures? TLS-RPT lets mail servers notify you when TLS connections to your domain fail, helping you identify delivery problems early.
BIMI publishes a location for your logo and, where required, a Verified Mark Certificate. It requires DMARC at enforcement. Whether any mailbox provider displays the logo is that provider's decision; publishing the record does not oblige anyone to show it.
Each check contributes a fixed number of points to your Authentication Score. Points are additive and capped at 100.
Being reconciled, 2026-09-08. The table below is the published formula. The audit API currently returns a different number from the grade the report renders for the same domain, so which of the two this table describes is not settled. Until it is, read this as the intended model rather than a guarantee of the number you saw. The reconciliation is tracked and this note comes down when it lands.
Beyond authentication records, our audit pulls additional signals that affect real-world deliverability.
We believe in transparency. Our audit checks your domain infrastructure — not your email content.
Our audit is entirely infrastructure-based. We use public DNS lookups on the client side and our own backend for DKIM and blacklist checks. We do not access your email platform, inbox, or sending history.
We assign a confidence level to every audit. It says how complete the evidence behind the score is, not how any receiver will treat your mail.
Domain is 5+ years old with full authentication and clean blocklist status. Every check returned an answer, so the score rests on complete evidence.
Domain has partial signals or is between 1–5 years old. Score is directionally accurate but providers may apply additional caution to newer senders.
New domain (under 1 year) or missing critical authentication. Some checks had little history to read, so the evidence behind the score is thinner.
Last updated: April 2026 · Humerly Scoring Engine v2.0