email·digit
Pillar 02 · Managed Deliverability

Three records.
We handle the rest.

Two CNAMEs and one TXT record at your DNS provider — once. Then we manage DKIM rotation, SPF flattening, and DMARC progression on our zone. Q3 2026 MTA-STS · TLS-RPT · BIMI · 100+ blocklist surveillance — all included on the same delegation when they land.

Setup

Five minutes.
Three steps.

Most teams are sending from your-domain.com within an hour of access. DMARC walks to enforcement automatically over the next six weeks.

01

Connect your domain

Tell us acme.com. We generate a unique slug for you, like acme-com-a3f1b8, that you'll never have to think about. The slug is your namespace on our zone.

02

Publish three records · one time

At your DNS provider: ed1._domainkey.acme.com CNAME → acme-com-a3f1b8.dkim.emaildigit.com; _dmarc.acme.com CNAME → acme-com-a3f1b8.dmarc.emaildigit.com; and acme.com TXT → v=spf1 include:_spf.emaildigit.com ~all. We don't touch your root A/MX, your nameservers, or anything else.

03

We propagate · verify · operate

Inside 5 minutes we publish DKIM (RSA 2048), SPF (flattened SES IPs), and DMARC at p=none. Over the next 6 weeks we walk DMARC to p=reject with reporting throughout. Future key rotations happen on our zone — your DNS is never touched again.

What we manage

Six records.
Continuous custody.

Every record below is published, monitored, and rotated on a schedule. Misconfigurations alert before they affect deliverability. You'll see them in the dashboard but you won't have to touch them.

Record
Purpose
What we do
Status
DKIM
Cryptographically signs every outgoing message so recipients can verify it came from you.
RSA 2048-bit keys per workspace, generated on domain create. Signed via dkimpy library (RFC 6376). Keys are Fernet-encrypted at rest. Rotation in-place on our zone — your CNAME never has to change.
Live
SPF
Tells receiving mail servers which IPs are allowed to send for your domain.
Customer SPF includes our managed _spf.emaildigit.com, which we keep flattened to the current AWS SES IP list. When AWS rotates IPs, we re-flatten our record — your DNS keeps working untouched.
Live
DMARC
Tells receivers what to do when SPF or DKIM fail — quarantine, reject, or report only.
Starts at p=none. 6-step progression to p=reject pct=100. Safety gates require alignment ≥ 95% before each promotion. RUA reports ingested + summarized in the dashboard.
Live · in progress
MTA-STS
Requires that mail be delivered over TLS — protects against downgrade attacks in transit.
Hosted policy file + DNS TXT, mode=enforce. Not yet shipped — comes with the next deliverability layer.
Q3 2026
TLS-RPT
Reports back when an MTA can't establish TLS — visibility into man-in-the-middle attempts.
RUA pointed at our reporting endpoint. Daily reports parsed; anomalies surfaced as Sev-2 incidents.
Q3 2026
BIMI
Brand logo shown alongside your messages in Gmail, Apple Mail, and Yahoo inboxes.
Optional. Requires a Verified Mark Certificate (VMC) — $99/year add-on. We file with Entrust or DigiCert, host the SVG, and publish the TXT.
Q3 2026
Deliverability score Q3 2026

One number that means something.

Most deliverability tools surface 40 metrics and let you figure out which ones matter. Email Digit will compose one daily score from five weighted components — and tell you which one moved when the number changes.

  • Authentication · SPF / DKIM / DMARC alignment (30%)
  • Reputation · sender score across major receivers (25%)
  • Complaint rate · ratio of complaints to delivered (20%)
  • Bounce mix · hard vs soft, transient vs permanent (15%)
  • Inbox placement · seed-test rate to major providers (10%)
mail.acme.com · preview▲ 1.4 today
98.4/100
Auth alignment30/30
Reputation24/25
Complaint rate19.6/20
Bounce mix15/15
Inbox placement9.8/10
Blocklist surveillance Q3 2026

100+ blocklists.
Watched continuously.

When it ships: alerts the minute your sending domain or any of its IPs appears on a blocklist. We'll temporarily reroute sending through a clean pool while we work on the delist request.

Spamhaus DBL
Spamhaus SBL
Spamhaus XBL
Spamhaus ZEN
Barracuda
SORBS
SURBL multi
URIBL
SpamCop
Invaluement
Mailspike
Lashback UBL
PSBL
Truncate
Spam Eating Monkey
UCEPROTECT L1·2·3
DNSBL.info
SEM FRESH
Backscatterer
+ 80 more
Positioning

Why not a dedicated deliverability tool?

The Valimails and dmarcians of the world tell you what's broken. Email Digit fixes it — because we're already sending your mail.

DIY (DNS + your ESP)

$0 + your time
  • You manage every record by hand
  • You parse DMARC XML reports
  • You discover a blocklist when sends drop 40%
  • You rotate DKIM keys (or don't)
  • You answer when activation tanks

Valimail · dmarcian · EasyDMARC

$50–500/mo · enterprise tier $$$$
  • Excellent DMARC reporting
  • Tells you what's failing
  • Doesn't actually send your mail
  • You still need an ESP
  • Doesn't process replies
  • Priced for procurement teams

Email Digit RECOMMENDED

Included in every paid tier
  • Two CNAMEs + TXT, full record custody
  • DMARC walked to enforcement automatically
  • Reports translated to plain English
  • Same product handles campaigns + replies
  • One number summarizes everything Q3 2026
FAQ

DNS questions, answered.

What if I leave Email Digit — can I roll back?

Yes, one click. You're only delegating a subdomain via CNAME, not handing over your nameservers. Remove the CNAMEs and the records stop resolving — your root domain, every other subdomain, and your existing DNS records are untouched throughout. We also offer a full export of historical DMARC reports and DKIM key history on request.

Why subdomain — why not nameserver delegation?

Trust gradient. Nameserver delegation means we'd run your whole DNS — your apex A record, your CDN, your Google verification token. That's far more access than you need to give for email infrastructure. Two CNAMEs + a TXT is the minimum we need to do the job, so it's what we ask for.

Why two CNAMEs and a TXT — not just one record?

SPF must live as a TXT record at the apex of your domain (acme.com, not _spf.acme.com) — DNS rules forbid putting a CNAME alongside other records there. DKIM and DMARC can be CNAMEs to our zone, so those two move to managed delegation. Net: one ongoing TXT (SPF, set once), two CNAMEs that we manage forever.

How long until DMARC reaches p=reject?

Default schedule is 6 weeks: 2 weeks at p=none, 4 weeks at p=quarantine pct=50, then p=reject. We hold position if we see legitimate mail being affected — your forwarding rules, third-party senders, anything not aligned gets surfaced before we tighten policy.

What happens if my deliverability score drops?

Score crossing thresholds (when shipped): 90 → 80 creates a Sev-3 incident with diagnosis. 80 → 70 Sev-2, sending throttled. Below 70 sending pauses until root cause is resolved.

Do you support BIMI?

Q3 2026. The DNS TXT record will be included. The Verified Mark Certificate (VMC) is a $99/year add-on because Entrust and DigiCert charge us a fee per VMC issued. We handle the filing on your behalf.

Pillar 02 · Managed Deliverability

Let us own
the records.

Three records. One-time setup. Six weeks to enforcement. You write the email.