Best Tools for Auditing an Outbound Email Stack

Yananai A. ChiwutaPublished ·15 min readUpdated
Best Tools for Auditing an Outbound Email Stack

TL;DR

  • Use MXToolbox for immediate DNS and header checks, then dmarcian or EasyDMARC for a continuing authentication inventory. They answer different questions from inbox-placement tests.
  • GlockApps is the most economical starting point in this shortlist for a small, occasional placement audit. Buy enough test credits for the actual domain and message combinations.
  • MailReach fits recurring mailbox monitoring, especially when the team already uses its warmer. Its test results still need to be connected to the sending configuration and recipient segment.
  • Google Postmaster Tools and Microsoft SNDS add provider evidence where coverage and access permit. An empty dashboard or clean IP is not proof that every business recipient received a message.
  • Finish by tracing a reply into the CRM. A technically healthy sender can still lose revenue through an expired integration, missing suppression or an unassigned conversation.

What a stack audit should establish

An outbound stack spans the prospect source, verifier, exclusion list, domains, mailboxes, sequencer, tracking host, reply inbox and CRM. An audit should establish how those parts connect, who can change them and what happens when a connection fails. A list of green DNS checks is useful, but it cannot explain why an existing customer entered a prospect campaign or why an interested reply never reached a salesperson.

Start with an inventory that connects each sending address to its domain, mailbox tenant, sequencer account, campaign and reply owner. Add the registrar and DNS owner, renewal date, authentication configuration, tracking domain and integration credential owner. Record who can revoke access when a client leaves. A shared spreadsheet can handle twelve mailboxes; the important feature is a maintained relationship between assets, rather than an expensive inventory application.

Then follow one eligible prospect from its source to a reply, and one excluded prospect through the stop path. Preserve timestamps, record identifiers, campaign identifiers and the relevant message header. Those artefacts let the operator distinguish an import error from a sending failure or a CRM handoff failure.

This is a whole-stack review before scaling, after a migration or during a periodic maintenance check. Our cold email deliverability forensics guide concentrates on diagnosing a delivery incident. Here, even successful inbox placement is only one stage of the buying decision.


Compare the tools by the question they answer

Prices and public documentation were reviewed on 1 October 2026. USD figures below exclude tax. Free provider tools require appropriate domain or IP access; they do not replace the team's own campaign and CRM records.

Tool Useful audit evidence Purchase basis Best use Important boundary
dmarcian Which services send authenticated mail for the domains? Basic $24/month for up to two active domains; Plus $240/month for up to eight Identify legitimate sources and continuing authentication drift Aggregate authentication reports do not show a CRM reply handoff
EasyDMARC Authentication management across several domains DMARC Plus $44.99/month, two domains; Premium $89.99/month, four domains A small managed domain fleet needing retained reports and alerts Its broader Deliverability tier has custom pricing; do not assume full placement testing is included in the DMARC base
MXToolbox Public DNS, blacklist and message-header clues Free lookups; paid monitoring depends on the selected Delivery Center package Quick independent checks and investigation of a particular message A blacklist result alone does not establish inbox placement
GlockApps Where a controlled message lands in its seed accounts Ten-test credit pack $47.99, valid two months; twenty-test pack $75.99, valid three months Occasional comparisons of domains and message variants A seed result is a sample, not the placement rate of the whole campaign
MailReach Placement tests tied to mailboxes, with scheduled testing available Separate test-credit purchase or mailbox warmup subscription; warmer includes at least twenty test credits Continuing monitoring within an existing mailbox operation Warming activity is not proof of prospect engagement or clean suppression
Google Postmaster Tools Gmail authentication, reputation, complaints and errors Provider dashboard without a separate paid audit subscription Trends for mail reaching personal Gmail accounts Low volume can leave gaps; it does not represent every Google Workspace recipient
Microsoft SNDS Outlook.com evidence about sending IPs, plus associated complaint feedback Provider service for authorised IP operators Teams operating IPs or obtaining evidence from their sending provider Shared mailbox customers usually cannot treat a provider's entire IP range as their own

Sources: dmarcian pricing, EasyDMARC business plans, MXToolbox package comparison, GlockApps credit packs, MailReach pricing, Google's dashboard documentation and Microsoft SNDS.


The seven audit tools

1. dmarcian: account for the services using your domains

dmarcian belongs in an audit when the team cannot confidently list every legitimate sender. Marketing software, invoicing, support and prospecting may use the same organisation's domains, with different authentication arrangements. DMARC reporting helps the domain owner separate expected services from forgotten or unauthorised sources.

Basic supports up to two active domains and 100,000 legitimate DMARC-capable messages per month, with three months of history. Plus raises the domain limit to eight, the message allowance to one million and history to a year. The monthly prices are $24 and $240 respectively; annual billing displays lower monthly equivalents. The personal free plan is for non-business use, so it is not the budget assumption for a commercial outbound team.

Choose it when understanding sending sources and retaining their authentication history matters more than buying another placement score. A four-domain team exceeds Basic's domain allowance even when message volume is modest. The limitation is scope: a valid DMARC result cannot show whether a salesperson followed up on a reply.

2. EasyDMARC: a practical four-domain monitoring purchase

EasyDMARC provides domain authentication management and reporting, with a wider platform extending into sender insights and deliverability. It is a useful alternative when a small team wants several outbound domains in one purchase rather than a two-domain entry tier.

Its current business pricing separates DMARC Plus, Premium, Deliverability and Enterprise. Premium's monthly base is $89.99 for four domains, starting at 100,000 messages per month and one year of history. The $71.99 monthly equivalent belongs to annual billing. Plus is $44.99 monthly for two domains and three months of history. Dedicated customer-success support on these DMARC plans is identified as annual-only.

For the four-domain example below, Premium is the more direct package than dmarcian Basic. That is a capacity and price judgment, not a claim that the products have identical analysis or service. Full placement testing and the broader deliverability modules belong to a different, custom-priced tier. Buy Premium for the authentication task and budget a placement tester separately.

3. MXToolbox: inspect the actual DNS and header

MXToolbox is valuable at the beginning of an audit because a public lookup can expose a missing record, unexpected routing or a listed sending IP without another mailbox subscription. Its message-header analyser is useful when the team has a received message to inspect. Keep the header associated with its domain, sending account and message variant; an isolated screenshot loses that context.

The free monitoring offer covers one blacklist monitor across thirty lists. Paid products add monitoring and deliverability reporting through selected packages. This guide uses the free lookup layer rather than assigning an unsupported all-in paid price.

The distinction matters for shared infrastructure. A listed IP can be a clue about the provider, while a domain or authentication problem may be specific to your configuration. Neither result is an instruction to replace every mailbox. MXToolbox also cannot inspect the exclusion decision in a prospecting database or certify the permissions of the CRM integration. Choose it for a fast technical second view, then follow the clue to the responsible asset.

4. GlockApps: compare controlled messages without a large subscription

GlockApps tests placement through seed recipients. Send the actual proposed message through the same route as the campaign so that the result relates to its sender, content, links and headers. A message sent manually from another application is a different experiment.

The credit-pack pricing makes it useful for an occasional audit: three credits cost $16.99 and expire after one month, ten cost $47.99 and expire after two months, and twenty cost $75.99 and expire after three months. The larger pack has a lower unit cost, but unused or expired credits have no audit value. Pack validity matters more than the lowest advertised price per test when a team tests only once a quarter.

Use it to compare a small, declared test matrix. Hold the recipient panel and sending route consistent when comparing two versions. A poor result identifies something to investigate; a good result supports that particular sample. It cannot establish the percentage of an entire live prospect list reaching inboxes, and it cannot show whether opt-outs were excluded before sending.

5. MailReach: recurring mailbox tests where the operation already exists

MailReach combines a warmer with a spam tester and also sells test credits separately. It is worth considering when the audit will become a regular mailbox monitoring process. The published warmer includes at least twenty test credits; do not multiply that allowance by the number of mailboxes without establishing the purchased pool.

Its one-time test documentation says a completed test consumes one credit. Results distinguish business and consumer recipient-provider groups, which helps a B2B operator avoid interpreting a personal-mailbox score as the whole target market. Scheduled tests can make repeat observations easier than relying on someone remembering to send a seed message.

Pricing depends on selected warmup mailboxes or test credits, and the public calculator mixes several selections. Use that purchasing basis rather than presenting one extracted calculator total as the price of every configuration. An existing subscriber should use the included testing capacity before adding another service. A team seeking eight occasional tests has a clearer bounded purchase in GlockApps' ten-credit pack. Buying warmup across twelve mailboxes solely to perform that audit is difficult to justify.

Google Postmaster Tools supplies provider-level authentication, reputation, user-reported spam and delivery-error information for personal Gmail recipients. It is useful context when repeated tests and campaign observations suggest a Gmail-specific problem.

The data is delayed and can be absent at low volume. The user-reported spam metric concerns messages reaching engaged recipients' inboxes and then being marked as spam. Automatic filtering can therefore coexist with an apparently low complaint rate. Zero complaints is not a general inbox-placement certificate.

Use the dashboard where the sending domain has enough covered traffic, then compare dates and domains with the campaign record. A small B2B fleet targeting company mailboxes may obtain limited information from this consumer-Gmail view. Do not increase sending simply to populate a dashboard, or blend the provider's complaint metric with a tester's seed-placement percentage as though their denominators matched.

7. Microsoft SNDS: IP evidence from the responsible operator

Microsoft's current SNDS portal, updated in September 2026, provides Outlook.com information about individual sending IPs and access to complaint feedback through its related reporting programme. It suits the organisation operating the relevant IPs, or an audit conducted with that provider's evidence.

A team using Microsoft 365 or Google Workspace mailboxes on shared infrastructure usually does not control the provider's IP range. Record who owns the transport and who can supply relevant reputation information rather than making an unsupported access assumption. SNDS's Outlook.com scope also differs from delivery into every Microsoft 365 business tenant.

The service adds a useful provider perspective, but it is not another SaaS mailbox health score. Choose it when IP ownership and recipient coverage make its evidence applicable. Otherwise, use received headers, sending errors and a controlled business-provider seed test to investigate the route you actually use.


A source-to-reply audit

Consider an illustrative team with four sending domains, twelve mailboxes, one sequencer and one CRM. It imports 1,000 records for a new campaign. This is a constructed audit example, not a test of any named vendor.

The source ledger identifies four non-overlapping exclusion groups: eighty duplicates, sixty current customers, twenty recorded opt-outs and forty invalid addresses. The eligible export should contain 800 records. The sender instead contains 820 because the export job omitted the opt-out table. DNS can be perfectly configured while this defect remains.

Stage Artefact to retain What the example finds Diagnosis and repair
Source and verification Batch ID, stable contact IDs, verification date and result Forty invalid addresses excluded Verification is functioning; do not blame this stage for twenty excess imports
Eligibility Exclusion reason per record and eligible-export count Source says 800; sender shows 820 Join the opt-out table before export; remove the twenty records before activation
Infrastructure Domain-to-mailbox inventory, DNS results and a received header One mailbox still uses an obsolete signing configuration Repair that mailbox's configuration and retest its actual sending route
Placement Four domains × two message variants, with sender and test time The link-bearing version performs poorly on one domain's business seed group Compare tracking/link configuration while holding sender and copy otherwise constant
Sending Campaign enrollment, message ID and send timestamp for contact L042 Eligible contact L042 receives the intended first message The source-to-sender path works for this contact; this does not absolve the exclusion defect
Reply and CRM Received reply ID, integration event, CRM record and assigned owner L042's interested reply is in the inbox but has no CRM task An expired webhook credential interrupted the handoff; restore it and reconcile missed replies

These findings require three repairs, not a wholesale infrastructure replacement. The omitted exclusions need a corrected export and a stop-path fixture. The affected mailbox needs configuration repair and a new header/test. The broken handoff needs credential restoration, replay or manual reconciliation and an assigned reply owner.

After fixing the export, import an explicit test record that should be excluded and confirm it stays out of both existing and future campaigns. After fixing the reply integration, follow a new test conversation into the CRM and confirm the owner can see it. Reconcile the period since the credential expired; restoring a connection does not itself recover messages already missed.

Eight placement tests cover four representative domain senders and two variants. They do not inspect all twelve mailboxes. The inventory and header checks cover each mailbox; expand placement testing when different tenant settings, sending routes or symptoms justify more combinations. This keeps the audit bounded while retaining the information needed to choose the next repair.

The final record should give each finding an owner and a closure artefact: corrected counts, a new header, a retest result or the CRM task linked to the reply. “Tool says healthy” is weaker than an observable repaired path. Our outbound playbook helps connect that operational work to the campaign decision.


What the audit costs

A one-off audit of this example can start with free technical lookups, available provider evidence and a ten-credit GlockApps pack for eight placement tests. Assume six operator hours at $75/hour. Labour is $450, and the pack is $47.99, giving $497.99 before tax and repair work. This is an editorial budget, not a vendor service quote. Existing CRM, sender, domains and mailboxes are operating costs already incurred and are outside the incremental audit purchase.

The two unused credits can support a limited retest within the pack's two-month validity. If repairs require substantially more comparisons, add capacity explicitly rather than pretending the initial budget covers unlimited iteration.

A continuing version could add EasyDMARC Premium for four domains, allocate two operator hours each month and buy a twenty-credit pack every two months. Eight tests each month consume sixteen credits per two-month period, within the twenty-credit capacity and three-month validity. Four spare credits per pack provide some retesting room, although that is not an unlimited allowance.

Recurring annual budget Calculation USD
Four-domain DMARC monitoring, monthly billing $89.99 × 12 $1,079.88
Placement packs $75.99 × 6 $455.94
Review and reconciliation labour 2 hours × 12 × $75 $1,800.00
Total recurring audit allocation Sum $3,335.82

This is a separate recurring option, not an additional fee to stack mechanically on the one-off package. Initial inventory work and any remediation are extra. Annual EasyDMARC billing changes the software amount, but the table deliberately uses monthly billing to avoid disguising a commitment as a monthly cancellable price.

dmarcian Plus at $240/month would add $150.01/month, or $1,800.12/year, over Premium's monthly base in this four-domain scenario. Its eight-domain capacity and larger message allowance may become useful as the fleet expands. Basic does not fit four domains, but buying Plus merely to solve that capacity limit is expensive compared with the directly applicable Premium package.

The commercial value comes from correcting a real defect. At an illustrative $400 contribution per recovered sale, a $497.99 initial audit needs two attributable recovered sales to exceed its cost. That is a decision threshold, not a forecast that an audit will recover two sales. Suppression failures may warrant repair regardless of short-term revenue, while a missed interested reply provides a concrete commercial reason to prioritise the CRM handoff.


Build the smallest useful audit stack

For a small team performing its first audit, begin with the source and sender counts, the asset inventory, MXToolbox checks, received headers and a bounded placement pack. Add provider dashboards where they cover the audience. That combination can reveal configuration and handoff problems without paying for seven overlapping subscriptions.

For four domains requiring continuing authentication history, EasyDMARC Premium is the straightforward priced option here. Choose dmarcian when its source analysis, larger qualifying package or the team's existing expertise makes the higher purchase useful. Existing MailReach customers should incorporate their included tests and scheduled observations into the same audit record rather than discard a working monitoring process merely to buy another tester.

The acceptance point is a prospect excluded when it should be excluded, an eligible message sent through the intended infrastructure, and a reply reaching a responsible person. Each tool illuminates part of that path. The stack is operationally ready when the parts connect and the important defects have been closed.


FAQ

Can one deliverability tool audit the entire stack?

One product may combine authentication reports, placement tests and alerts, but those observations do not establish how a data export applies exclusions or how a reply becomes a CRM task. Keep the source-to-reply trace even when the technical checks sit in one vendor. It identifies failures outside the vendor's visibility and gives the team a concrete closure test.

Is a free audit enough for a small team?

Free DNS lookups, received headers, eligible-record counts and available provider dashboards can expose important faults. Add paid placement tests when you need to compare message variants or routes, and retained DMARC reporting when authentication history matters. Labour and access ownership usually determine whether the audit gets completed; a free dashboard alone does not do that work.

Should every mailbox receive a seed test?

Every mailbox should appear in the inventory and have its actual configuration checked. Placement sampling can start with representative senders for each domain and configuration. Test more mailboxes when routes differ, an account has changed or symptoms point to a specific sender. Eight tests across four domains are a defined sample, not a claim that twelve mailboxes have identical performance.

Does a clean Google or Microsoft dashboard prove delivery is healthy?

Provider dashboards cover defined audiences and metrics. Google may withhold data at low volume, and SNDS concerns Outlook.com traffic associated with sending IPs. Read them alongside message headers, errors, seed tests and replies. An apparently clean metric can coexist with an unrelated suppression or CRM failure.

How often should the team audit the stack?

A full trace is useful before scaling and after a provider, CRM, sequencer or client migration. A small recurring review can check changed assets, authentication alerts, exclusions and unmatched replies. Repeat the affected path after a defect is repaired. Frequency should follow the rate of change and the cost of a missed handoff rather than the number of tools purchased.

Yananai A. Chiwuta

Author

Yananai A. Chiwuta

CEO & Co-Founder

Yananai A. Chiwuta is the CEO and Co-Founder of Forma Nôrden, where he builds managed acquisition systems for B2B companies through signal-based outbound and precision paid ad acquisition. He has built and exited two companies, most recently FunnelVision.

Celine Sky-Chiwuta

Article reviewed by

Celine Sky-Chiwuta

Co-Founder & CMO

Celine Sky-Chiwuta is the Co-Founder and CMO of Forma Nôrden, where she shapes the positioning and marketing behind the company’s managed acquisition systems. She previously served as CMO of FunnelVision through its 2025 acquisition.

Related Articles