Read your email authentication breakdown
A single 'authentication: pass' label hides the details that actually explain deliverability failures. A useful authentication breakdown separates the message verdicts from the DNS controls behind them: SPF authorization, SPF alignment, DKIM DNS, DKIM alignment, DMARC policy, reverse DNS/HELO, MTA-STS/TLS-RPT and BIMI readiness. If SPF, DKIM and DMARC pass on the actual message but placement is still poor, stop editing DNS at random and move to reputation, recipient response, message and link integrity, mailstream isolation and provider-specific evidence.
Mailbox providers evaluate identity as a chain, but authentication establishes accountable identity rather than guaranteed inbox placement. If one link is vague, a sender can waste days fixing the wrong thing: SPF passes but does not align, DKIM passes with an old selector, DMARC exists but does not enforce, or reverse DNS makes dedicated infrastructure look disposable. If the chain is verified, the next investigation belongs to reputation and behavior. Breaking the evidence into sub-checks turns a generic failure into a bounded DNS, message, infrastructure or recipient-quality task.
How to fix it
- Start with message-level verdicts: SPF pass/fail, DKIM pass/fail and DMARC pass/fail from the received authentication results.
- Split SPF into DNS health and alignment, because a syntactically correct SPF record can still fail DMARC alignment.
- Split DKIM into selector DNS, key quality and alignment, because a DKIM fail can come from DNS, signing or message modification.
- Split DMARC into record validity, reporting, policy strength, subdomain policy and the actual SPF/DKIM alignment path.
- Add infrastructure checks for dedicated senders: reverse DNS, forward-confirmed hostnames and HELO/EHLO naming.
- Track security/readiness checks separately: MTA-STS, TLS-RPT and BIMI should inform the report without pretending they replace inbox-placement testing.
- When SPF, DKIM and DMARC pass, confirm the verdicts belong to the same message, domain, ESP and mailstream that experienced the placement problem.
- Inspect provider-specific placement, complaint, bounce and eligible Postmaster or ESP evidence; do not infer reputation recovery from one seed test.
- Audit links, redirects, unsubscribe behavior and destination trust, then map promotional, transactional and acquisition streams to their domains, return paths, DKIM identities and IP pools.
- Make one bounded change and run a comparable retest. Preserve the baseline and change log so a higher score cannot be mistaken for proof of the wrong fix.