You will get your SPF, DKIM and DMARC aligned and enforced at p=reject

Project details
What you get:
Every source sending as your domain, found and listed
SPF rebuilt under the ten lookup limit, DKIM set up per source
DMARC live with reporting, then moved to p=reject when the data says it is safe
A written report at the end, not just changed DNS records
Broken email is mostly invisible. Nobody calls to say your invoice landed in their spam folder, and your platform still logs it as delivered.
Usually the cause is alignment. SPF passes, DKIM passes, and the message still fails DMARC because the Return-Path domain does not match your From domain. That is what happens when Salesforce or Klaviyo sends on your behalf and nobody sets it up.
The aggregate reports are the closest thing there is to a live view of your own email. Every IP sending under your name turns up. The tool marketing signed up for in 2022. The vendor still sending from a cancelled account. Anyone spoofing you.
I did this at Proofpoint for years, running enforcement across more than sixty organizations. Sequence is most of the job. Publish an enforcing policy before you know every sender and you find the ones you missed when someone calls about missing invoices.
Every source sending as your domain, found and listed
SPF rebuilt under the ten lookup limit, DKIM set up per source
DMARC live with reporting, then moved to p=reject when the data says it is safe
A written report at the end, not just changed DNS records
Broken email is mostly invisible. Nobody calls to say your invoice landed in their spam folder, and your platform still logs it as delivered.
Usually the cause is alignment. SPF passes, DKIM passes, and the message still fails DMARC because the Return-Path domain does not match your From domain. That is what happens when Salesforce or Klaviyo sends on your behalf and nobody sets it up.
The aggregate reports are the closest thing there is to a live view of your own email. Every IP sending under your name turns up. The tool marketing signed up for in 2022. The vendor still sending from a cancelled account. Anyone spoofing you.
I did this at Proofpoint for years, running enforcement across more than sixty organizations. Sequence is most of the job. Publish an enforcing policy before you know every sender and you find the ones you missed when someone calls about missing invoices.
Project Type
Cybersecurity, ITWhat's included
| Service Tiers |
Starter
$149
|
Standard
$450
|
Advanced
$1,200
|
|---|---|---|---|
| Delivery Time | 3 days | 7 days | 30 days |
Number of Revisions | 2 | 2 | 0 |
Frequently asked questions
115 reviews
(114)
(1)
(0)
(0)
(0)
This project doesn't have any reviews.
SH
Scott H.
Jul 3, 2026
Email Reputation and Deliverability Expert
CM
Cooper M.
Dec 19, 2025
Website, DNS, Teaching, Etc
DK
Dave K.
Mar 1, 2022
Email Deliverability Project
Great experience working with Neil.
SV
Shlomo V.
Feb 21, 2022
Troubleshoot email delivery problem
A pleasure to work with.
Provided expert assistance
Provided expert assistance
JS
Justin S.
Feb 3, 2022
Neil - Email Advice - Driven Media Group
About Neil
Email Deliverability & DMARC | SPF, DKIM, DNS, Inbox Placement
Eugene, United States - 4:02 pm local time
People usually find me after they've already tried a few things. Mail is landing in spam. Gmail or Microsoft is rejecting the domain on reputation while SPF, DKIM, and DMARC all pass, which means authentication was never the problem and someone has been fixing the wrong thing for weeks. A DMARC rollout is stuck at p=none because every move toward enforcement breaks something. Inbound mail went dead after a registrar move and nobody noticed the MX records didn't survive it. Marketing complaints are dragging down transactional mail, which is a subdomain problem and not a content problem. Or a mail migration is coming and the history can't be lost.
Most jobs start the same way. Read the headers, trace where the message actually died, pull the DMARC aggregate reports, and find out what is sending on your behalf that you don't know about. Usually it comes down to SPF and DKIM alignment, then a staged move from p=none to reject, paced by the report data so nothing legitimate gets caught. Sometimes it isn't authentication at all. It's reputation, the fix is sending behavior rather than DNS, and that's a harder conversation to have. Sometimes the whole thing is one MX record.
145 of my 179 Upwork contracts have been deliverability work. Before that I ran DMARC enforcement across more than 60 enterprise domains at Proofpoint, working in Email Fraud Defense, the Secure Email Gateway, and Domain Discover. Earlier I spent twelve years inside an email service provider handling deliverability for large senders. That is where you learn that the technical answer and the real answer are often different.
I work the mail and DNS layer inside Google Workspace and Microsoft 365. That covers setup, domain cutovers, tenant moves, and migrations where the history can't be lost. What I don't do is run a tenant day to day, so if you need ongoing user and license administration, that isn't me.
What I do work in: DNS at Cloudflare, GoDaddy, and most registrars, Postfix and cPanel on the server side, and sending through Mailgun, SendGrid, Mailchimp, Klaviyo, HubSpot, and Amazon SES. I use Google Postmaster Tools and Microsoft SNDS for reputation work, and I'll set up MTA-STS, TLS-RPT, BIMI, or DNSSEC when they actually matter, which is less often than vendors suggest.
I also build. I wrote an open source DNS and email security auditor in Python and FastAPI, made to check domains against RFC 9989, 9990, and 9991 while those were still being finalized. It explains what a result means instead of flagging a missing record and leaving you to work out the rest. It's in my portfolio below. Run your own domain through it before you hire anyone, including me.
Before Proofpoint I ran my own consulting practice for five years, handling email migrations, web hosting, and Linux infrastructure alongside authentication work. My writing has appeared in Linux Journal and MarketingProfs.
You get written findings with the reasoning behind them, not a list of records to change. Available for one-off diagnostics, project work, or ongoing advisory. Oregon, US hours.
Steps for completing your project
After purchasing the project, send requirements so Neil can start the project.
Delivery time starts when Neil receives requirements from you.
Neil works on your project following the steps below.
Revisions may occur after the delivery date.
Inventory what is already visible
I start with your DNS and whatever you can tell me about the tools you use. That covers some of what sends as you. It never covers all of it.
Publish DMARC at p=none and turn on reporting
Nothing about your mail changes at this stage. The record simply tells receiving systems to start sending reports, which is what makes everything after this possible.