ServicesGrowthWorkBlogAboutContactRequest a call
Home/Services/Email Deliverability & DMARC
Email Deliverability

Authenticated email that is hard to spoof.

Most domains send mail from more services than anyone remembers: the website, the CRM, the help desk, the billing tool. We find them all, authenticate each one and shut out spoofing without breaking legitimate mail.

From $299 setup + $49/mo

In short

Email deliverability is whether your messages reach the inbox instead of the spam folder or a rejection. Gmail and Yahoo expect every sender to use SPF or DKIM; bulk senders (around 5,000 or more messages a day) also need DMARC and one-click unsubscribe. Authentication improves deliverability, and once DMARC is enforced others cannot send email as your exact domain. FIMM finds every sender, fixes the DNS records and moves your policy in steps to p=reject. Setup starts at $299, with monitoring from $49 a month.

SPF DKIM DMARC p=reject Gmail & Yahoo rules CASL Postmaster Tools
What we build

What we build.

A

Sender inventory

We list every platform that sends as your domain, using DMARC reports and your DNS history, so nothing legitimate gets blocked when the policy tightens.

B

SPF, DKIM and DMARC records

A correct SPF record within the lookup limit, DKIM keys for each sender and a DMARC record that starts in monitoring mode. Alignment is checked so the visible From domain matches the authenticated one.

C

Staged move to p=reject

We move from p=none to quarantine to reject in steps, reading the reports at each stage. Spoofed mail gets refused while real mail keeps flowing.

D

Bulk-sender requirements

One-click unsubscribe headers, a working unsubscribe link, TLS, valid reverse DNS on any mail servers you run, and spam-rate checks in Google Postmaster Tools.

E

CASL-ready consent capture

Sign-up forms that record consent, identify your business and make unsubscribing easy, as Canada's anti-spam law expects. Each consent record is stored with a date and a source.

F

Contact-form protection

Forms that cannot be abused to send email to arbitrary addresses, with rate limits and bot checks. Nobody should be able to use your website to send mail in your name.

G

Monthly monitoring

We read the DMARC aggregate reports, flag new or failing senders, watch blocklists and fix records when a vendor changes its setup.

How it ships

How a DMARC rollout runs.

We change DNS only after we know who sends your mail, and we tighten the policy in stages so a forgotten billing system never loses its invoices.

01

Check

We look up your current DNS records and any DMARC data and show you what is missing or misconfigured.

02

Inventory

With DMARC in monitoring mode, we collect reports for a few weeks and identify every legitimate sender.

03

Enforce

Each sender is authenticated and aligned, then the policy moves to quarantine and finally to p=reject.

04

Monitor

Monthly report reviews and alerts keep new tools and vendor changes from breaking delivery.

Frequently asked

Common questions.

Why are our emails going to spam?
Common technical causes are missing or broken SPF and DKIM, no DMARC record, a From domain that does not match the authenticated domain, or a high spam-complaint rate. Content and sending habits matter too. A DNS and message-header check usually shows the technical causes quickly, and those are the ones we fix.
What do Gmail, Yahoo and Microsoft require from senders?
Since February 1, 2024, Gmail has required all senders to use SPF or DKIM, and bulk senders, meaning those sending around 5,000 or more messages a day to Gmail addresses, to have SPF, DKIM, DMARC, an aligned From domain and one-click unsubscribe. Yahoo applies a similar framework, and Microsoft has introduced comparable requirements for high-volume senders to Outlook.com addresses. We set up your domain to meet these technical rules.
What is p=reject, and is it safe to switch on?
p=reject tells receiving servers to refuse mail that fails DMARC, which stops others from sending as your exact domain. It is safe once every legitimate sender is authenticated, which is why we move there in stages. Jumping straight to reject without that work is how invoices and password resets go missing.
Do we need DMARC if we only send a little email?
Yes. Even low-volume senders need SPF or DKIM to reach Gmail reliably. DMARC also protects your domain from being spoofed in phishing aimed at your customers, which has nothing to do with how much you send.
Does this make our email marketing CASL compliant?
We build the technical parts CASL relies on: consent capture with records, sender identification and a working unsubscribe. Whether your messages and consent basis meet CASL is a legal question. FIMM provides technical implementation and is not a law firm, so we give no legal advice; your lawyer should review your consent practices.
How much does DMARC setup cost?
Setup starts at $299 for one domain and covers the sender inventory, the DNS records and the staged move to p=reject. Monitoring is from $49 a month, month-to-month, and you can cancel anytime.
Will you need access to our DNS and email platforms?
Yes. We need to edit records at your DNS host and add DKIM keys in each sending platform. We work through a delegated user account where possible, and every change is logged so your team knows exactly what moved.

Let's build
something.

// A 30-minute call · one problem worth solving · a straight answer on fit

Request a DMARC check →