Forward and reverse identity
Confirm the sending IP, PTR, HELO/EHLO hostname and forward DNS agree. Use FCrDNS where appropriate and keep shared/customer and control-plane sending identities separate.
Reputation tools
Public blocklists are only one part of deliverability. Check server identity, authentication, behaviour, receiver feedback and list-specific evidence separately.
Confirm the sending IP, PTR, HELO/EHLO hostname and forward DNS agree. Use FCrDNS where appropriate and keep shared/customer and control-plane sending identities separate.
Verify the actual sending path passes authentication and aligns with the visible From domain. Passing authentication is necessary groundwork, not an inbox guarantee.
Check reliable SMTP transport, STARTTLS where offered, valid certificates and stable sending hostnames before attributing failures to reputation.
Check multiple providers and distinguish individual-IP findings from network or ASN collateral. Record provider reason and timestamp rather than a generic red/green score.
Use mailbox-provider postmaster, complaint and sender-feedback programs when available. Private provider reputation can matter even when every public DNSBL is clear.
Review sudden volume changes, compromised accounts, web-form abuse, bounces, complaint rates, list quality and retry patterns. Reputation problems often start with behaviour, not DNS.
Separate recipient rejection, temporary deferral, spam placement and authentication failures. Save provider response codes and message IDs when escalating.
Stop abuse, patch compromised systems, rotate credentials, fix identity and reduce bad traffic first. Then follow the specific provider's ordinary removal or appeal process.
Useful next checks: blacklist/reputation, FCrDNS, SPF, DKIM, DMARC, and SMTP STARTTLS.