Skip to content

Sender Domain Health ​

New in v6.0.1

The Sender Domain Health report in the admin area lists every sender domain across all user accounts, with the result of its last DNS check. Use it to find domains whose DNS records stopped matching, domains that were demoted for it, and domains that wait for approval. You can open each domain's per-record results and run a new check on demand.

Opening the Report ​

Navigate to Reports > Sender Domain Health in the admin area.

The menu entry appears only for administrators with permission to edit users. An administrator who is limited to some user groups sees only the domains of accounts in those groups. Deleted domains are not listed.

The admin Overview page also shows a Sender Domain Health tab with four counts: Healthy, Failing, Demoted by DNS drift and Never checked. Click a count to open the report filtered to it. The tab appears when there is at least one sender domain.

How Domains Are Checked ​

Octeth checks each Enabled domain in the background once a day. A check looks up every DNS record the domain was given when it was created and compares the answer with the expected value.

Three failed checks in a row move the domain to Approval Pending, and it can no longer send. This is called DNS drift. A domain owner can also run a check from the domain's edit page.

Summary Tiles ​

Five tiles at the top count the domains in each health class. Click a tile to filter the list to that class.

TileWhat it counts
HealthyEnabled domains whose last check passed every record, with no failed checks pending.
FailingEnabled domains that failed one or two checks in a row, or whose last check had a failed record. They can still send.
Demoted by DNS driftDomains that were Enabled and moved to Approval Pending because a check failed.
Awaiting approvalOther Approval Pending domains: new domains not verified yet, domains whose subdomain settings changed, and domains an administrator sent back for approval.
Never checkedDomains with no stored DNS check yet.

Domains in Disabled, Suspended or Blocked status that have a stored check are not counted in any tile. Choose Other in the health filter to list them.

Filtering the List ​

Use the toolbar above the list:

  • Domain... matches part of the domain name.
  • User ID shows the domains of one account.
  • The health filter (All Health) limits the list to one health class.
  • The status filter (All Statuses) limits the list to Enabled, Disabled, Suspended, Approval Pending or Blocked.

Click Filter to apply, or Clear to remove every filter. The list shows 50 domains per page.

Reading a Row ​

ColumnWhat it shows
DomainThe domain name and its actions.
AccountThe owner's username and email address. Click it to open the account's Sender Domains tab.
StatusThe domain's status. A demoted domain also shows DNS drift under APPROVAL PENDING.
HealthThe health label, described below.
Last checkedWhen the last check ran and what started it: Scheduled check (background), Manual check (the owner) or Admin check (Re-check now).
FailingHow many records failed the last check.

The Health column uses these labels:

LabelMeaning
HealthyEnabled, and the last check passed.
Failing 1/3 or Failing 2/3Enabled, and that many background checks failed in a row. The third failure demotes the domain.
Last check failedThe last check failed. For an enabled domain this is a failed Re-check now, which does not count toward the three.
Demoted by DNS driftDemoted, and the records still do not match.
Passing, awaiting approvalDemoted, but the last check passed.
Awaiting approvalApproval Pending for any other reason.
Never checkedNo stored check.
Last check passedDisabled, Suspended or Blocked, and the last check passed.

Per-Record Results ​

Click Records under a domain name to show the result of its last check, one row per DNS record:

ColumnWhat it shows
TypeThe record type, for example CNAME or TXT.
HostThe host name that was looked up.
ExpectedThe value the record should have.
ResolvedThe value the DNS server returned, or No answer when nothing was found.
ResultPass when the resolved value equals the expected one (letter case is ignored), Fail otherwise.

The records are the ones the domain received from its DNS template when it was created, typically the return-path, DKIM, DMARC and tracking CNAMEs plus an ownership TXT record. Octeth does not evaluate SPF, DKIM or DMARC policies. It checks that each record matches. The lookups use the DNS servers set in config/global/const_OEMPRO_DNS_LOOKUP_SERVERS.php.

Why a Domain Waits for Approval ​

A domain that cannot send while waiting for someone falls into one of these cases:

  • Awaiting approval (status Approval Pending): the owner has not verified the DNS records yet, changed the subdomain settings, or an administrator clicked Unblock on a suspended domain. The owner adds or fixes the records and verifies the domain.
  • Demoted by DNS drift (status Approval Pending, DNS drift): the records stopped matching. The owner fixes them and verifies the domain again. Background checks do not restore it.
  • Blocked: the domain passed verification, but the owner's user group has Require new domain approval before email sending is allowed turned on. An administrator blocking an enabled domain also gives this status. Filter by the Blocked status to find these domains, then click Approve or block and click Activate on the account's Sender Domains tab.

When the owner verifies a demoted domain and every record passes, it becomes Enabled again. If the owner's user group requires approval, it becomes Blocked and waits for you to activate it.

Re-checking a Domain ​

Click Re-check now under a domain to check its DNS records right away. The report shows A DNS check of mail.example.com is queued. Reload this page in a minute to see the result. Reload the page to see the new result, labeled Admin check.

A re-check:

  • Records the result and never changes the domain's status.
  • Never counts as a failed check toward the three that demote a domain.
  • Clears the failed-check count of an Enabled domain when every record passes.
  • Runs even if the domain was already checked today, and counts as that day's background check.

Re-check now is available for Enabled, Approval Pending, Blocked and Suspended domains, not for Disabled ones. There is no limit on how often you can use it.

To approve, suspend or block a domain, click Approve or block under its name. This opens the owner's Sender Domains tab.

Any questions? Contact us.