
Philippe Namias
I run the audit. There is no team behind this page — you are buying a few hours of one person's attention, and that person is me.
I run my own production mail infrastructure: OpenSMTPD and Stalwart Mail Server, Dovecot, rspamd, self-hosted for years. That is where the audit comes from. I debug deliverability at the protocol level rather than in a vendor dashboard, because the dashboard is downstream of the thing that is actually wrong.
Why the free scanners weren't enough
The last hard one took a week. Gmail was dropping my mail on and off, with no pattern I could see. SPF passed. DKIM passed. DMARC passed. Every free checker I fed the domain to came back green.
OVH had put an IPv6 address on the interface with no PTR behind it. Mail that happened to take the IPv6 path was arriving from an address with no reverse DNS; mail on IPv4 was fine. The scanners only tested the IPv4 path, so they reported a clean bill on a domain that was quietly losing mail.
That is the shape of most real deliverability problems: not a missing record, but a record that is right in the place everyone looks and wrong somewhere else. A checker tells you what it tested. It does not tell you what it didn't.
Which stack you run barely matters
The audit is stack-agnostic: Postfix, Exim, OpenSMTPD, Stalwart, haraka, or a managed stack like Google Workspace, Microsoft 365, SES or Postmark. The protocols are the same in all of them, and the protocols are what I read. Self-hosted setups are most of the hard cases, which is the direction the experience runs.
What else I'm building
StrictMX is becoming a mail transport security monitoring tool — MTA-STS, TLS-RPT, DANE and certificate changes, watched over time rather than checked once. The inbound checks in this audit come from that work. The audit funds it and keeps it honest: a monitoring tool built by someone who does not read other people's broken mail setups drifts towards checking what is easy to check.
Check my own domain
A reasonable thing to ask of someone selling a mail audit is what their own domain looks like. This one is signed with DNSSEC and publishes DANE records for its mail server, on top of the SPF, DKIM and DMARC you expect — the DKIM keys are RSA and Ed25519 both. Run whatever checker you like against it.
You will not find it perfect, and I would rather say which part than have you find it. Anything a checker flags here is either something I have decided against on purpose or something on the list, and if you ask me about it before you buy I will tell you which. That is the same answer your report will give about your domain: what is wrong, what it costs, and what is genuinely fine to leave alone.
Where I am
Based in the EU, trading as Rapid Ventures OÜ — the full details are on the imprint. Intake data is used only for the audit and deleted on request; the privacy notice says exactly what is kept and for how long.
Report by email within 48 hours of your intake. No account, no call.
Not sure it covers your setup? Ask before you buy: audit@strictmx.com