SPF DKIM and DMARC API Notes
How email authentication records should be read and verified from API clients.
How email authentication records should be read and verified from API clients.
Coverage
| Item | Status |
|---|---|
| SPF TXT record visibility | Use deployed route documentation |
| DKIM selector visibility | Use deployed route documentation |
| DMARC policy visibility | Use deployed route documentation |
| DNS propagation checks | Use deployed route documentation |
Workflow
- Confirm each route against the deployed route documentation.
- Test with a staging token first.
- Use read endpoints to inspect current state before any write operation.
- Record the external workflow ID in your own system.
- Review jobs, request logs, and audit logs after the workflow runs.
Notes
- Do not create production automation around undocumented routes.
- Use idempotency keys for write endpoints.
- Keep rollback steps documented with the integration runbook.
Diagram
flowchart TD
A[External System] --> B[Read Current State]
B --> C{Expected State?}
C -- No --> D[Stop and Alert]
C -- Yes --> E[Run Approved Workflow]
E --> F[Read Jobs and Logs]
F --> G[Operator Review]