Stampwing — DNS troubleshooting worksheet
This is a read-only diagnostic. Do not publish fixture records.

Sending provider and region:
Visible From domain:
Envelope sender / Return-Path domain:
Provider's exact expected record name/type/value:
Cloudflare zone and current nameservers:
DKIM selector:
TTL before the change:
UTC check time and recursive resolver used:
Authoritative result:
Recursive result:
Trusted receiving system's Authentication-Results:
Last confirmed fact:
Next check and owner:

Optional read-only commands (replace placeholders with your real values):
dig NS example.com
dig TXT bounce.example.com
dig CNAME selector._domainkey.example.com
dig TXT selector._domainkey.example.com
dig TXT _dmarc.example.com
dig @authoritative-nameserver.example TXT _dmarc.example.com

SPF applies to the envelope sender, which can be a subdomain. Do not add a
second SPF record. Check provider requirements before merging mechanisms.
CNAME delegation may be correct for DKIM; use DNS only, not Cloudflare proxy.
A published record is not proof of authentication or DMARC alignment.
Negative DNS caching can persist after a missing record has been added.
Do not change DMARC to reject until you have reviewed legitimate senders.
