Agent skill
domain-health
When the user wants to check email deliverability posture, domain authentication, or sending reputation for a domain.
Filed under Outbound email.
From realjaymes/marketingagentskills · 26 skill entries · 64 · pushed 2026-10-05
What it does when it runs
When the user wants to check email deliverability posture, domain authentication, or sending reputation for a domain. Use when the user mentions "domain health," "inbox health," "deliverability," "SPF," "DKIM," "DMARC," "email authentication," "are my emails landing in spam," "can I send from this domain," "is my domain spoofable," "warm up a domain," "check this sending domain," "DMARC rollout," "p=quarantine," "p=reject," "blacklisted," or "email going to spam." Also use before starting cold outbound from any domain, and to score prospect domains for deliverability gaps worth opening a cold email with. For writing the outbound emails themselves, see cold-email. For building the prospect list, see clay-gtm-outbound.
Automated analysis of the skill and the 6 files bundled beside it. A skill’s own description is written to be selected by an agent, so it describes the job and not the dependencies.
- Keys and connectors you must supply
- None found.
- Hosts it reaches
- No third-party host appears in the skill or its bundled files.
- Tool permissions it declares
- No
allowed-toolsin the frontmatter. It does act, so it runs under whatever permissions your session already grants. - Actions present in the files
- shellwrites files
Install it
View source on GitHub ↗git clone --depth 1 --filter=blob:none --sparse https://github.com/realjaymes/marketingagentskills.git /tmp/marketingagentskills git -C /tmp/marketingagentskills sparse-checkout set "skills/domain-health" mkdir -p ~/.claude/skills/domain-health cp -R "/tmp/marketingagentskills/skills/domain-health/." ~/.claude/skills/domain-health/
Picked up without a restart. A project skill of the same name is shadowed by your personal one. For one repository only, swap ~/.claude/skills for .claude/skills. Claude Code docs ↗
The folder is the same in every client that implements the format — 46 of them — so if yours is not above, only the destination changes.
The skill
Source on GitHub ↗Reproduced in full from realjaymes/marketingagentskills/blob/9fa1da4bb219223c504cae8315a85d28583ff0a7/skills/domain-health/SKILL.md, which is licensed MIT (repository). 792 words, 10 headings.
Domain Health
Email authentication and deliverability posture for any domain, using only dig and the standard library. No API key, no paid tool, no per-check cost.
The same DNS primitives serve two opposite jobs, which is why they live in one skill:
Defensive. Audit a domain you own before you send from it, and before you tighten a DMARC policy. Getting this wrong silently sends your own invoices and password resets to spam.
Offensive. Score a prospect's domain to find a real, specific gap worth opening a cold email with.
When to run it
Before starting outbound from any domain. Before changing a DMARC policy. When email is landing in spam and nobody knows why. When enriching a prospect list with a technical hook. After adding any new sending tool, because that is when sender inventory drifts.
Modes
Audit (default) runs against domains you own.
python3 scripts/domain_health.py --domain example.com
python3 scripts/domain_health.py --domain example.com --json
python3 scripts/domain_health.py domains.txt
Prospect produces a CSV for list enrichment, with a gap column that is true when the domain's DMARC is missing or monitoring-only.
python3 scripts/domain_health.py --mode prospect domains.txt > signals.csv
Blacklist is opt-in via --blacklist. See the warning below before using it.
Mailbox verification is separate, in scripts/verify_email.py. It does MX plus an SMTP probe for a single address. Most networks block outbound port 25, in which case it returns unknown rather than guessing.
What it checks
MX, establishing who receives mail for the domain.
SPF, including whether more than one record exists (which is a PermError and means SPF fails entirely), the qualifier the record ends in, and the count of DNS-lookup-triggering mechanisms against the limit of ten. Exceeding ten is a common and invisible failure.
DKIM, by sweeping a maintained list of per-provider selectors in scripts/selectors.json.
DMARC, covering policy, the separate subdomain policy, percentage, reporting addresses, and whether those reports go somewhere a human will actually read.
Sender inventory, which is the check that matters most and the reason this skill exists. It reads apex verification tokens and sending-subdomain CNAMEs to infer which providers are attached to the domain, then cross-checks each against SPF. This catches a provider verified two years ago, still able to send, never added to SPF, and invisible until the day the policy tightens.
Maturity signals, meaning MTA-STS, TLS-RPT and BIMI.
Honesty constraints
These are load-bearing. Do not relax them, and do not let output phrasing drift past them.
DKIM absence is never claimed. Selectors are arbitrary strings and some providers use per-account random ones that cannot be guessed. A sweep that finds nothing means "no key on the selectors tried."
Verification tokens prove a relationship, not sending. A token proves the domain was verified with a provider at some point. Treat every inferred sender as a lead to confirm, never a fact. The tool separates mail-relevant signals from non-mail ones (site verification, custom web domains) precisely so the gap list stays worth reading.
A prospect's primary domain is a proxy. Teams running cold outbound properly send from a separate domain to protect the primary. Never state a finding about a prospect's primary domain as a confirmed claim about their outbound.
Blacklist results describe the provider. For any domain on hosted email, the MX addresses belong to the provider, so a listing reflects their shared infrastructure, not this domain's reputation. This is why the check is gated behind a flag and labelled in the output. Do not report it as the domain's own reputation.
The DMARC rollout
Never raise a DMARC policy without first completing a sender inventory and reading real aggregate reports. The staged sequence, including how to make reports readable and what to fix before each step, is in references/dmarc-rollout.md.
The short version: make reports readable, wait and read them, fix every legitimate sender that is failing, then tighten policy one step at a time. The cost of waiting a month is zero. The cost of guessing wrong is business mail silently going to spam.
Remediation
Per-provider fixes for each failure mode, covering the records to add and where to find them in each provider's dashboard, are in references/remediation.md.
Turning gaps into outbound
How to convert a prospect's missing or monitoring-only DMARC into a specific, non-generic cold email opener, and the framing rules that keep it honest, are in references/prospect-scoring.md.
Scoring
The audit returns a 0 to 100 readiness score weighted toward what actually blocks a rollout. Treat it as a triage signal for comparing domains, not a precise measurement. The numbered findings beneath it are the real output.
Related skills
cold-email for writing the outbound itself. clay-gtm-outbound for building and enriching the prospect list. seo-audit for the equivalent audit on the web side.
Files bundled with it
These load only when the skill asks for them, so they cost nothing until it runs.
Other skills for the same job
Different authors, same problem. Matched on the words in the skill name, across every library in the catalogue except this one.
- zapmail-domain-setup-public by growthenginenowoslawski · 739
- domain-research by OpenClaudia · 708
- domain-expired-opportunity-finder by Varnan-Tech · 672
- 05-pipeline-health-analyzer by SimonTheSalesBooster · 39
- content-health by jbalbu01 · 17
- zapmail-domain-setup-public by timyakubson · 3
- client-health-review by b2bforce · 2
- gtm-graph-health by rvanshur · 2
Need help setting it up?
This page tells you what domain-health does and what it needs. Cheetah builds the agent setup it runs inside: data, CRM, sequencing and the guardrails.
Book a call →The directory stays free. There is nothing gated behind this.