AlignedMail
Harbourway Group Ltd · 17093218
For recruitment agencies

Your CRM sends the mail. Nothing tells you it arrived.

Bullhorn, JobDiva, Loxo and the rest send on your behalf, using your name. Whether a receiving system accepts that is decided by records on your domain, and almost nobody checks them.

Send me your domain
Free. You get the answer either way, including when it is fine.
314
UK and US recruitment agency domains checked, September 2026
72
carry a fault that stops them proving their mail is genuinely theirs
47
of those 72 have no reporting at all, so they cannot find out
Checked from public DNS on 20 September 2026. "Fault" means no SPF record, an SPF that fails to evaluate, several SPF records at once, or DKIM signing not enabled. Every one is reproducible with a single lookup.

You already have the symptom

A candidate does not reply. A hiring manager goes quiet. You log it as a slow market, a flaky candidate, a client going cold.

Some of that is exactly what it looks like. Some of it is mail that never arrived, and there is no way to tell the two apart from where you sit. No bounce comes back. Nothing appears in a log. The only record of what happened sits with the receiving system, and unless your domain asks for it to be sent to you, it is discarded.

Your recruiters' own mail keeps working throughout, because it goes out on a different path. That is the part that makes this hard to notice. The stream that fails is the automated one: interview confirmations, application responses, everything your CRM sends with your name on it.

Email authentication is the only part of an IT estate that fails silently. A broken website is obvious in a minute. This can be wrong for years.

What I actually do

  1. Turn the reporting onWithin about 48 hours you see every system sending as you, and how much of it is accepted. Most agencies have never seen this and find senders they had forgotten about.
  2. Authorise every legitimate senderOne SPF list inside the ten-lookup limit, and a signing key for each system, so your CRM's mail can prove it is really yours.
  3. Raise enforcement in stagesMonitor, then a quarter, then half, then everything. Watched at each step and reversible in minutes. Nothing goes to enforcement until the reports say it is safe.
  4. Keep reading the reportsNew systems get added and suppliers change. The reports are the only place that shows up, and they only help if a person reads them.

What it looks like

Two things from the screen. One is a domain that publishes three lists where the standard allows one. The other is why that fault shows up as candidates who did not turn up, rather than as an email problem.

$ dig +short TXT anagency.co.uk | grep spf1
"v=spf1 a mx include:_spf.elasticemail.com ~all"
"v=spf1 include:_spf.bullhornmail.com ~all"
"v=spf1 include:spf.protection.outlook.com -all"
A real agency domain from the 314, anonymised. Three lists where the standard allows one, so every receiving system discards all three. The middle line is the one authorising their CRM to send candidate mail. It does nothing.
yourfirm.com one domain Recruiters' mailbox Microsoft 365 or Google noticed Your CRM, as you interview confirmations not noticed both streams are judged by the same records on your domain
Two paths out of one domain. Only the top one has anybody watching it, which is why a fault in the records shows up as candidates who did not turn up rather than as an email problem.

What this does not do

It stops mail being sent from your exact domain. It does nothing about a lookalike domain, a WhatsApp message using a recruiter's name, or a fake advert posted somewhere with your branding on it. Every documented case of a UK agency being impersonated that I could find used one of those routes, not the domain. Anyone selling you this as fraud protection is overstating it.

It will not make a weak email get replies. If your mail is arriving and nobody is answering, this is not your problem and I will tell you so.

I cannot tell from outside whether your mail is currently landing in junk. Nobody can. What I can tell you, before you pay anything, is exactly what your domain publishes and whether it works.


Who I am

Byron Coke
Byron Coke
Harbourway Group Ltd

More than 3 decades working as a Unix/Linux and infrastructure engineer, including building the call centre systems that took a UK answering service from nothing to over 5,000 calls a day.

I found this on my own domain first. I switched reporting on, and the first report showed somebody forging it from a host with no reverse DNS that is listed on Spamhaus. Three messages, and the policy at the time told every receiving system to do nothing about it. I do this work for a living and I could not see it until I looked.

£1,900 One domain, up to three sending systems. Six to eight weeks.
£950 for the first three clients, in exchange for a named case study.
Reading the reports afterwards is £295 a month, and optional.
Send me your domain

You get the check whether or not you ever buy anything. Of the 314 I have looked at, 242 were fine and were told so.