Fictional composite example • public DNS only • no account access

Sample DNS & Email Launch Snapshot for Example SaaS

A one-page pre-launch check of the public domain surface: nameservers, apex/www behavior, HTTPS redirects, MX, SPF/DMARC presence, TTL risk, and rollback readiness. This is not a security audit or deliverability guarantee.

Executive verdict

12/20

Soft-launch acceptable, migration needs owner verification.

The homepage resolves over HTTPS and email routing is present, but DMARC is missing and SPF has multiple include chains that should be verified against actual transactional and founder-outreach providers before paid traffic or a DNS migration.

Apex/www checkHTTPS redirect chainMX/SPF/DMARCTTL riskRollback plan

Commercial package

Free mini snapshotpublic-only, no-login
A$99 standaloneone domain report
A$149 Launch Readinessincluded with MVP review
A$299 migration packsnapshot + checklist + rollback plan

What looks OK

Homepage resolves over HTTPS

The public website responds on HTTPS and the canonical page is reachable without logging into hosting or DNS providers.

MX provider appears consistent

Public MX records point to one expected mail provider. No obvious duplicate mail providers are visible from this fictional snapshot.

Apex → www redirect works, but needs owner note

The canonical domain is understandable from the browser path, but the DNS owner should document whether apex or www is the long-term source of truth before a launch-day migration.

Fix before public launch

DMARC missing or not visible

Add a deliberate _dmarc record, starting with an owner-approved monitoring policy if the email stack is still being verified.

SPF is present but complex

Verify the include chain against every actual sender: transactional email, product notifications, CRM, and founder outreach. Remove providers that are no longer used.

TTL is mixed

Reduce high-risk records 24–48h before any provider migration, export the current DNS zone, and define a 15-minute rollback path.

10-point scorecard

Nameserver clarity1/2
Apex/www consistency1/2
HTTPS redirect chain2/2
MX records2/2
SPF presence1/2
DKIM discoverability1/2
DMARC presence0/2
TTL migration readiness1/2
Legacy record hygiene2/2
Launch rollback readiness1/2

Recommended next step

Export → verify → migrate, not the reverse

Before launch day: export current DNS, confirm all email senders, add DMARC intentionally, reduce risky TTLs, and write a rollback owner + rollback window. No live DNS change should happen from a free public snapshot.

Boundary: this page is a fictional composite example. It makes no claim about any real domain, customer, provider, or deliverability outcome.