Email authentication
Email sending source
An email sending source is a customer-maintained record of a system allowed or expected to send mail for a domain.
Updated 24 July 2026
What it means
An email sending source is a record of a platform, application, service, or workflow that sends email using a monitored domain. Examples might include a helpdesk, newsletter tool, CRM, ecommerce platform, billing system, or custom application. The record explains what the source is, who owns it, how it sends, and how SPF, DKIM, and DMARC alignment are judged by the customer.
Why it matters
Email authentication checks can show public DNS records, but they do not always explain why a sender exists or who should maintain it. A sending-source register helps teams avoid forgotten mail systems, unclear owners, and alignment assumptions that live only in one person's head.
How CertPilot uses the term
CertPilot's Email Sending Source Register is customer-entered metadata. It does not scan mailboxes, read message headers, send email, configure SPF/DKIM/DMARC, guarantee deliverability, or connect to Microsoft 365 or Google Workspace. It supports review context beside public email-authentication DNS checks.
What to record
- Source name, type, sending method, and owner.
- Customer-judged SPF, DKIM, and DMARC alignment status.
- Notes explaining purpose and review context.
- Last reviewed date.
What not to assume
- A sending-source record is not mailbox scanning.
- Customer-entered alignment context does not configure DNS.
- The register does not guarantee deliverability.
How to use this term in a review
Use Email sending source when you need a shared operating definition in a management report, access review, renewal review, domain review, or evidence-pack discussion. The goal is not to turn a glossary term into a control by itself. The goal is to make the scope, source, owner, status, date, and follow-up clear enough that a manager or client can understand what was reviewed and what still needs attention.
- Use the related pages to move from definition to workflow.
- Keep evidence wording precise and avoid audit, legal, or certification overclaims.
- Record limitations when the source is public, manual, customer-entered, or incomplete.