Deliverability
Deliverability is a workspace-wide readiness view, separate from the per-campaign pre-send preflight shown inside Campaign Builder. It has two tabs: Domain Health, a snapshot of your DNS setup and connected inboxes, and Tracking, where you configure a tracking subdomain for each sending domain.
On this page
Domain Health
The header shows an overall READY/WARNING/BLOCKED verdict badge next to the page title. Below it, a left panel (roughly 30% width) stacks four metric tiles, a Workspace checks panel, and a Domain health panel; the right panel is the Inbox readiness table.
Deliverability
WARNINGConnected inboxes
4
Domains checked
2
With capacity
3
Blockers / warnings
0 / 2
Workspace
Domain health
Expand allInbox readiness
4 inboxes · 1 with issues
DNS and authentication checks
Expanding a domain in the Domain health panel shows its four DNS checks in this order: MX, SPF, DKIM, DMARC.
meridian.co
meridian.co has 2 MX record(s).
meridian.co has an SPF record.
No DKIM record found for common selectors on meridian.co.
Confirm the correct DKIM selector from Google or Microsoft and publish the TXT record.
meridian.co has a DMARC policy.
DKIM is checked against six common selectors, in order — google, selector1, selector2, default, mail, dkim — and passes as soon as any one of them resolves a TXT record containing v=DKIM1. Missing MX, SPF, or DMARC blocks the domain; a missing DKIM record only warns, since ForgeSend can't know a non-standard selector your provider might use.
Inbox readiness
Every connected inbox appears as a row: provider chip, status dot, today's send usage, and OAuth token state. Rows are sorted worst-first — errors, then warnings, then ready inboxes.
Connected
Jun 12, 2026
Remaining today
0 sends
Last error
Reconnect required
Status shows as Ready, Warning, or Error — a blocked inbox reads "Error" here, not "Blocked." Token shows Valid, Error, or Password auth for SMTP/IMAP inboxes, which don't use OAuth tokens at all. Clicking a row expands it to show when it was connected, remaining sends today, and either the last error or the full provider name.
Tracking
The Tracking tab lets you give each sending domain its own tracking subdomain, so open and click links resolve through a hostname your recipients recognize instead of a shared ForgeSend host. This only takes effect once Track email opens and clicks is also turned on in Workspace settings — the two switches work together, not one or the other.
meridian.co
✓ Verifiedtrack.meridian.co
acme-aviation.com
Not verifiedNo tracking subdomain set
Clicking a card opens a modal where you set the subdomain prefix — you type just the prefix (like track or updates), and the domain is appended automatically.
acme-aviation.com
Not verifiedTracking subdomain prefix
Add a CNAME record for track.acme-aviation.com pointing to tracking.forgesend.cloud, then enable Cloudflare's proxy (orange cloud) on that record — Cloudflare handles TLS for your subdomain, ForgeSend doesn't need or manage a certificate for it. DNS changes can take a few minutes to propagate; click Verify once it's set up.
Verifying isn't a plain DNS lookup — it's a real HTTPS request to your subdomain's health endpoint. That's deliberate: once Cloudflare's proxy is on, public DNS no longer shows the real CNAME target, so a live request is the only way to confirm the whole chain — DNS, proxy, TLS, and reachability — actually works end to end.
There's no scheduled re-check once a subdomain is verified — verification only happens when you click Verify. If the CNAME changes or the proxy gets turned off later, ForgeSend won't detect it on its own; re-verify manually if you change your DNS setup.
If tracking is turned on workspace-wide but a particular sending domain has no verified subdomain, ForgeSend doesn't block sending for that domain — it falls back to its own shared tracking host for those emails instead.
Three verdict systems — don't mix them up
ForgeSend has three status vocabularies that all sound similar but measure different things:
| Where | Values | What it measures |
|---|---|---|
| Deliverability checks (this page) | PASS / WARNING / BLOCKED | Individual DNS, inbox, and workspace checks |
| Campaign launch verdict | READY / WARNING / BLOCKED | Whether a specific campaign can start, from preflight |
| Analytics health badge | Healthy / Watch / Risk | A sent campaign's actual bounce and send-failure rates |
A domain can PASS every check here while a specific campaign is still BLOCKED at launch for an unrelated reason (like having no active leads) — and a campaign that launched cleanly can still turn up Watch or Risk in Analytics once real sends start bouncing.
Where to go next
Next: Pre-send preflight