Schedule icon
Commands icon
Docker icon
If icon
SlackIncomingWebhook icon
Log icon

Verify SPF, DKIM, and DMARC Records

Check SPF, DMARC, and DKIM presence for your sending domain and alert Slack when records go missing.

Categories
CloudInfrastructureinfrastructure

Deliverability dies quietly when a TXT record gets edited or a DKIM selector rotates. This blueprint digs the apex for SPF, _dmarc for DMARC, and the DKIM selector record, alerting Slack when any is missing.

How it works

  1. check_records (io.kestra.plugin.scripts.shell.Commands on Alpine with bind-tools) queries TXT records and classifies them via the ::{"outputs": ...}:: protocol.
  2. gaps_found (io.kestra.plugin.core.flow.If) branches to alert_gaps or log_ok.
  3. The errors block alerts on lookup failure.
  4. Trigger: a disabled weekly Schedule.

What you get

  • Per-record health for your domain.
  • Early warning before mail starts bouncing.

Who it's for

  • Teams that send transactional or marketing email.
  • Anyone who has ever debugged "why did spam score explode".

Why orchestrate this with Kestra

dig prints TXT records; the flow proves the three that matter are there, on a schedule, with alerts. The next step (auto-fix via DNS API, ticket, fail the weekly digest) is one task away.

Prerequisites

  • Docker available on the Kestra Worker.
  • A Slack webhook.

Secrets

  • SLACK_WEBHOOK_URL: webhook for gap and failure alerts.

Quick start

  1. Add the Slack webhook secret.
  2. Set domain and dkim_selector.
  3. Run once and read records_status.
  4. Enable the weekly schedule.

How to extend

  • Check MX and PTR (reverse DNS) too.
  • Alert on DMARC policy weakening (p=none).
  • Loop over several domains with a ForEach.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.