# Deliverability agent

> Couryo's deliverability agent checks SPF, DKIM, DMARC and return path live, domain block lists, bounces and complaints by mailbox provider, and sends the weekly "Your email health" summary.

Source: https://couryo.com/en/docs/deliverability

The deliverability agent watches every domain in the project and explains in plain words what is fine, what is at risk and how to fix it. In this version it **only reads and warns**: it does not change DNS, pause anything or touch your list.

## What it checks

| Item | How |
|---|---|
| **SPF, DKIM, DMARC and return path** | live DNS lookups: both DKIM selectors (`couryo1` and `couryo2`), the return path, DMARC (policy and duplicate records) and the main domain's SPF (two SPF records or `+all` raise a warning) |
| **Domain block lists** | Spamhaus DBL and SURBL, over DNS. When a list refuses the query, the result shows as "no answer", never as "clean" |
| **Bounces and complaints** | over the last 30 days, in total and by mailbox provider (Gmail, Microsoft, Yahoo, UOL, BOL, Terra, Locaweb and others), with a warning when one provider stands out |
| **Reputation** | the sending engine's reputation recommendations for your domain (DKIM, DMARC, SPF, bounces, complaints), translated |
| **Next DMARC step** | after 30 clean days, suggests moving from `p=none` to `p=quarantine`, then to `p=reject`, with the record ready to copy |

"30 clean days" means: domain verified and on its current policy for 30 days or more, DKIM and return path right, no block list, bounces up to 2% and complaints up to 0.1% over the last 30 days, and no account pause in that period. Before moving DMARC up, make sure every service that sends from your domain (company email, billing, CRM) signs with DKIM on your own domain: the policy applies to all of them.

Each domain gets **All good**, **Needs attention** or **Serious problem**, with the findings from most to least serious and how to fix each one.

## Where to see it

- **Dashboard:** the **Deliverability** screen shows the diagnosis of every domain in the project, with a **Check now** button; **Home** has the "Email health" card.
- **API:** `GET /v1/domains/{id}/health` (`read` scope).
- **MCP:** the `domain_health` tool returns the same diagnosis to your AI agent. See [MCP and agents](https://couryo.com/en/docs/mcp.md).
- **Email:** every Monday morning (Brasília time), the **"Your email health"** summary with each domain's status and the main points. To stop it, turn off **Weekly health** under **Settings > Notifications**.

The diagnosis is kept for 15 minutes; `?refresh=1` (or **Check now**) runs everything again.

```bash title="cURL"
curl "https://api.couryo.com/v1/domains/dom_7h2kq9w4x1abcdef/health?refresh=1" \
  -H "Authorization: Bearer $COURYO_API_KEY" \
  -H "Accept-Language: en"
```

```json title="Response (shortened)"
{
  "domain": "example.com",
  "status": "good",
  "summary": "example.com is all set: full authentication, no block list and 0.6% bounces in the last 30 days.",
  "authentication": {
    "spf": { "status": "ok", "detail": "..." },
    "dkim": { "status": "ok", "selectors": [{ "selector": "couryo1", "status": "ok" }, { "selector": "couryo2", "status": "ok" }], "detail": "..." },
    "dmarc": { "status": "warning", "policy": "none", "detail": "..." },
    "return_path": { "status": "ok", "detail": "..." }
  },
  "blocklists": [
    { "list": "spamhaus_dbl", "name": "Spamhaus DBL", "status": "clean", "detail": "Not listed." },
    { "list": "surbl", "name": "SURBL", "status": "clean", "detail": "Not listed." }
  ],
  "delivery": { "window_days": 30, "sent": 1840, "bounced": 11, "complained": 0, "bounce_rate": 0.006, "complaint_rate": 0, "by_provider": [] },
  "reputation": [],
  "dmarc_suggestion": {
    "current": "none",
    "next": "quarantine",
    "record": "v=DMARC1; p=quarantine; rua=mailto:dmarc@couryo.com; adkim=r; aspf=r",
    "clean_days": 34,
    "message": "..."
  },
  "findings": []
}
```

## What it does not do yet

- Act on its own (move DMARC up, pause a campaign, suppress a list): later, always with your permission.
- Read DMARC aggregate reports and Google Postmaster or Microsoft SNDS data: coming soon. Today the rates come from emails sent through Couryo.
- Alerts on Slack or WhatsApp: coming soon; today the summary arrives by email.
