# Web3 Email Authentication Operations Kit - Free Sample

Version: 1.0.0 sample
Format: Markdown
License: You may share this sample. The complete kit is licensed for internal use by one purchasing organization.

## What this sample helps you do

Use these three worksheets to stop treating email authentication as a single DNS record. They separate each message stream, capture receiver evidence, and make rollback ownership explicit before a DMARC change.

The complete kit also includes DMARC enforcement gates, a 15-question vendor review, a critical-message control matrix, suspicious-email triage, an incident runbook, a weekly scorecard, ticket templates, a quarterly review, and completion criteria.

## 1. Thirty-minute kickoff

1. Name one accountable owner for the visible From domain.
2. List every system allowed to send mail using that domain or a subdomain.
3. Mark the messages that can lock a user out, move funds, or change security posture.
4. Capture one recently delivered header from every active message stream.
5. Record the aligned DKIM signing domain and SPF MailFrom domain from the final receiver's Authentication-Results field.
6. Freeze DMARC enforcement changes until unknown senders and failover paths are classified.
7. Define rollback ownership and the previous known-good DNS value before any change.

Do not treat a vendor dashboard, a successful API response, or SMTP submission as receiver evidence.

## 2. Sender inventory starter

Create one row per distinct message stream, not merely one row per vendor.

```csv
stream_id,business_purpose,criticality,visible_from_domain,provider,environment,return_path_domain,dkim_domain,dkim_selector,spf_aligned,dkim_aligned,last_header_date,failover_path,owner,status,notes
auth-login,Login links,critical,example.com,Provider A,production,bounce.example.com,example.com,s1,yes,yes,2026-07-01,Provider B,Identity Team,active,
wallet-alert,Wallet security alerts,critical,alerts.example.com,Provider B,production,bounces.vendor.example,alerts.example.com,w1,no,yes,2026-07-02,None,Security Ops,active,
newsletter,Newsletter,standard,news.example.com,Provider C,production,mail.vendor.example,vendor.example,no,no,no,2026-06-20,None,Growth,needs-remediation,DKIM is not aligned
```

Recommended status values:

- `active`: evidence is current and the stream is intentionally authorized.
- `needs-remediation`: the stream is required but alignment or ownership is incomplete.
- `unknown`: the source appeared in telemetry and has not been attributed.
- `retired`: sending is disabled and a removal date is recorded.
- `failover-only`: a tested standby route that is not normally active.

## 3. DNS change worksheet

```text
Change ID:
Requested by:
Approved by:
Domain:
Record owner:
Record type and host:
Current exact value:
Proposed exact value:
Current TTL:
Planned TTL:
Reason:
Streams affected:
Pre-change evidence links:
Validation queries:
Receiver-header validation plan:
Monitoring start and end:
Rollback trigger:
Rollback exact value:
Rollback operator:
Post-change evidence links:
```

Never put a seed phrase, private key, mailbox password, API secret, or wallet signature in this worksheet.

## Decision checkpoint

Do not move DMARC from monitoring to enforcement until every critical stream has an accountable owner, an aligned path observed at a final receiver, a tested failover where required, and a literal rollback value.

The full Web3 Email Authentication Operations Kit is delivered as a SHA-256-verified Markdown file after an encrypted, accountless order and payment at the launch price of exactly 1 native USDC on Base Mainnet.
