DIAGNOSTIC PLAYBOOK
Create an evidence pack for an email incident
An evidence pack helps a mail provider investigate without a long sequence of vague requests. Include reproducible identifiers, times and results while limiting unnecessary message content.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Capture the sending service, affected domain, UTC timestamps and safe message or queue identifiers.
- Add exact SMTP replies, relevant trusted authentication results and current DNS answers.
- Describe the expected behavior, actual scope and changes near the incident, then share through the authorized support channel.
What this looks like
ILLUSTRATIVE EXAMPLE
A report saying email is broken becomes a precise case: one stream, one receiver, three message IDs and the same rejection over a defined interval.
A mistake to avoid
Redact private content, tokens and unrelated recipient data. More raw information is not always more useful evidence.
Keep the result in context
A monitoring routine needs an owner, a baseline and a response to a meaningful change. Keep the sender inventory and approved DNS configuration alongside incident notes. HealthCheck Email supplies checks, history and supported alerts; publishing DNS changes and administering mail systems remain with your team.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.