DIAGNOSTIC PLAYBOOK

Retire an email vendor without leaving stale authorization

Retiring a vendor means confirming that no live mail stream still depends on its credentials or DNS records. Remove authorization and delegated signing only after identifying those dependencies.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Check application settings, scheduled jobs and recent reports for continued use of the vendor.
  2. Move or stop the remaining streams and verify the replacement configuration.
  3. Remove confirmed obsolete authorization and selector delegation, and record the retirement date.

What this looks like

ILLUSTRATIVE EXAMPLE

A marketing contract ends, but a monthly invoice job still uses the same platform. Traffic review identifies the delayed dependency before cleanup.

A mistake to avoid

Zero traffic during a short window does not prove a monthly or seasonal workflow is unused. Confirm with the business owner.

Keep the result in context

A monitoring routine needs an owner, a baseline and a response to a meaningful change. Keep the sender inventory and approved DNS configuration alongside incident notes. HealthCheck Email supplies checks, history and supported alerts; publishing DNS changes and administering mail systems remain with your team.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.