All templates

Automated SendGrid Sender Authentication Audit

Every Monday, WebRun opens SendGrid, checks each authenticated domain and its DNS records, verifies link branding, lists sender identities that are unverified or unused, matches them against where mail is actually going out from, emails you the failures, and books a fix window in Google Calendar.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 SendGrid audit domains and senders
2 Gmail email the fix list
3 Google Calendar book the fix window
In short

How do I check my email sending domains are still authenticated?

WebRun audits your SendGrid setup every Monday, checking each authenticated domain's DNS records, its link branding, and every sender identity's verified state. It emails the failures ranked by sending volume through Gmail and books a fix window in Google Calendar, so a broken record is fixed before the next bounce spike.

  • A broken DNS record is caught before it becomes a bounce spike
  • Failures are ranked by the sending volume behind them
  • A fix window is booked only in the weeks something actually failed

Built for email marketers · deliverability managers · growth teams · platform engineers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens app.sendgrid.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    SendGrid - audit domains and senders
    sendgrid.com
    WebRun in SendGrid: audit domains and senders
    WebRun opens SendGrid to audit domains and senders.
    • Open SendGrid and list every authenticated domain with the DNS records it depends on
    • Check each record's verified state and note any that have stopped resolving since last week
    • Check link branding on each domain and flag anything not verified
    • List the sender identities on the account and mark the ones still unverified
    • Compare the sending activity against those domains and identities, so a domain carrying real volume with a broken record is flagged first
    • Note any API key that has not been used in months, so unused access can be reviewed
    • Read only. WebRun never edits DNS, deletes a key, or changes a sender identity

    Done when Every domain, record, and sender identity has a verified state and the failures are ranked by sending volume.

  3. 2
    Gmail - email the fix list
    gmail.com
    WebRun in Gmail: email the fix list
    WebRun opens Gmail to email the fix list.
    • Draft the audit email to whoever owns deliverability, listing failures before anything else
    • Name each broken record with its domain and what the record should look like
    • List unverified sender identities and the volume each one is sending
    • Put a short all clear section at the end for the domains that passed
    • Send it to your own team only. Nothing goes to a subscriber or an outside party

    Done when The deliverability owner has this week's audit email with failures listed first.

  4. 3
    Google Calendar - book the fix window
    calendar.google.com
    WebRun in Google Calendar: book the fix window
    WebRun opens Google Calendar to book the fix window.
    • Book a short fix window in Google Calendar for the week whenever the audit found a failure
    • Put the failing domains and records in the event description, so the work starts without a hunt
    • Skip the booking entirely on a week where everything passes
    • Invite only your own team. WebRun never adds an outside guest to an event

    Done when A fix window is on the calendar for any week with failures, carrying the details.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
app.sendgrid.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Authentication audit · Gmail
OutputWhat each run produces - A weekly authentication audit: each domain's DNS records, link branding, and sender identities, with failures ranked by sending volume.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change DNS records or delete an API key?

No. WebRun reads the verified state of your domains, records, and sender identities and reports what is broken. Editing DNS, rotating a key, or removing an identity stays with your team.

Does it email anyone outside the team?

No. The audit email goes to the deliverability owner you name, and calendar invites include only your own team. Nothing reaches a subscriber or a vendor.

How does it decide what to fix first?

It ranks failures by the sending volume behind them, so a broken record on a domain carrying your main campaigns sits above an unverified identity that sends nothing.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.