Decay University · Part 7: The practitioner track
Lesson 64 of 64
Graduation: the competence checklist
Sixteen self-assessable checklist items decide whether you can charge for this work, plus the sources that keep the rules from decaying under you.
Last updated 19 July 2026
Finishing this course proves you read it. The sixteen claims below are what matter: each one is concrete and testable, and together they are the working definition of "competent enough to charge for deliverability work". If you can make every claim honestly, and the gauntlet from the last two lessons didn't wreck you, you are ready to take a paying client. Not certified; there is no certificate here, and I'd trust one honest claim off this list over most of the certificates sold in this industry anyway.
Self-assessment invites self-flattery, which is why the gauntlet came first. Your score there is the external evidence, and this checklist is the map of what that score means. An unchecked item is not a failure, either. Each claim carries the lesson numbers that taught it, so the honest response to "I can't actually do that" is a reread with your own domain open, not a shrug.
The competence checklist
Read each claim aloud and decide whether it is true of you today, with evidence you could show someone. "I read the lesson about it" is not evidence. "I did it last week on a real domain" is.
How email works
- You can narrate one email's journey from "send" to inbox, naming every hop and every gate, and say which record or score each gate consults. (If not: the opening lessons of Part 1.)
- You can explain the two From addresses, which one the recipient sees, which one bounces return to, and why the whole of authentication stands on that split. (The anatomy lesson, then alignment.)
Authentication
- You can read a stranger's SPF record and spot the classic wounds on sight: the second
v=spf1record, the blown lookup budget, the dead include, the+all. (Lessons 8 and 9.) - You can find a domain's DKIM selectors, tell a delegated CNAME from a pasted key, and say which of the two survives key rotation without anyone touching DNS. (Lessons 10 and 11.)
- You can read a DMARC record, explain what each policy stage does, and diagnose an alignment failure from an
Authentication-Resultsheader, including the case where SPF passes and DMARC still fails. (Lessons 12 through 14, with headers from the headers lesson.)
Reputation
- You can explain domain reputation versus IP reputation, say which one follows a client through an ESP migration, and give the honest shared-versus-dedicated answer for a client's actual volume. (Lessons 18 and 21.)
- You can state the Gmail and Yahoo bulk-sender requirements from memory, including the complaint-rate threshold, and check a domain's compliance from the outside. (Lessons 26 and 27.)
- You can explain why B2B placement behaves nothing like Gmail: the secure email gateways, the Microsoft 365 quarantine and its digests, and why a consumer seed test says little about a corporate inbox. (Lesson 20.)
The audit
- You can run a full audit on a domain you have never seen, using only free tooling, and produce written findings ordered by impact rather than by the order you found them. (Lessons 50 and 59.)
- You can present those findings to a small-business owner in plain English, each one translated into what it is costing them. (Lesson 60.)
Repair
- You can fix a broken setup in dependency order (inventory, then SPF, then DKIM, then alignment, DMARC last) and explain why tightening DMARC first creates the exact incident it was meant to prevent. (Lesson 54.)
- You can verify every fix the way a receiver would: a fresh public DNS query after the TTL expires, a real message sent, the
Authentication-Resultsverdict read, and no dashboard taken at its word. (Lessons 3 and 55.)
Decay and monitoring
- You can name every decay mechanism this course covered: edited records, rotated keys, expired includes, provider rule changes, list aging, reputation drift, the blocklisting nobody tells you about, and going cold. (Lessons 42 through 45.)
- You can design a monitoring routine, tool by tool and cadence by cadence, that catches each of those mechanisms before it costs money. (Lessons 47 and 48.)
The business
- You can scope and price the three engagement shapes (the one-off audit, the fix engagement, the monitoring retainer) and say exactly what each includes and excludes. (Lesson 61.)
- You can say the refusal sentences without flinching: no, I cannot guarantee the inbox; no, I won't set up a warm-up network; no, don't pay that delisting service; no, this one is not a deliverability problem. (Lessons 62 and 63, with the delisting lesson behind the third.)
Fourteen or fifteen with the gaps named is a strong place to stand. All sixteen claimed on the first pass, without a single wobble, usually means the assessment was done with confidence rather than evidence, and confidence is the thing the gauntlet exists to calibrate.
Staying current
The checklist has a shelf life, because rule decay applies to it too: providers change the rules, and a compliant setup becomes a violation without a single record changing. What separates a practitioner from someone who took a course in 2026 is a short reading list and one habit.
The reading list:
- The providers' own sender pages: Google's Email sender guidelines, Yahoo's senders hub, and Microsoft's postmaster pages. These are the primary sources. When a rule genuinely changes, it changes here, on a page with a date on it.
- M3AAWG's published documents: the anti-abuse working group where the people who actually run the filters write down what senders should do. Slow, dry, and worth more than a hundred hot takes.
- The practitioner community: the Email Geeks community and the long-running practitioner blogs (Word to the Wise and Spam Resource among them). This is the fastest signal you'll get, and it is also, by nature, secondhand.
- The RFCs, when a claim turns on what a standard actually says (RFC 7208 for SPF, RFC 8058 for one-click unsubscribe). Nobody reads them until there's a dispute; the person who reads them wins the dispute.
The habit: before repeating a claimed rule change to a client, find it on the provider's own page, dated, and read the actual wording. Rules decay, and secondhand rules decay fastest. The 2024 bulk-sender requirements made the point better than I could: the retellings circulated for months with thresholds and enforcement dates that disagreed with each other, and the disagreement itself was the tell that most summaries were summaries of summaries. Your clients will forward you those posts. The answer that protects your reputation is "here is what Google's page says as of this week", with the link attached.
The one instrument to leave running
This course made one argument from its first lesson: deliverability is a condition that degrades, not a task you finish. By now you have watched every mechanism of that degradation from the inside, so the argument doesn't need restating, and the closing advice is purely operational. The DIY routine from the monitoring lesson (weekly DMARC report review, the postmaster dashboards, a blocklist sweep, a record diff against your written baseline) is fully sufficient. Nothing in it requires spending money.
What it costs is attention, every week, forever, on domains where nothing appears to be wrong, and that is precisely the kind of bill humans are worst at paying. Inbox Decay is that same routine run on a schedule, and if the premise isn't self-evident by now, one more sentence from me was never going to get it there.
One last drill. Twenty terms spanning the whole course, Part 1 plumbing to Part 7 practice, and this one doubles as interview prep: define these in plain English without hesitating and you sound like a practitioner, because sounding like one and being one converge right about here.
Term drill
1/20
PTR record
The sixteen claims hold the same way DNS records do, only while something keeps checking them, so put the first real audit of a domain you don't own on this week's calendar.