The three statuses
Sendvery discovers senders automatically: every source IP that shows up in a DMARC report for your domain gets a row in your inventory. It arrives as Needs review, because nothing in a DMARC report tells us whether that server is your mail host or somebody impersonating you. Only you know that.
- Authorized — you confirmed this server is allowed to send as your domain. It stops appearing in alerts, reminders and the weekly email.
- Needs review — we've seen it, nobody has decided yet. This is the only status that is asking something of you. Every newly discovered sender starts here.
- Not authorized — you looked at it and decided it isn't yours. It stays flagged, so a spoofer can't slowly drift into the "we always ignore that one" pile.
How do I verify a sender is really mine?
There is no button that proves it — but three signals together are strong evidence, and they're all on the row in front of you.
- Do you recognise the organisation? Sendvery resolves the reverse DNS and the owning organisation where it can, so you usually see a name rather than a bare IP. If it names your mail provider, your newsletter tool, your invoicing system or your CRM — something you pay for — that's the strongest signal available.
- Is DKIM passing, consistently? This is the one that's hard to fake. DKIM signatures are made with a private key that only you and the services you set up hold. A sender at 100% DKIM pass is cryptographically demonstrating it has your key. A spoofer cannot do that; spoofed mail shows up with DKIM failing.
- Does the volume match mail you actually send? If your team sends a few hundred messages a week, a sender at that scale is plausible. One at 50,000 is not.
A worked example, because it's the common one. You see five rows — mxb.seznam.cz, mxb-1-910.seznam.cz and friends — each at 100% DKIM and 100% SPF, all badged Needs review. Read it back through the three signals: the name is your mail provider, they're signing with your DKIM key, and the volume is your normal traffic split across the provider's outbound machines. That's your own mail host, seen from the outside. Authorize them.
The reverse case: an IP with no resolved organisation, DKIM failing on most messages, appearing out of nowhere with a burst of volume. That's what spoofing looks like. Mark it not authorized.
And when you genuinely can't tell — no recognisable name, but the mail is passing DKIM — leave it in Needs review and check back. Passing DKIM means somebody with your key is sending it, which almost always means a service one of your colleagues set up. Ask around before you decide either way.
What happens if I do nothing?
Nothing breaks. Statuses never change your DNS, your SPF record, your DKIM keys or your DMARC policy, and they never block or release a single message. What actually stops spoofed mail from being delivered is your DMARC policy — moving from p=none to p=quarantine or p=reject.
What you lose by not deciding is signal. A sender left in Needs review keeps being flagged in your inventory, your alerts and your weekly email, because Sendvery has no way of knowing it's fine. Working through the list once is what makes the next genuinely suspicious sender stand out instead of being lost among a dozen amber rows you've learned to scroll past.
What "authorized" actually changes
Marking a sender as authorized is a note-to-self — it tells Sendvery that you've recognised the source and intend mail from it, so we should stop highlighting it. It does not change anything visible to receivers. Authorization is an internal label that also helps the next person looking at your inventory understand what's expected versus what's surprising.
Not authorized is the inverse signal, and it's equally internal: we don't block anything either. Its value is that the sender becomes a standing red flag rather than fading into the background.
How Sendvery picks the recommendation
On top of the three statuses, Sendvery looks at the last 30 days of activity for each sender and, when there's enough history, offers an opinion. The thresholds are chosen so a legitimate marketing IP that's been sending real mail for a week clears the authorize bar, while a spoofer producing failing mail crosses the other bar before they drown out the genuine traffic.
- Recommend authorize: at least 50 messages in the last 30 days with a DKIM pass rate of 90% or higher, and we can identify the organisation (so the suggestion is concrete: "Mailchimp has sent X messages"). It never fires for unidentified IPs — we won't pre-stamp "looks fine" for a source we can't name.
- Recommend not authorized: at least 20 messages in the last 30 days with a DKIM pass rate below 50%, and the source is unidentified. A known organisation with a low pass rate is more likely misconfigured than malicious — that needs a DKIM fix, not a rejection, so we don't suggest one.
- Monitor: enough activity to be worth surfacing but the volume or pass rate sits between the two thresholds — not yet enough signal to commit to a recommendation. We'll re-evaluate as more data arrives.
Senders below five messages in 30 days get no recommendation at all. They still show as Needs review and still count towards the "senders waiting for your review" total — a quiet sender is still a sender you haven't accounted for; we just don't have the evidence to advise you about it.
You're never forced to follow a recommendation. If a sender looks wrong to you, mark it not authorized even if we said "authorize". The advisor exists to surface the senders worth your attention, not to make the decision for you.