Job email-forwarding-breaks-sender-checks · revised 11 October 2026
Stop forwarded business mail being rejected, junked or dropped
Check up to five forwarding rules, fix your side or swap the forward for an alias or shared mailbox, and show the result with test messages; a strict-policy sender's result is recorded, not promised.
You might be seeing
- Mail to the company address reaches the first mailbox but not the one it is forwarded to
- Forwarded messages appear in the junk folder, or only some senders' messages are missing
- The sender gets a bounce mentioning forwarding, authentication or a policy
- Forwarding worked for years and stopped after a provider or security setting changed
No passwords, keys, card details or admin invites needed to start.
What usually happened
A forwarding rule resends the message from your server, not from the original sender's, so the final receiver may see an SPF check fail, a DKIM signature broken by edits, or, where the sender publishes a strict DMARC policy, a message that fails alignment and is rejected. Separately, some providers block automatic forwarding to outside addresses and return an access-denied bounce. The sender sees a bounce or nothing at all, and nobody on your side knows. The checks an outside receiver applies are not ours to change, so for a forward to an outside address this job can change only what is on your side and show what then happens.
Who it’s for: Owner or office manager who forwards info@, sales@ or a departed colleague's address to a personal or other mailbox and has found that some messages never arrive.
Usually starts when: A sender reports a bounce such as "access denied" or "failed authentication", forwarded mail lands in junk, or a customer says they wrote and heard nothing.
The result: For each forwarding rule in scope, test messages from two outside providers reach the final destination without a bounce, or the rule is replaced by an alias, group or shared mailbox that delivers the original message. For a forward to an outside address, a test from a sender whose domain publishes an enforcing DMARC policy is also run and its result shown, passing or not, or the limit is stated in writing. A failed strict-sender result is a stated limit of that forward; it does not reduce the price.
Check whether this job fits
Four questions, about two minutes. Your answers stay on this page unless you choose to email them.
Checks you can run yourself
Read the verdict lines in a forwarded message
Open one forwarded message that did arrive, choose "show original" or "view message source", and find the line beginning Authentication-Results.
Look for: spf=fail, dkim=fail or dmarc=fail tells you which check the forwarded copy failed. Keep this text, with personal details removed, for your enquiry.
What you get
- A table of the rules, their type and the cause of each failure found
- The changed settings, or exact steps for the administrator who must make them
- A test table with the authentication results shown in each delivered message, and, for each outside forward, the result for the strict-policy test sender
- Plain advice on any rule where forwarding is the wrong tool and why, and on which outcomes are possible for each outside forward: a change on your side, a result that depends on the receiver trusting the forwarder, or replacing the forward
Included
- Up to five forwarding rules on one domain at one email provider you name
- Classifying each rule: provider-level forward, inbox rule, host-level forwarder, alias, group or shared mailbox
- Reading the bounce text or message headers to find which check or policy stopped each failing message
- Replacing a rule with an alias, group or shared mailbox where the final recipient is inside the same provider; for a forward to an outside address, changing only what is on your side (your provider's forwarding policy and settings, an inbox rule or a host forwarder), which may or may not be enough for every sender
- Test messages from two outside providers to every rule, and, for every forward to an outside address, from a test sender whose domain publishes an enforcing DMARC policy, with the headers kept as evidence
Not included
- Recovering messages that were already rejected or dropped
- Setting up SPF, DKIM and DMARC for your own outgoing mail: that is a separate job
- Changing a recipient's own spam filter or mailing-list settings
- Setting an organisation's security policy: if your policy blocks outside forwarding on purpose, we offer the alternatives and you decide
- Mail gateways, bulk mailing and newsletters
How we know it’s done
Agreed with you before work starts. Each check produces evidence you keep.
For each rule, a test message from each of two outside providers reaches the final destination within the agreed wait, with no bounce and no reliance on the junk folder.
Evidence: The test table and a screenshot or header excerpt of each received message
For each forward to an outside address, a message from a test sender whose domain publishes an enforcing DMARC policy (p=quarantine or p=reject) and signs its mail with DKIM is sent to the final destination, and its result is recorded, with the delivered message's Authentication-Results line or the bounce text. This test is recorded, not pass-or-fail for the price: if the message bounces or lands in junk, the hand-over states that as a limit of that outside forward, and the price is not reduced. If no such test sender is available, the hand-over states that the outside forwards are improved but not proven against senders with a strict policy.
Evidence: The strict-sender test row for each outside forward with its result and header excerpt or bounce text, or the written statement of the limit
For each rule, the delivered message's headers are recorded and the cause of the original failure is stated with the line that shows it.
Evidence: Header excerpts with personal details removed
Where a rule was replaced by an alias, group or shared mailbox, a test message to the old address arrives in every named recipient's mailbox as the original message.
Evidence: Screenshots from each recipient's mailbox
Sign-off. You sign off after each rule's test messages have been seen at the destination, you have read the strict-sender result or the stated limit for each outside forward, whether it passed or not, and you have accepted any rule we advised replacing.
If it fails. If a rule cannot be made to pass, we say which one, show the evidence and advise the alternative, and £33 (one fifth of the £165 fixed price) is deducted for each rule that does not pass its checks. The strict-sender test on a forward to an outside address is not one of those checks: if it fails, or no strict-policy sender is available, that is written up as a limit of the forward and the price is not reduced.
When it fits, and when we stop
It fits when
- You can sign in as an administrator at the provider where the forwarding is set, or an administrator will follow our steps
- Every forwarding destination is an address you or your staff own and control
- You can supply or agree test sender accounts at two outside providers
- For forwards to outside addresses, a test sender is available whose domain publishes an enforcing DMARC policy (p=quarantine or p=reject) and whose own mail is DKIM-signed with that domain, such as a domain you control. Without one, the outside forwards are tested against ordinary senders only and the hand-over says plainly that they are improved but not proven against senders with a strict policy
We stop and tell you if
- The destination is an address you do not control
- The administrator will not change a security policy that blocks forwarding, and the alternatives do not suit
- The failing mail comes from a sender whose own domain is misconfigured, which only the sender can fix
- The rules relate to more than one domain or more than five rules
What could go wrong
Every rule is recorded before it is changed, so an administrator can recreate it. A rule is deleted only after its replacement has passed the tests and you agree.
Scroll the table sideways to read it all.
| Risk | How we handle it |
|---|---|
| Allowing outside forwarding widens what a compromised mailbox could leak. | We name the alternatives that avoid outside forwarding and leave the security decision with you. |
| A replacement alias changes who can see the original message. | The recipients of every alias, group or shared mailbox are listed and approved by you before the change. |
| The cause is at a sender or at the destination, outside our control, or an outside receiver still rejects strict-policy senders after our change. | We show the evidence and say so, we do not claim a fix that the tests do not prove, and we advise replacing the forward with a mailbox that person opens directly. |
A second reviewer, separate from the work that produced the plan, checks each proposed change against the recorded rules and the test evidence. No human supervisor is included unless your proposal names one. At launch much of the preparation is automated, and we say so.
How we deliver
We arrange the work and independent review, then show you the result against the agreed checks. You keep authority over your systems.
- List each rule and classify its type from the settings and from a test message's headers
- Send first-round test messages from two outside providers and keep the bounce text and authentication lines
- For each rule decide with you: replace it with an alias, group or shared mailbox, or repair the forwarding settings
- A second reviewer checks each change against the evidence and against your security policy
- You or your administrator apply the change; we repeat the tests and record the results rule by rule
This is a one-off job, not emergency cover or a subscription. We confirm eligibility, the total price, a start window and a delivery date before you accept. Work starts only after agreed inputs, secure access, any licences and necessary permissions are in place. Hosting, platform and supplier charges are excluded unless the written quote includes them. No charge or booking is created by an enquiry.
Need to keep it working?
If you add senders or mailboxes often, ask about the standing responsibility that keeps mail authentication and routing checked each month.
Ongoing work is separately scoped and quoted: no monitoring, response-time guarantee or automatic subscription is included in this job.
Explore an ongoing engineering lane, or mention the responsibility you need in your enquiry.
What you can check
This is a new service. We have not delivered this job for a client yet.
Other ways to get this done
- Google's documentation draws a line between forwarding, which alters the original content, and redirecting, which does not. If everyone who should receive the mail is in the same email account, our reading is that an alias, group or shared mailbox gives each person the original message instead of a re-sent copy; for a replaced rule, the acceptance check on replacements tests that. knowledge.workspace.google.com
- Microsoft documents a setting that blocks automatic forwarding to outside addresses and the exact bounce text it causes, which an administrator can review. learn.microsoft.com
Questions
Is forwarding unsafe?
Not by itself, but a forward that reaches an outside address can leak mail if an account is compromised, which is why some organisations block it. We set out the options and you choose.
Can you guarantee forwarded mail is never junked?
No. The final receiver's filters decide, and we cannot control them. We show the authentication results; the two ordinary test messages must reach the destination, and the strict-policy test is recorded as a result or as a stated limit.
What is the alternative to forwarding?
Often an alias, a group or a shared mailbox, so that the original message is delivered to each person rather than re-sent.
What can you change if the mail goes to my personal Gmail or Outlook address?
Only what is on your side: your provider's forwarding policy and settings, an inbox rule, or a host forwarder, or replacing the forward. The checks the outside receiver applies are not ours to change. We test with a sender that publishes a strict policy and show the result, and if it still fails we say so, record it as a limit of that forward without reducing the price, and advise a mailbox that person opens directly.
Send an enquiry
Send us
- The email provider and a description of each forwarding rule: from address, to address and who set it up
- One or two bounce messages with personal details removed, or the date and sender of a missing message
- Whether the destination is inside the same provider or an outside address
Later, once you agree
- Administrator access arranged through a company-controlled secure handoff, scoped to mail settings, or a person who will make the changes from our steps
- Two outside test sender accounts, or agreement that we use ours, and for outside forwards the strict-policy test sender (a domain you control, with access to send from it)
- No live passwords, mailbox contents or customer messages by ordinary email
The domain, the provider account and the mailboxes stay in your name. We read the rules and the test messages' headers only; we never need to read other people's mail.
Email fallback: open your mail app
If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “email-forwarding-breaks-sender-checks” as the subject.