Audit
Aimly Audit checks whether a mailbox is set up to reliably land in the inbox rather than spam. It looks at authentication (SPF, DKIM, DMARC), sender reputation, and inbox placement, then gives you an overall score with specific issues to fix.
Running a new audit
Click Run a new audit to open the audit dialog, which offers two starting points:
New mailbox
Audit a mailbox that isn't already saved as a brand. You'll enter the email address to audit and choose an audit type from the dropdown (e.g. Full audit). From here, there are two ways to proceed depending on whether you're willing to share mailbox credentials:
With credentials (app password) — provide the mailbox's app password, and Aimly handles the entire audit itself: connecting via SMTP/IMAP, sending test messages, and checking where they land. This is the most complete option since Aimly can verify authentication and inbox placement directly, without you doing anything manually.
Without credentials (manual probe) — if you'd rather not share a password, you can still get a live authentication check by sending the email yourself:
- Aimly gives you a destination address to send to, and a unique code to include in the subject line.
- Send an email from the mailbox you're auditing to that address, with the code in the subject.
- Aimly waits for that email to arrive — while it's checking, you'll see "Checking for your email..."
- Once received, Aimly reads the authentication headers on that message to verify SPF, DKIM, and DMARC without ever needing your password.
This step is optional — if you don't want to send the probe email, click Proceed without it to run the audit without a live authentication check (falling back to DNS-based checks only).
Existing brand
If the mailbox is already connected as a brand, pick it from the list instead of re-entering an email address. Since Aimly already has that mailbox's credentials on file, it can run a full audit automatically — no probe email or extra steps needed.
Audit types
The dropdown next to the email address lets you choose what kind of audit to run — the fuller the audit, the more it can actually verify (for example, DNS-only checks can confirm authentication records exist, but can't confirm real-world inbox placement the way a full audit with live sending can).
Reading your results
Once an audit completes, you'll see a report broken into sections — Authentication, Sender Reputation, Inbox Placement, and an overall score out of 100 — along with concrete suggestions for anything that isn't passing. Sections you didn't grant access to check (for example, inbox placement when you skipped the probe on a new mailbox) show as not evaluated rather than a failing score.