Evidence standards

Specific evidence. Explicit uncertainty.

Mailybox is designed to help people make technical decisions without pretending that one DNS record, one header or one score can explain an entire email system.

Observation comes before diagnosis

Results distinguish facts that can be read directly from supplied evidence or public records from conclusions that require interpretation. A published DMARC policy is an observation. Whether a particular sender is correctly aligned depends on message-level authentication evidence.

Scores summarize; they do not certify

Where a score is shown, it is a prioritization aid. It is not a guarantee of inbox placement, sender legitimacy, security or regulatory compliance. The underlying findings remain the primary output.

Public configuration is not activity proof

DNS can reveal authorization, delegation and provider fingerprints, but it cannot prove that every discovered service is currently sending. Mailybox labels these distinctions rather than presenting inference as inventory certainty.

Message evidence is receiver-specific

Authentication-Results, ARC and Received fields reflect how a particular message was processed by particular systems. The same domain can produce different outcomes when the route, sender, signing identity or receiver changes.

Privacy is part of the analysis design

Tools avoid requesting mailbox access when the task can be completed with public records or user-supplied evidence. The complete-message forensic tool keeps the message body in the browser and submits only the extracted header for route and authentication analysis.

Retesting closes the loop

Email configuration changes can affect several dependencies at once. After a correction, Mailybox encourages repeating the same analysis with the new evidence rather than assuming publication alone resolved the original failure.