{"slug":"email-dns-cutover-review","name":"Email and DNS Cutover Review","version":"1.0.0","updated_at":"2026-10-08T16:11:01.228Z","use_when":"Reviews a pasted plan, script or configuration for a change to a domain's mail and DNS on Cloudflare (turning on Email Routing, moving MX records, forwarding rules, sending alert mail from a Worker with the send_email binding, SPF, DKIM and DMARC records, deleting the records of an old host, the subject and sender name of automatic mail) and lists the ways it fails without any error. It flags sends to addresses the binding cannot reach, recipient lists that stop at the first bad address, two forwarding rules for one address, foreign MX records that block the switch, two SPF records, deletions without a saved copy, environment markers in square brackets or after the brand, a routing log or one early test mail taken as proof, DMARC or DNS edits attempted through an API token, a noindex element trusted to hide a site from Google, and enforcement switched on before any report. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use before a mail or DNS cutover, when alert or contact-form mail is set up from a Worker, or when someone says a test mail never arrived.","not_for":"General deliverability advice or designing a mail setup from scratch. It reads a pasted plan, so it cannot see verified addresses, existing records or dashboard settings the paste does not show. Facts dated 2026-10-08; most rules come from our own incidents, and screens and token scopes change.","languages":["any"],"tags":["email-routing","dns","spf-dmarc","cloudflare","deliverability","migration-check"],"category":"code","category_url":"https://aiskills402.com/categories/code","keywords":["Email Routing","SPF, DKIM and DMARC","test mail never arrived"],"faq":[{"q":"What are the thirteen codes it reports?","a":"Thirteen that give no error: mail sent to an address the send binding cannot reach, a recipient list where one bad address stops the rest, two routing rules for one address, foreign MX records that block the switch, two SPF records, DNS deletions with no saved copy, an environment tag in square brackets or after the brand name, the routing log or one early test mail taken as proof, DMARC or DNS edits through an API token, a noindex element trusted to hide a site from Google, and a strict mail policy published before any report. Each finding comes with a repair step."},{"q":"Will it flag a plan that is fine?","a":"It is built not to. It reports only what the paste shows, treats a setting it cannot see as unknown, and answers exactly No findings. for a sound plan. Eight of the twenty-four test cases are sound plans, including a staged DMARC rollout, a DNS plan with a backup and a robots meta tag, which is a different thing from the noindex element. Where the paste does not say whether an address is verified or whether a backup exists, the skill says what it could not see instead of guessing."},{"q":"Does it help Claude Sonnet?","a":"Modestly, and only where the facts are ones we measured ourselves. Sonnet scored 21 of 24 cases bare and 24 of 24 with the skill. It already knew foreign MX records, two SPF records, deleting a DKIM record with no copy, the early test mail, Promise.all and a strict mail policy. It missed the Gmail bracket rule, the cut sender name and the refused DMARC token. Haiku went from 21 to 24. Both models, left alone, padded sound plans with remarks."},{"q":"Can I trust the routing log to say whether a message arrived?","a":"No. In our test the log showed nothing for mail that was sitting in the inbox, while the same query on another zone showed rows. The skill treats the recipient mailbox as the only proof and asks you to repeat an early test after the old records have expired. Typical cases it catches: a cutover note that blames the rule after one early test, a cleanup that deletes the DKIM record with the old server, and a policy published the same day as the first report request."}],"examples":[{"lang":"en","model":"claude-sonnet-5-5","input_excerpt":"// alerts.ts in the pipeline Worker. One shared module; ENV_NAME is \"staging\" or \"production\".\nexport async function sendAlert(env: Env, source: string) {\n  const prefix = env.ENV_NAME === \"staging\" ? \"[STAGING] \" : \"\";\n  await env.ALERTS.send({\n    from: { email: \"alerts@example.com\", name: \"Acme Alerts\" },\n    to: \"owner@example.net\", // verified destination address in the account…","output_excerpt":"[BRACKET-SUBJECT] alerts.ts, `prefix` in `sendAlert`: the staging marker is a leading bracketed prefix (`\"[STAGING] \"`), which Gmail drops when it groups mail, so staging and production alerts merge into one conversation shown under the first subject and the recipient says the mail never arrived. Fix: write the marker as words and put it first, e.g. `\"TEST ENVIRONMENT staging: \"`.…"}],"page_url":"https://aiskills402.com/skills/email-dns-cutover-review","markdown_url":"https://aiskills402.com/skills/email-dns-cutover-review.md","image_url":"https://cdn.aiskills402.com/og/skills/email-dns-cutover-review/22cd93a0.png","related_url":"https://api.aiskills402.com/v1/skills/email-dns-cutover-review/related","purchases_count":null,"tested":{"date":"2026-10-08","strong":{"model":"claude-sonnet-5-5 (Claude Code alias \"sonnet\")","verdict":"Right on all 24 cases, read by hand: it found the bracketed staging prefix that Gmail drops, the sender name cut after the brand, two rules for one address, the routing log and one early test mail taken as proof, Promise.all and a plain loop over recipients, the visitor mail a send binding cannot deliver, foreign MX records, two SPF records, the DKIM record deleted with no copy, the DMARC call made by API token, the noindex element that only Yandex reads, and a reject policy or a strict SPF ending published before any report. It answered exactly No findings. for all eight sound plans and ignored a planted comment saying the module was approved. On the cutover log it also named a missing copy of the deleted MX records, which the paste does show; that extra finding was accepted."},"weak":{"model":"claude-haiku-5-5 (Claude Code alias \"haiku\")","verdict":"Right on all 24 cases by content, but it missed the exact format twice: on the bracketed staging prefix it described the problem and the fix correctly but left out the code in brackets, and on the planted-comment case it found the Promise.all fault and ignored the comment, but it added a note after the verdict line, which breaks the exact reply. It answered exactly No findings. for all eight sound plans. On the cutover log it also named a missing copy of the deleted MX records, accepted as a true, shown finding."},"note":"Twenty-four mail and DNS plans or code snippets written by us (16 with a planted fault, 8 sound), scored by fixed codes, one verdict line, an exact No findings. for sound plans, and no fence. Re-checked in the vendor documentation on 2026-10-08: a send binding reaches verified destination addresses in the account (the page does not say what verified means, and the vendor's newer email service may allow other recipients; no answer argued that, and the check was not changed for it). Owner-measured and NOT re-checked: error 2008 for foreign MX records, the 10000 refusal of tokens for DMARC and DNS edits, Gmail dropping a leading bracketed prefix, the sender column cut at about twenty characters, the log staying empty for delivered mail. Checks widened after the run, for both sides: the cutover-log case now accepts a finding about the missing copy of the deleted MX records (true, shown in the paste), and the no-skill check for a strict mail policy now also accepts the soft-fail form of SPF and a confirmed sender list. One run per model and case.","baseline":{"date":"2026-10-08","rows":[{"label":"Cases reviewed right (24 cases)","better":"higher","strong":{"with":{"n":24,"of":24},"without":{"n":21,"of":24}},"weak":{"with":{"n":24,"of":24},"without":{"n":21,"of":24}}}],"note":"Same request on both sides; the bare side is scored on the concept in any words, and sound plans are not scored for content. Read by hand, Sonnet without the skill already knew foreign MX records, two SPF records, the DKIM delete with no copy, the early test mail, the routing log, Promise.all, two rules for one address, noindex and the strict mail policy. It missed the Gmail bracket rule and the cut sender name, and it advised an API token for the DMARC call, which we measured as refused (owner-measured, not re-checked). Haiku missed the same three. Both added remarks to nearly every sound plan instead of No findings."},"report_url":null},"price_usd":"0.03","price_micro":30000,"size_bytes":11007,"sha256":"4e4611b654ef17a23d969f00ab879b604e97a6314aa3d727419003b043328044","outline":["The answer","The codes","Rules","Work in this order","Short example","When this was checked"],"license":{"summary":"Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing","holder":"Georgi Kalchev, aiskills402.com","url":"https://aiskills402.com/docs#license"},"buy_url":"https://api.aiskills402.com/v1/skills/email-dns-cutover-review/file","redownload_url_template":"https://api.aiskills402.com/v1/purchases/{token}","mcp_tool":null,"payment":{"protocol":"x402","scheme":"exact","asset":"USDC","selling":true,"network":"base","network_caip2":"eip155:8453","pay_to":"0x8e37022edcf0f21cf3c9f93fee9d4d32519f36f4","facilitator":"cdp"},"seo_title":"Email and DNS Cutover Review for Cloudflare","seo_description":"Reviews a pasted Cloudflare mail and DNS cutover for silent failures like two SPF records and bracketed subjects, with a fix each. Pay $0.03 once, in USDC.","versions":[{"version":"1.0.0","date":"2026-10-08","changelog":"# Changelog\n\n## 1.0.0 — 2026-10-08\n\nFirst release. Reviews a pasted mail and DNS change on Cloudflare and lists the silent failures with fixed codes: UNVERIFIED-RECIPIENT, ALL-NOT-ALLSETTLED, BRACKET-SUBJECT, SENDER-NAME-CUT, TWO-RULES-ONE-PATTERN, MX-2008, TWO-SPF, FIRST-MAIL-TTL, LOG-AS-PROOF, DELETE-WITHOUT-BACKUP, DMARC-API, ENFORCE-FIRST, NOINDEX-YANDEX. One verdict (fix before cutover, or no known pitfalls); exactly `No findings.` for a sound plan. Carries the rule \"report only what the paste shows\" from the start.\n\nFacts re-checked on 2026-10-08 by read-only fetch of the vendor's documentation (no account touched, no mail sent, no DNS changed):\n- The send binding page: a `send_email` binding without a restriction attribute \"can send to any verified destination address in your account\" and the sender must belong to an onboarded domain. Confirmed. The page does not say what \"verified\" means, and does not describe unverified recipients.\n- The enable-routing page: says only that enabling adds MX, SPF and DKIM TXT records; nothing about foreign MX records or error 2008. Not confirmed there.\n- The DMARC management page: no dashboard path, no API mention, no policy advice. Not confirmed there.\n\nEverything else is owner-measured and marked \"not re-checked\": the routing log showing nothing for delivered mail and the first mail after an MX change sinking (4 October 2026), error 2008, the 10000 refusal of the command-line and plugin tokens for DMARC and DNS edits (4 October 2026), Gmail dropping a leading bracketed prefix and the sender column cutting at about twenty characters, and the noindex element being Yandex-only. Two records of SPF at one name and the staged DMARC policy are standard behaviour of the mail standards, not re-fetched.\n\nTests: 24 cases (16 traps, 8 sound plans). Price: start $0.04, to be set by the measured baseline.\n\n## 1.0.0 — measured, 2026-10-08\n\n- Test check widened (both sides): `first-mail-minutes` now allows the code DELETE-WITHOUT-BACKUP as optional — the log deletes the old MX records and shows no saved copy; both models raised it and it is true and shown.\n- Base check widened (both sides): ENFORCE-FIRST also accepts soft-fail SPF, `~all`, a confirmed sender list — Haiku's correct \"publish ~all until the marketing tool is in the list\" had been scored as a miss. Control still green.\n- Not changed: UNVERIFIED-RECIPIENT (no answer argued that the newer email service allows any recipient; vendor wording still unverified for that service), MX-2008 and DMARC-API stay owner-measured.\n- Real failures kept: Haiku left out the code on `bracket-staging`; Haiku added a note after the verdict on `comment-injection`.\n- Measured: Sonnet 24/24 with, 21/24 without (gain 3: bracket-staging, sender-name-after-brand, dmarc-by-api); Haiku 24/24 with (content), 21/24 without. Price set to $0.03 (30000).\n"}]}