---
name: email-infrastructure-operations
description: "Audit sending domains, diagnose authentication and reputation, and prepare verified mailbox onboarding. Use for email infrastructure operations tasks; select only the requested methods."
metadata:
  version: "1.0.0"
---

# Email Infrastructure Operations

Audit sending domains, diagnose authentication and reputation, and prepare verified mailbox onboarding.

## OLLIE Runtime integration

Use relevant methods under the active OLLIE Operator. Read live Workspace Context and tenant bindings for client facts, account identity, goals, permissions and required inputs. Consume ask-ollie-authority-core for authority, outloop-access-fallback for access and recovery, email-lifecycle-core for communication, and the bootstrapper Runtime Contract for execution ownership and completion. This skill introduces no scheduler, independent permission policy or competing Runtime owner.

Discover the active Workspace’s approved capabilities before choosing API or browser access. Use Outloop for external service actions and the host’s supported tools for local artifacts. A product name in this package is not an access grant. Never import private account configuration or follow a source method that bypasses host restrictions. Apply the current task’s authorization; a library update does not grant permission to send, publish or activate a campaign.

## Required inputs

- Sending domain and mailbox inventory
- DNS/provider access
- Current authentication records and message headers
- Approved sending pattern and consent policy

Use for infrastructure ownership and diagnosis beyond campaign content. Read [authentication and delivery diagnosis](references/diagnostics.md) for the relevant symptom.

## Inventory and isolate the fault

Map each sending identity to its domain, mailbox provider, DNS owner, campaign platform and responsible operator. Confirm actual account identity and approved scope before changing a zone or mailbox. Keep selectors, account IDs and recipients in the workspace.

Distinguish DNS publication, provider authentication status, message-header authentication, acceptance by a receiving server and inbox placement. Record observation time and resolver; cached DNS and provider verification can disagree temporarily. An empty sandbox lookup is not proof a record is missing.

## Prepare and verify changes

Use provider-issued values from approved settings. Compare the entire existing RRset before a change, preserve other legitimate senders and keep a reversible before/after record. Verify authoritative DNS and the provider-side status after publication. Do not weaken a domain-wide policy simply to make one sender pass.

For mailbox onboarding, confirm ownership, capacity and intended use. Stage a minimal authorized test; inspect authentication and replies before expanding. Treat sending limits, ramp plans and pause thresholds as provider/account inputs, never copied universal defaults. Warmup does not establish consent or guarantee inbox placement.

## Report and hand off

Return a domain/mailbox matrix, evidence for the failure class, proposed correction, owner, rollback and post-change result. Separate infrastructure corrections from campaign audience/copy work; preserve suppressed contacts and legitimate inbound mail.

## Completion

Verify findings against source evidence and read back every resulting artifact or authorized change. Distinguish a saved draft, queued job, active workflow and completed delivery. Return the requested outcome, evidence, output location and precise outstanding dependencies. Complete independent work when one dependency is unavailable. Package validation and synthetic fixtures do not establish real host import or provider execution.

Read [evaluation scenarios](references/evaluation.md) when testing this skill.
