Delivery Recovery & Observability

Email incident postmortem template for routing failures

Write the Friday so it does not repeat. Artifacts not vibes.

MailerZ editorial · Secuno LLC16 min read

An email routing incident postmortem records the class, the evidence, the one change that fixed it, and the rule that prevents a repeat. It is not a blame doc and not a SOC 2 certificate. Leftover MX, empty maps, dual MX heroics, and self-send QA are the usual root causes. Write the SMTP codes. Keep screenshots. MailerZ history is an artifact. No inboxing percentage as a lesson.

email routing incident postmortem: the decision
Class, evidence, one fix, one rule.

Quick answer for email routing incident postmortem

If you do not write it down, you will dual-publish MX again.

RFC 5321 codes belong in the timeline.

Root cause should be a class, not a person.

Prevention is exclusive MX checks, sheets, and third-mailbox probes.

Store windows explain missing artifacts. Say so.

Start free and practice a fake postmortem on a test alias.

Authoritative mail transport is defined in IETF RFC 5321 — Simple Mail Transfer Protocol. Product path: delivery recovery, troubleshooting, and features.

User problem and decision criteria

Decision criteria: was this leftover, HOLD, reject, folder, or process.

Do not use the doc to sell Workspace.

Do not add SOC 2 as a prevention if you do not have it.

Agencies should share a redacted template with clients.

If two editors flapped, the rule is one editor.

If QA was self-send, the rule is third mailbox.

No inboxing target as a smart goal.

Keep it short enough to read.

Technical mail flow

email routing incident postmortem flow
Exclusive MX. SRS envelope. Header From intact.

Incident → evidence → class → fix → postmortem → calendar rule.

Artifacts: MX screenshots, history, probe IDs.

Rollback notes if you rolled back.

Offboard if a vendor left leftovers.

Step-by-step setup / decision path

email routing incident postmortem steps
Map, exclusive MX, third-mailbox probe.
  1. Fill summary in one sentence.
  2. Paste UTC timeline.
  3. Attach MX before/after.
  4. Paste SMTP codes.
  5. Name the class.
  6. Name the single fix.
  7. Name the detection miss.
  8. Add one prevention rule and an owner.

Classify the next failure before a second DNS edit.

HOLD unknown unless you wrote a FORWARD reason.

Quote live pricing before promising alias counts.

Failure modes and proof

No postmortem: repeat leftover MX.

Blame-only doc.

Invented SLA.

Inboxing KPI.

Missing codes.

No screenshots.

Five unrelated fixes listed.

SOC 2 theater.

Header rewrite as a lesson.

Catch-all as prevention.

Secret SMTP in the doc.

Never reviewed.

MailerZ workflow and product boundary

MailerZ is custom-domain aliasing and forwarding with optional paid send-as. Secuno LLC operates mailerz.net. The app is mail.mailerz.net. Not Workspace, not IMAP, not an open relay, not a campaign ESP.

Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME stay intact. Exclusive MX. Hold unknown on Free. Copy SMTP host, port, and TLS or STARTTLS from the dashboard when you send.

Free: one domain, three aliases, one seat, fourteen-day store, fifty outgoing a month, no send-as. Solo forty dollars a year, fifteen aliases, ninety-day store, one hundred outgoing, five send-as per hour. Starter eight or eighty. Business nineteen or one hundred ninety. Agency thirty-nine or three hundred ninety. Quote pricing. No SOC 2, ISO, HIPAA, SLA, or inboxing percentage.

Cost, alternatives, and trade-offs

Repeating leftover MX is the expensive no-doc outcome.

A one-pager is cheap.

Agencies can bill it as quality.

Invented SLAs are legal cost.

Catch-all prevention is junk cost.

Review time is cheaper than the next Friday.

No fake metrics.

Training new hires on real postmortems is leverage.

Operational depth

Keep a folder of postmortems. Review quarterly for the same class.

Redact customer content. Keep codes and MX.

If the store expired, the lesson is “ask for resend faster,” not a fake hop.

Agencies: a postmortem is a deliverable after dual-MX events.

Put exclusive-MX in the launch checklist if that was the miss.

Put third-mailbox in QA if that was the miss.

Put one DNS editor in the incident runbook if that was the miss.

Do not write novels. One page.

Link the missing-mail runbook.

No legal badges.

Schedule the prevention check.

Close the incident only when the probe ID is in this doc.

Field notes for an email routing incident postmortem

Fill the template the same day the probe goes green, while UTC times are still in chat. A week later you will remember a vibe. The template wants a class: leftover MX, empty map, destination 5xx, 250-plus-junk, expired store, or self-send QA. One class. If you list five unrelated fixes, you have not found the cause. You have a shopping list.

Timeline in UTC. Local “this morning” is how store windows get argued. Free keeps fourteen days. Paid ninety. If evidence expired, the lesson is “ask for a resend faster,” not a fabricated hop. Say the clock in the doc.

Attach MX before and after from two resolvers. Demoted leftovers belong in the before picture. If you cannot show exclusivity after, you did not close. Priority tricks are not deletion. Write that as the prevention rule if it was the miss.

Paste SMTP codes in full. “5.7.1” without the rest is how two teams argue past each other. Host that answered, enhanced status, attempted recipient. IETF RFC 5321 — Simple Mail Transfer Protocol is the language. Folklore is not.

Root cause is a class, not a person. “Jordan published leftover MX” becomes “two editors, no screenshot gate.” The rule is one DNS editor and a picture in the ticket. Blame novels do not prevent Fridays.

Detection gap: why did you learn from a customer instead of two resolvers. Put exclusive-MX check on the launch list if that was the miss. Put third-mailbox QA on the launch list if self-send was the miss. Put one commander and one editor in the incident runbook if two people flapped overnight.

Prevention must have an owner and a calendar date. “Be more careful” is not a rule. “Screenshot MX before every cut, reviewed in the Friday ops meeting for thirty days” is a rule. Then stop adding rules. One page.

Do not invent an SLA in the close. Do not add an inboxing percentage as a smart goal. MailerZ does not publish those. A 250 plus junk is a filter lesson, not a DNS lesson. Keep them separate so the next incident does not republish MX for Promotions.

Do not add catch-all FORWARD as prevention. That hides the next missing alias in junk and trains the destination. HOLD plus a better sheet is the prevention for unknown recipients.

Do not put SMTP secrets in the postmortem. Redact. Keep codes and MX. Customer bodies do not belong in a folder that lives forever in Drive. Store windows exist for a reason. Shadow archives are worse stores with no clock.

Do not mint SOC 2 as a prevention if you do not have it. Point at security. Honesty is the enterprise line. Stickers you invent are a second incident.

Agencies should share a redacted template with the client when dual MX happened on their zone. It is a deliverable. It also trains them not to ask for backup MX next time.

Review the folder quarterly for the same class. If leftover MX appears three times, your launch checklist is theater. Fix the gate, not the tone of the docs.

Practice on a test alias. Break HOLD on purpose, write the postmortem, delete the experiment. Unused templates rot. Used ones stay short enough to fill at 6 p.m.

Close the incident only when the new probe Message-ID is in this document. Old missing mail that hit another host stays missing. Do not promise a restore you cannot perform. That sentence belongs in the customer close and in the postmortem.

Header rewrite is not a lesson MailerZ will implement. If someone proposed it during the incident, write “rejected: identity contract” so it does not return as a clever fix next quarter.

Worked postmortem scenarios

Class leftover MX. Timeline: Thursday add MailerZ MX, Friday still Google at 10. Codes: empty history for bank senders. Fix: delete Google MX. Detection gap: no two-resolver check at launch. Rule: screenshot two resolvers before the launch message. Owner: whoever publishes MX. Customer close: some messages hit the old host; we cannot recover them; please resend. No SLA invented.

Class empty map. Support@ printed, never created. HOLD or 550. Fix: create alias, recover inside the window if the copy exists. Detection gap: footer designed after the sheet froze. Rule: printed strings require a sheet row before print. Prevention is not catch-all FORWARD.

Class self-send QA. Launch declared green. Customers missing. Gmail short-circuited. Rule: third mailbox Message-ID in the launch channel or it is not green. Owner: QA. Do not flap MX in the postmortem of a lie you told yourselves.

Class 250-plus-junk. History perfect. User did not search all mail. Rule: screenshare search before a P1 DNS page. Separate filter tickets. No MX change in this postmortem. Inboxing percentage is not a lesson.

Class expired store. Complaint from three weeks ago on Free. No artifact. Lesson: ask for a uniquely titled resend the same day. Do not fabricate hops. Do not buy a fake archive story. Paid ninety days is the honest longer window if the business needs it. Quote pricing.

Class two editors. Overnight MX flap. Serial increments. Rule: one editor, one commander. Night page may wait on 4xx. Write permission to wait. Heroes created Monday’s leftover.

Class destination 5xx. Microsoft refused the hop. Full string in the doc. Fix is not Header From rewrite. Fix may be destination policy or a different destination. MailerZ will not rewrite From. Write “rejected proposal: From rewrite.”

Class process: secrets in the postmortem draft. Redact before share. Rule: codes and MX only. Bodies stay in the product. Slack is not the store.

Agency shares redacted leftover-MX postmortem with the client. They stop asking for backup MX. That is the template working as education. Do not add SOC 2 as a closing sticker.

Quarterly folder: three leftover-MX docs. Launch checklist is theater. Fix the gate. Add a human who refuses to send the launch message without two-resolver screenshots. Process, not tone.

Practice: disable an alias on a test domain, mail it, write the postmortem in fifteen minutes, restore. The template stays short because you used it. Unused templates grow novels.

Close without probe ID. Incident reopens Tuesday. Rule: probe Message-ID is the last field. Old mail that hit another host remains missing. The doc says so twice so sales does not promise a restore.

Someone adds five fixes including SPF edits and a new vendor. You strike four. One class, one fix, one rule. SPF did not receive the mail. MX did. Keep the doc readable at 6 p.m.

Link the missing-mail runbook and delivery recovery. Do not invent a third path. The postmortem points at the same artifacts the runbook used. That is system-wide consistency, not a new design system.

Practice and anti-patterns for routing postmortems

Anti-pattern: five unrelated fixes. Strike four. One class, one fix, one rule. SPF does not receive mail. MX does.

Anti-pattern: blame novel. Jordan is not the root cause. Two editors and no screenshot gate is. Name the rule and the owner.

Anti-pattern: invented SLA or inboxing goal in the close. MailerZ does not publish those. 250-plus-junk is a filter lesson, not a DNS lesson.

Anti-pattern: catch-all FORWARD as prevention. Hides the next missing alias. HOLD plus a better sheet.

Anti-pattern: SMTP secrets or customer bodies in Drive forever. Redact. Codes and MX only. Slack is not the store.

Anti-pattern: SOC 2 as a closing sticker. /security. Honesty.

Anti-pattern: Header From rewrite listed as a smart fix. Write rejected: identity contract.

Anti-pattern: close without probe Message-ID. Reopens Tuesday. Last field is the probe. Old-host mail stays missing. Say it twice so sales does not promise a restore.

Anti-pattern: local “this morning” timestamps. UTC. Store clocks are fourteen or ninety days. Expired evidence is a resend lesson, not a fabricated hop.

Anti-pattern: unused template that grew into a novel. Practice on a test alias in fifteen minutes so the real one stays one page.

Practice: same-day fill while chat still has UTC. Class leftover, empty map, self-send QA, junk, expired store, two editors, or destination 5xx.

Practice: MX before/after from two resolvers attached. If exclusivity is not in the after, you did not close.

Practice: full SMTP strings. Host, enhanced status, recipient. RFC 5321 language.

Practice: prevention with a calendar date and an owner. “Be careful” is not a rule.

Practice: quarterly folder review. Three leftover-MX docs means the launch gate is theater. Fix the gate.

Practice: agencies share redacted leftover-MX docs so clients stop asking for backup MX. Link the missing-mail runbook. No third religion.

Operator closeout for routing postmortems

Fill the page the same day the probe goes green. UTC timestamps. One class: leftover MX, empty map, destination 5xx, 250-plus-junk, expired store, self-send QA, or two editors. If you list five fixes you have a shopping list, not a cause. SPF still does not receive mail.

Attach MX before and after from two resolvers. If the after picture is not exclusive, you did not close. Demoted leftovers belong in the before. Priority tricks are not deletion. Paste full SMTP strings: code, enhanced status, host, recipient. RFC 5321 is the language. Folklore is not.

Root cause is a class, not a person. Two editors and no screenshot gate is a rule you can own. Night pages may wait on 4xx. Write that permission down. Heroes who flap MX at 3 a.m. create Monday leftovers. One commander, one editor.

Detection gap becomes a launch-list item. Two-resolver screenshots before the launch message. Third-mailbox Message-ID or it is not green. Footer strings require a sheet row before print. Prevention is not catch-all FORWARD. HOLD plus a better sheet prevents the next unknown recipient.

Store clocks matter. Fourteen Free, ninety paid. Expired evidence is a resend lesson, not a fabricated hop. Do not promise restore of mail that hit another host. Say it in the customer close and again in the last paragraph so sales cannot invent a miracle.

Redact secrets and bodies. Codes and MX only. Slack and Drive are not archives. Do not mint SOC 2 or an inboxing KPI in the close. Send /security. 250-plus-junk is a filter ticket. Do not republish MX for Promotions.

Header From rewrite is a rejected proposal. Write it down so it does not return as a clever fix. MailerZ rewrites envelope only. Identity stays. Open-relay fantasies stay 550.

Close only with a new probe Message-ID in the document. Quarterly, read the folder for the same class. Three leftover-MX docs means the launch gate is theater. Fix the gate, not the tone.

Agencies share redacted leftover-MX postmortems so clients stop asking for backup MX. Link troubleshooting and delivery recovery. Do not invent a third incident religion in Slack.

Practice on a test alias in fifteen minutes so the real template stays one page. Unused templates grow novels. Used ones get filled at 6 p.m. One class, one fix, one owner, one calendar date. Then stop adding rules.

Handoff memo for the next operator

Postmortems fail when the template is a secret. Put the blank template and two filled examples in the same folder the on-call wiki already uses. The next operator should open one file and start typing, not ask Slack where the "good" template lives. Include the severity definitions you actually use, not a borrowed ITIL chart nobody follows.

Name the people who must review a Sev-1: founder or owner, the person who can change DNS, and the person who talks to the client. If those three are the same human, write that risk in bold. Single-person review is how polite fiction survives.

Record where logs live for MailerZ, the registrar, and the destination mailbox. A postmortem that says "we looked at logs" without paths is not reusable. The next incident will happen at 1 a.m. Paths beat memory.

Add the follow-up tracker you will actually update. A graveyard of unchecked boxes trains the team to ignore the template. Prefer three durable actions over twelve wishes. MailerZ HOLD reviews and SPF audits are durable. "Be more careful" is not.

Acceptance criteria before you call it done

A postmortem is done when the timeline has timestamps, the impact has numbers, the cause names a system not a mood, and every action has an owner and a date. If any of those four are missing, keep writing. A published draft that fails those tests trains the team to treat the template as theater.

Share the write-up with someone who was not in the incident channel. If they cannot retell the story in three sentences, the document is still insider shorthand. Fix the shorthand before you archive it.

Close the loop in the tracker you named in the handoff memo. An accepted postmortem with open actions is a bookmark, not a finish. MailerZ HOLD reviews and SPF audits should appear as dated work, not wishes.

FAQ

What is the safest way to handle email routing incident postmortem?
Template: summary, timeline UTC, MX before/after, history codes, classification, fix, detection gap, prevention rule, owners. Link probes. Do not invent SLAs in the close.
Does this require a new mailbox?
No. MailerZ is not IMAP. Keep Gmail or Outlook unless you need a suite for other reasons.
Will it work with Gmail or Outlook?
Yes as destinations. Self-send is not proof. Use a third mailbox and open original.
What DNS records are involved?
Exclusive MX, verification TXT, one SPF if you send-as. Leftover MX is a hard stop. Dashboard values only for sending.
What should I test before production?
A uniquely titled probe from an unrelated provider to each public alias. Confirm Header From and hop history.

Key takeaways

  • One class. One fix. One rule.
  • Codes and screenshots.
  • No blame novel.
  • No invented SLA or inbox rate.
  • Prevention has an owner.
  • Store clock if evidence died.
  • Third-mailbox QA.
  • Review repeats.

Conclusion

Write the routing failure so the next person does not repeat your Friday. Evidence, class, rule.

Start free, break a test alias on purpose, and fill the template once before you need it live.

Start free on MailerZ