Revenue Deliverability Infrastructure Assessment
Executive Summary
Northlane Software, Inc. ("Northlane") engaged Vaixus Technologies to assess the infrastructure supporting its outbound sales email program following a sustained decline in outbound reply and meeting-booked rates across its North American and EMEA sales development pods. Northlane treats outbound email as a revenue-critical system: it is the primary top-of-funnel channel for its Revenue Intelligence platform and supports prospecting, demonstration scheduling, and account management across a combined sales development and account executive organization of 54 representatives.
The assessment examined DNS infrastructure, authentication configuration (SPF, DKIM, DMARC), domain segmentation strategy, and the integration quality of Northlane's outbound technology stack.
Vaixus identified thirteen findings spanning DNS configuration, authentication posture, domain architecture, and vendor operations. Two findings are rated Critical: the primary corporate domain's SPF record exceeds the RFC 7208 ten-lookup limit and is intermittently evaluated as a hard failure by strict receiving systems, and one of Northlane's secondary outbound domains was provisioned inside the same Google Workspace tenant as corporate mail, causing it to share the corporate MX destination and trust boundary rather than remaining operationally isolated.
Environment Overview
Northlane's revenue organization relies on a modern outbound technology stack layered on top of Google Workspace. Outbound sending is distributed across dedicated sending platforms which route mail through secondary domains intended to be kept operationally separate from the corporate domain.
| Domain | Platform | Function |
|---|---|---|
| northlanesoftware.com | Google Workspace | Corporate mail, system of record |
| mail.northlanesoftware.com | SendGrid | Transactional (notifications, billing) |
| northlanehq.io | Smartlead | North America SDR cold outbound |
| northlane-connect.com | Instantly | EMEA SDR cold outbound |
Assessment Scope
- DNS infrastructure for all sending domains
- SPF, DKIM, and DMARC configuration and alignment
- MX configuration and inbound mail routing architecture
- Domain architecture and sending-domain segmentation strategy
- Third-party sending service configuration
- Endpoint security of employee workstations
- Web application security or source code review
- Internal network security and corporate firewall configuration
- Employee security awareness training
- Mail content, copywriting, or sequence messaging review
Assessment Methodology
This assessment follows the five-stage Vaixus Email Infrastructure Assessment Methodology.
Structured interviews to document intended architecture, ownership, and prior incidents.
Authoritative-record enumeration across all in-scope domains to establish the as-built configuration.
Controlled test messages sent through each sending platform with full header capture.
Direct review of administrative consoles to confirm published DNS records match configuration.
Consolidation of findings into severity-rated, business-impact-aligned recommendations.
Representative Engineering Evidence
The critical finding regarding MX trust boundary overlap (CS001-01) was identified during the DNS reconnaissance phase. The secondary domain, intended to be isolated, was found to be sharing the primary corporate Google Workspace MX cluster.
$ dig MX northlanehq.io +short
1 aspmx.l.google.com.
5 alt1.aspmx.l.google.com.
5 alt2.aspmx.l.google.com.
10 alt3.aspmx.l.google.com.
10 alt4.aspmx.l.google.com.
$ dig MX northlanesoftware.com +short
1 aspmx.l.google.com.
5 alt1.aspmx.l.google.com.
...
; ANALYSIS: The secondary domain shares the exact MX cluster of the corporate domain.
; A reputation event on the secondary domain has a credible path to affect the corporate cluster.
Executive Findings Summary
Vaixus identified thirteen total findings. The Critical and High severity findings requiring immediate executive attention are summarized below.
Business Impact & Remediation Strategy
The SPF lookup limit violation creates intermittent, hard-to-diagnose delivery failures against exactly the enterprise-gateway-protected recipients that represent Northlane's target buyer profile.
The corporate domain has no enforcement policy against spoofing, and the secondary outbound domain's inbound path is not isolated from corporate infrastructure.
Remove northlanehq.io as Workspace secondary domain; re-provision isolated MX. Correct primary domain SPF record to resolve ≤9 lookups. Begin staged DMARC enforcement ramp.
Author and adopt sending-mailbox warm-up policy. Rotate Google Workspace DKIM key to 2048-bit. Add DMARC rua reporting to remaining secondary domains.
Standardize DKIM selector naming across vendors. Evaluate/implement backup MX for meetnorthlane.com. Advance primary domain DMARC to p=reject.
Download the Complete Case Study
This webpage summarizes the investigation logic. The complete 28-page PDF report contains full DNS trace evidence, detailed technical findings, risk prioritization tables, and structured remediation guidelines.
Download Representative Report (PDF)Ready to begin an assessment?
Submit a request and we will review your domain, scope the engagement, and respond within one business day.
Request Assessment