Signals

Are companies really going to hand DNS administration to marketers?

Across 117 job postings in our hiring scan, email ownership now lands on marketing under four different titles — and the job descriptions name SPF, DKIM and DMARC directly. So we audited the sending domain of every company doing the hiring.

TL;DR  They already have. Across 117 job postings from 117 companies in our hiring scan, email ownership now lands on marketing under four different titles — and the descriptions name SPF, DKIM and DMARC directly. Our audit of all 117 sending domains in that dataset found 62% with zero outbound authentication gaps.

HireAmino · Hiring figures from our own scan · DNS audited live over DNS-over-HTTPS · job-description quotations re-verified word-for-word against the live postings

Free email deliverability assessment powered by Amino Check SPF, DKIM, DMARC and alignment in one pass

Table of contents

  1. Are companies really handing DNS to marketers?
  2. What does the job actually ask the hire to do?
  3. What state is that DNS actually in?
  4. Does email posture actually drift?
  5. Which companies are most exposed?
  6. Why would one company open five email roles at once?
  7. What did we not measure?
  8. What should you do about it?

Are companies really handing DNS to marketers?

Yes, and it is already routine. Across 117 postings tracked in the HireAmino deliverability hiring scan over roughly three months, email ownership arrived under Lifecycle Marketing (46 postings), an Email-titled role (26), Marketing Operations (20), or a general growth title (21) — every one of them a marketing-side seat, and none of them routing authentication to a platform team. The titles disagree, which is itself the finding: a function with a settled home produces a settled title, and this one has not got one yet.

Title familyPostingsShare
Lifecycle Marketing4639%
Email-titled (Email Marketing Manager, Email & SMS, …)2622%
Other growth and demand-gen roles2118%
Marketing Operations / Automation2017%
Deliverability-titled22%
CRM-titled22%
Total117100%

Each of the 117 postings is a distinct company in the same scan — this is not one employer reposting a vacancy. Sourcing was Indeed (43 postings), Glassdoor (41) and applicant-tracking boards (27), with the remaining 6 from unspecified aggregators. The split by segment was 72 B2C to 45 B2B.

The title tells you less than the bullet list does

Because the titles disagree, the only reliable way to identify this role is to read what it is accountable for. Three responsibilities recur across every title family in our scan:

That last item is what did not used to appear in marketing job descriptions, and it is the reason this scan is worth running at all.

Two employers in the scan have now stopped burying it in the bullets and put it in the title:

Two out of 117 is not a category yet. It is the point at which a responsibility that has been travelling inside other roles starts to get its own name.

It also shows how far ahead of the configuration the hiring can run. Native Commerce is recruiting a dedicated deliverability lead while its own sending domain publishes DMARC at p=none — a policy that asks receivers to do nothing. That is not a gotcha; it is the most honest possible statement of why the role exists.

The strongest counter-argument is that none of this is new — marketing operations has owned deliverability for years. That is fair, and the pattern predates the scan: Replit's first lifecycle hire was already a deliverability story before this scan began, and the function has been senior enough to warrant a director. What the scan adds is scale, spread across four title families and both segments, and the specificity of naming the authentication records out loud rather than asking for "email experience".

What does the job actually ask the hire to do?

It asks them to run the deliverability maintenance loop, not to set it up once. Two postings in our scan — both still live and re-verified word-for-word before publication — state it almost identically, despite sitting in different departments, at different sizes of company, in different segments.

Sleeper, the fantasy-sports app, is hiring a Lifecycle Marketing Manager into its Product organisation. Sleeper's posting in our scan, verified live word-for-word on its public applicant-tracking board before publication, states that this is "a rare zero-to-one role" and lists as a headline responsibility:

"Strengthen email as a channel. Own email deliverability end to end: domain warm-up, list hygiene, and engagement-based sending."

Pylon, a B2B customer-support software company, is hiring a Marketing Operations Lead into GTM. Pylon's posting in our scan, verified live word-for-word on its public applicant-tracking board before publication at a posted range of $150–180K, assigns the same accountability with more infrastructure detail:

"Own email deliverability: Keep marketing sends landing in the inbox, sending-domain health, SPF/DKIM/DMARC, list hygiene, and deliverability issues before they affect reach."

Read those two bullets side by side and the answer to the headline question is already settled in practice. One is a product-org hire at a consumer app, the other a go-to-market hire at a B2B SaaS, and both expect one person to hold DNS-level authentication records and campaign strategy in the same head. The mailbox providers push in the same direction: Google's email sender guidelines, instruct senders to "Keep spam rates reported in Postmaster Tools below 0.10% and avoid ever reaching a spam rate of 0.30% or higher" — a threshold nobody can hold by configuring something once, because nothing notifies you when you cross it.

The ask is getting more specific, not less

Three postings from the most recent week of the scan show the requirement hardening past "familiarity":

EmployerWhat the posting asks for
Wolfe, LLCA 90-day success metric of 95% inbox placement with complaints and unsubscribes under 0.3%
Centric BrandsOwnership of SPF, DKIM, DMARC and BIMI across a multi-brand domain portfolio, at director level ($160–180K)
KnowledgeCityDomain and IP warm-up named explicitly — in a specialist role, not a leadership one

A measurable inbox-placement target in a marketing job description is a different maturity level from asking for experience with deliverability. So is putting warm-up in a specialist brief: the responsibility is moving down the seniority ladder as well as across the org chart.

What state is that DNS actually in?

Better than the hiring urgency suggests. We established and confirmed a sending domain for all 117 companies in the scan and audited every one against live DNS. 72 of 117 (62%) have zero outbound authentication gaps. No audit returned an inconclusive result.

ControlPassingShareLane
DMARC published113/11797%Outbound
SPF valid108/11792%Outbound
DMARC rua reporting102/11787%Outbound
DMARC enforced (quarantine/reject)86/11774%Outbound
DKIM key found and modern95/11781%Outbound
BIMI28/11724%Brand-optional
TLS-RPT2/1172%Inbound-only
MTA-STS1/1171%Inbound-only
DANE1/1171%Inbound-only

The lane column is the point. A single blended "gap score" would have rated most of these companies a 3 or worse and made them look like they were in deliverability trouble. They are not. MTA-STS, TLS-RPT and DANE govern mail arriving at a company; they have no bearing on whether the marketing mail their new hire sends will land. Strip the inbound controls out and the picture inverts: the outbound authentication being handed to a marketer is, in roughly three cases out of five, already correct.

Only three companies in the entire scan publish any inbound control at all:

Getting to full coverage moved the number, and downwards. An earlier cut of this dataset reported 68% clean across 82 companies, because 17 domains had been excluded where we could not confirm the company's identity. That exclusion was not neutral: the companies we failed to match were disproportionately ones whose websites block automated requests, and they turned out to be gappier than average. Resolving all 17 and folding them back into the sample dropped the clean rate from 68% to 62%. A sample that quietly drops the hard-to-verify cases will flatter the result.

It has been stable since. A further 18 companies entered the scan in its most recent week and were audited on the same basis; the clean rate across all 117 in this dataset is still 62%, and the size gradient below is unchanged to the percentage point. That is the first evidence we have that this figure is a property of the population rather than of our sample.

The most common real defect is not a missing record but a weak one. Eleven of the 117 domains sign with a 1024-bit RSA DKIM key, which is below the modern bar and matches what we found when we measured the Fortune 50's email cryptography.

So the risk is custody, not repair

That reframes the job. The person taking this role is not inheriting a broken configuration to fix — they are inheriting a working one to not break, usually without the access to change it. That is a harder brief than it sounds, and it is the opposite of how these roles are usually pitched. We have argued that mailbox providers score one sending identity while the org chart splits its levers across two teams; this data says the levers are now mostly in decent shape, and the open question is who is allowed to touch them.

Does email posture actually drift?

Less than we expected, and this cuts against our own product pitch. Of the 20 domains in our earlier sample, re-audited eight weeks later, 19 were unchanged on every bucket. The single change was an improvement: US Water Systems fixed a missing SPF record and moved DMARC to enforcement.

We think the honest reading is that authentication does not rot on a weekly clock. It breaks on events — an ESP migration, a vendor changing its sending ranges, a record quietly exceeding the RFC 7208 ten-lookup limit as tools are added. That is why a new platform doesn't inherit your good name and why nobody emails you an error when your SPF breaks: the failure is silent and event-driven rather than gradual. An eight-week window with no migrations in it is exactly the window in which you would expect to see nothing, so treat this as a bound on the drift rate, not a refutation of it.

Count your SPF lookups powered by Amino See how many of the 10 permitted your record really uses

Which companies are most exposed?

The smallest ones, and the gradient is steep. Banding the 117-company sample by headcount, companies under 200 employees are about half as likely to have clean outbound authentication as companies over 1,000 — and exactly half of them enforce DMARC at all.

Company sizeDomainsZero outbound gapsDMARC enforced
Under 200 employees3413 (38%)17 (50%)
200–1,000 employees5537 (67%)44 (80%)
Over 1,000 employees2822 (79%)25 (89%)

That is the sharpest result in the dataset, and it is the one that should change behaviour: the companies least able to absorb a deliverability problem are the ones most likely to have one. A sub-200-person brand hiring its first lifecycle owner is handing that person a sending identity with no platform team behind it and, in half the cases in this sample, no DMARC enforcement to inherit.

Every outbound gap we found is specific and fixable, and none of them requires a platform team:

That last one is worth sitting with rather than scoring. Pylon wrote one of the sharpest deliverability job descriptions in the scan and still has a weak key, which is not hypocrisy — it is evidence that writing the requirement down is the first step, not the last, and that key strength is a blind spot almost everyone shares.

Why would one company open five email roles at once?

Because they are building the function, not backfilling a departure. Five companies in the scan were running multiple simultaneous email or lifecycle requisitions:

A single opening is ambiguous — someone left, and the seat needs filling. Simultaneous openings across email operations and lifecycle strategy are a structural bet that this work needs more than one person, and every one of those five companies audited clean on outbound authentication, which fits the custody reading rather than the repair one.

What did we not measure?

Five things, and each limits how far this finding travels.

What would prove us wrong: a comparable scan showing email ownership routed to platform or engineering teams, or a re-audit finding outbound authentication substantially worse than roughly three-fifths clean. We will re-run both and publish the delta, including results that go against us.

What should you do about it?

If you are hiring for this role, write the infrastructure into the requirements the way Pylon did, then decide before the person starts whether they can actually change a DNS record or only request one. Our audit says you are probably handing over something that works; the gap between accountability and access is what turns that into a liability.

If you just took the job, your first week is an inventory, not a campaign. Find out what is authorised to send as your domain, whether alignment passes, and whether DMARC is actually enforced — run an audit of your SPF, DKIM and DMARC setup before you inherit a problem you did not create. If bounces are already high, treat it as an acquisition question rather than a sending one, because your bounce rate is usually a list problem.

If you already own it and everything looks fine, our own data says it probably will stay fine until something changes — a migration, a new vendor, another include: pushing SPF past ten lookups. Those are the events worth watching for, which is the argument for monitoring tied to change rather than a quarterly check, and for warming a domain deliberately before volume arrives rather than after. Scaling sends without scaling the infrastructure is how an AI sequencer scales the sending but not the landing.

Free tools

Key takeaways

FAQ

Should a marketer be responsible for DNS records like SPF and DKIM?

In practice they already are. Every one of the 117 postings in our scan placed email ownership in a marketing-side seat, and the job descriptions increasingly name SPF, DKIM and DMARC directly. The practical question is not whether marketing should own it but whether the owner has permission to change a DNS record or only to file a request — accountability without access is where the role fails.

What job title should I use to hire someone for email deliverability?

There is no settled answer, which is why the requirements matter more than the title. In our 117-posting scan the three viable families were Lifecycle Marketing Manager (39%), an Email-titled role such as Email Marketing Manager (22%), and Marketing Operations (17%); two employers have now put Deliverability in the title itself. Choose based on whether campaign strategy or systems ownership should lead, and write the deliverability responsibilities in explicitly either way.

Is MTA-STS or DANE a deliverability problem if I do not have them?

Not for your outbound mail. MTA-STS, TLS-RPT and DANE protect mail arriving at your domain, so their absence says nothing about whether the campaigns you send will reach the inbox. In our audit, MTA-STS and DANE were each absent on 116 of 117 domains, including companies whose outbound authentication was flawless. They are worth adopting on their own merits and should not be counted as sending gaps.

How fast does email authentication break once it is set up?

Slowly on a calendar, suddenly on an event. Re-auditing 20 domains after eight weeks, we found 19 unchanged and one improved. The realistic failure modes are triggered by change — an ESP migration, a vendor altering its sending ranges, or an SPF record crossing the RFC 7208 ten-lookup limit as tools are added — rather than by gradual decay.

How was this data collected?

The HireAmino deliverability hiring scan tracked 117 email-ownership job postings from 117 distinct companies over roughly three months, sourced from Indeed, Glassdoor and applicant-tracking boards and filtered for recency and US English-language roles. Title, date, segment and company-size figures come from structured fields in that dataset. DNS posture was measured over DNS-over-HTTPS using the same open-source engine that powers our free audit tool. A sending domain was established and confirmed for all 117 companies — from the domain already on file, from a careers page on the company's own domain, by name with live homepage confirmation, or by hand where automated matching failed.

Sources

Free deliverability monitoring powered by Amino We watch your records and email you when one breaks
Talk to the founders More signals