Skip to content

[Human & Operations] Verify PostKit production email branding in DNS and mailboxes #12

Description

@patoperpetua

Parent: #6
Imported from: singleton-sd/poc-plattform-kit#280

This is Human & Operations work for PostKit production (ssd-postkit-api-prod-ae / rg-ssd-global). The original poc-plattform-kit #280 remains open for the first-consumer cutover on that PoC.

Goal

Complete the operational verification gate for branded/authenticated transactional email on the shared PostKit Function App — proving live DNS, auth alignment, and (where supported) BIMI presentation.

Checklist

DNS provisioning

  • Run the PostKit Forward Email provisioner for the production sending domain(s) with BIMI flags if applicable.
  • Confirm Forward Email verify-records / verify-smtp succeed (or exit 0 with documented pending-DNS message, then re-run until green).

Automated validation

  • Set EMAIL_VALIDATION_* env vars (or pass CLI args) matching production config.
  • Run branding validation from an environment with outbound DNS + HTTPS; exit 0.

Auth headers (transactional send)

  • Send a test transactional / contact email from the production Function (not the development provider).
  • Confirm SPF, DKIM, and DMARC pass with identifier alignment in message headers.

BIMI presentation

  • Verify logo display in at least one BIMI-capable provider (e.g. Yahoo, Apple Mail).
  • Document Gmail result separately (VMC/CMC required — track under the VMC issue).

App settings alignment

  • Confirm EMAIL_FROM_ADDRESS, sending domain, DKIM/DMARC/BIMI settings match Route53 / Forward Email reality.
  • Confirm CONTACT_EMAIL_PROFILES_BY_HOST matches allowlisted consumer hosts.

Done when

Checklist items are checked with evidence in issue comments (no secrets). Close this issue when complete.

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-requirementsGoal, scope, or acceptance criteria are not yet resolved — refinement work, not implementation work

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions