Yesterday I shipped an admin-only WordPress CRM with Cursor for a chocolate brand’s hotel and corporate gifting outreach. The CRM could import research, park drafts, and require a typed SEND confirmation — and it was still useless until mail actually left the brand domain cleanly.
So I stopped polishing the pipeline UI and fixed the mailbox.
What I actually shipped
- Google Workspace mail brought up for the brand domain
- WordPress SMTP wired with an app password (outbound through the authenticated mailbox)
- SPF, DKIM, and DMARC (
p=none) added at the DNS registrar for the sending domain - A real test message from the outbound mailbox that passed SPF, DKIM, and DMARC
- Visible From kept on the authenticated sending domain; Reply-To pointed at the brand’s preferred customer-facing address
- Branded HTML Wave 1 hotel outreach refined (logo, business-toned About box, signature with WhatsApp / Instagram — no brochure PDF on first touch)
- First hotel wave sent only after auth passed
This is not a deliverability product pitch. It is the boring gate that turns a CRM from a draft folder into outbound.
Why auth came before the wave
The CRM send path already refused to fire on import. That friction does not help if the first real send lands in spam — or never leaves the server — because the domain records are wrong.
I treated three checks as the ship bar:
- Mailbox exists and can send. Google Workspace live for the brand domain; SMTP authenticated with an app password.
- DNS proves the domain. SPF + DKIM + DMARC (
p=nonewhile we learn) published at the registrar, not “we’ll add them later.” - A real message passes all three. Not a simulator screenshot — an actual test from the outbound mailbox.
Only after that did Wave 1 leave the CRM.
Identity: From vs Reply-To
One sharp edge from the CRM build carried over: SMTP identity is not the same as “looks good in the editor.”
- Visible From stayed on the authenticated sending domain — the mailbox that actually signs the message.
- Reply-To pointed at the brand’s preferred customer-facing address so hotel replies land where the team watches.
Mismatch here is how you get “SMTP worked in a test” and “production From fails DMARC.” I kept them honest on purpose.
What broke earlier
- Missing MX / SPF: Brand-domain mail could not land cleanly inbound, and outbound had nothing trustworthy to advertise. The CRM was ready; the domain was not.
- Auth mailbox vs visible From: Authenticating as one mailbox while showing another From is a fast path to spam folders and failed alignment.
- Sending before auth: Tempting once drafts look polished. We waited. Branded HTML without SPF/DKIM/DMARC is still a spam risk.
What I left out on purpose
- No brochure PDF attached on first touch — samples / brochure stay on request
- No invented inbox placement rates or “100% deliverability” claims
- No blast of hundreds of hotels before the test message passed
- No rename of the brand in public — this stays a chocolate brand build log, same as the CRM post
Ship checklist (if you copy the pattern)
- Bring up the real mailbox (Workspace or equivalent) before you call outbound “live.”
- Publish SPF, DKIM, and a starter DMARC policy at the registrar that owns the sending domain.
- Send a real test from the outbound mailbox and confirm SPF + DKIM + DMARC pass.
- Keep visible From on the authenticated domain; use Reply-To for the customer-facing inbox if they differ.
- Only then fire Wave 1 from the CRM — drafts parked until an admin confirms.
FAQ
Is this a mustafa.net mail product?
No. It is the auth + first-wave story for a chocolate brand’s WordPress outbound stack. The CRM build is here.
Why DMARC p=none?
I wanted monitoring without rejecting mail while records settle. Tighten later once alignment stays clean.
Why not send the brochure on first touch?
First touch is a short branded intro. Brochure and samples stay behind a reply — fewer attachments, clearer ask.
