Domain health
Press Check now on the Inboxes page. Each domain your inboxes send from gets the six checks receivers care about, and anything that is not right says what to change.

The one record that names the servers allowed to send as the domain. No record, two records, or a record ending in +all fails, with the record to add or the change to make.
A signing key at the google, selector1 or selector2 selector, or at a selector you type in. No key fails, with where to turn DKIM on in Google Workspace and in Microsoft 365.
A policy at _dmarc. No record fails. A policy of none is a warning, because it watches but protects nothing. Quarantine or reject passes.
Somewhere for replies and bounces to go. A domain that cannot receive mail fails, since some receivers distrust it.
The sending domain and your tracking domain against the Spamhaus domain blocklist, and your mail servers against its address blocklist. A listing says what to do about it. A listing on Google’s or Microsoft’s shared servers is a note, not a failure, because nothing on your side can change it.
A lookup that does not answer shows as could not check, never as clean or as listed. Before trusting Spamhaus, the check asks about Spamhaus’s own test entry, and when that does not come back listed, the answer for your domain is not believed either. Each lookup gives up after three seconds.