In a real engagement, this note lists the deliverability and data-integrity checks I run before I believe any reported metric — sending domains and authentication, consent and suppression hygiene, identity stitching across app and email, and which instruments are known to lie. From the outside I can run almost none of these on Duolingo, which is itself the lesson: this is the part of the deliverable that is impossible to fake from public data.
What a public-info read can say is method, not verdict. A notification- and widget-led machine like this one lives or dies on signals that don’t survive naïve measurement: push opt-in rates by OS, iOS Mail Privacy Protection inflating any email open rate, and the gap between “notification sent” and “human actually came back.” On the deliverability fundamentals — SPF, DKIM, DMARC alignment, list hygiene, the unsubscribe path — I would assume nothing and verify everything against the actual sending infrastructure. None of that is visible here, so none of it is asserted.
The honest gap
The shortness of this section is the tell. Deliverability and data-trust work needs your DNS records, your ESP, your consent logs, and your event stream — the things a Diagnostic gets and a public-info sample never can. If a vendor claims a deep deliverability read of a company they have no access to, be skeptical.