Terms in this channel
BIMI
BIMI logo signals, DMARC enforcement, and provider scope.
Read the answerEmailCAN-SPAM
US commercial-email scope, requirements, and opt-out timing.
Read the answerEmailDKIM
DKIM signing, cryptographic requirements, and alignment.
Read the answerEmailDMARC
Learn how DMARC works, what email senders need, what p=none permits, and how to roll out an aligned policy safely.
Read the answerEmailDomain reputation
Authenticated-domain reputation in Google reporting.
Read the answerEmailEmail deliverability
Inbox placement and delivery outcomes.
Read the answerEmailGmail bulk sender requirements
Gmail's bulk-sender scope and published authentication requirements.
Read the answerEmailIP reputation
Sending IP reputation and its provider scope.
Read the answerEmailList-Unsubscribe header
List-Unsubscribe headers and one-click boundaries.
Read the answerEmailOne-click unsubscribe
RFC 8058 headers and endpoint requirements.
Read the answerEmailSender reputation
Provider-scoped sending reputation and spam signals.
Read the answerEmailSpam complaint rate
Provider-scoped complaint measurements and thresholds.
Read the answerEmailSPF
What SPF authorizes and what it does not prove.
Read the answerEmailSuppression list
Amazon SES suppression scope and reasons.
Read the answerEmailYahoo sender requirements
Yahoo authentication, unsubscribe, and spam guidance.
Read the answerWho this applies to#
- The cited rules apply to commercial email and to senders reaching personal Gmail or Yahoo recipients, with scope that varies by authority and provider
What Email compliance requires#
- Commercial email needs accurate routing and subjects, sender identification, a postal address, and a working opt-out process under the cited US guidance
- Gmail and Yahoo publish additional authentication and unsubscribe requirements for bulk senders reaching their recipients
Separate legal obligations, mailbox-provider rules, and protocol mechanics before deciding which requirement applies
What this does not require#
- Gmail's minimum bulk-sender DMARC rule permits p=none, so it does not require a quarantine or reject policy at that minimum
Common mistakes#
- Treating one provider's sender guidance as a worldwide email law
- Treating authentication, unsubscribe handling, and inbox placement as one test
Email compliance checklist#
- Identify the law and recipient geography that apply
- Check the current rules for every mailbox provider you send to at scale
- Verify authentication, unsubscribe handling, and suppression separately
OnVoard's take#
Build the audit in layers. Keep those layers separate. Start with law, add each mailbox provider's current rules, then test the protocols and operational controls that satisfy them.