A send that slows itself down before a receiver does it for you.
Segments, a drag-and-drop builder, a preflight that blocks bad sends, and a pacing controller that slows a campaign on live bounce and complaint data before a receiver does it for you.
- #Segments
- #Preflight
- #Pacing
- #Per-ISP
- #A/B-subject
- #Timezone-send
Lists, groups and segments
Audiences live in groups you can drag them between, so a campaign can target a whole group or individual lists. Segments are a visual AND/OR condition builder with a live estimate that updates as you edit.
A preflight that can say no
Unsubscribe header, DMARC, SPF/DKIM alignment, warm-up ceiling, link reputation, spam score, image-to-text ratio, merge-tag resolution, compiled size and consent evidence. A fail blocks scheduling. A warning requires an acknowledgement that is written to the audit log.
The audience scrub, shown
Suppression list, global suppression, role addresses, duplicate collapse, subscribed-only, previously hard-bounced, disposable domains. Every skipped recipient carries a reason, so you can see exactly why 128,430 became 121,340.
A pacing controller, not a firehose
A single leader ticks every five seconds, reading live bounce and complaint rates for this campaign over the last thirty minutes, and computes an allowed rate from your warm-up ceiling, plan limit, provider headroom and reputation multiplier.
Per-ISP pacing
Recipients are interleaved so no single provider receives a burst. Gmail receiving 40,000 messages in ninety seconds from a domain that has never sent 40,000 messages is the textbook way to get filtered.
Send in each recipient's local time
The audience splits into timezone buckets from contact attributes or historical open-time data, and each bucket gets its own sub-schedule. Or just pick a time and a timezone.
Draft to report, with a guardrail at every step.
- [01]
Audience
Pick lists, whole groups, or a segment. The estimate is live and it is the frozen number the send will actually use.
- [02]
Content
Subject and preheader with a mobile truncation preview and an optional A/B split. Then pick a template or open the builder.
- [03]
Preflight
Checks, the scrub funnel, the ISP distribution, and — above 25,000 recipients — an automatic seed test across eight providers before anything sends.
- [04]
Send and watch
A live screen: progress, per-ISP breakdown, a tailing event feed, current rate, ETA, and pause, resume and cancel that actually work mid-flight.
What happens, at which number.
These are our thresholds, not the provider's. Providers begin review around 5% bounce and 0.1% complaint. Ours are the inner wall and they must trigger first.
| State | Bounce rate | Complaint rate | Automatic action |
|---|---|---|---|
| Healthy | < 2.0% | < 0.05% | None |
| Watch | 2.0–3.0% | 0.05–0.08% | Internal flag and a dashboard notice |
| Throttle | 3.0–4.0% | 0.08–0.09% | Rate cut to 30%, owner emailed |
| Pause | ≥ 4.0% | ≥ 0.09% | Stop this plane, require human review |
| Emergency | ≥ 8.0% | ≥ 0.3% | Stop all planes, freeze, escalate to on-call |
A rate is only actionable above a volume floor. One bounce in twenty-five is 4% and means nothing, so below 500 messages in the window we use a Wilson lower bound at 95% confidence and cap new senders by the warm-up ladder instead of by rate.
- Campaign throughput
- Up to 1,000,000 recipients per hour
- What actually limits it
- Per-ISP pacing, not our hardware
- Audience freeze
- Materialised in batches of 10,000 before the first send
- Fan-out slice size
- 500 recipients, idempotent on re-run
- Provider bulk call
- 50 destinations per call
- Pacing tick
- Every 5 seconds, per running campaign
- Reputation multiplier
- ≥80 → 1.0 · 60–79 → 0.6 · 40–59 → 0.3 · <40 → pause
- Seed test threshold
- Automatic above 25,000 recipients
- One-click unsubscribe
- RFC 8058, injected on every campaign message, not toggleable
- Unsubscribe processing
- Synchronous, under one second
- Duplicate delivery
- Prevented by the recipient primary key, verified by recipient-side audit
- Post-send review
- Automatic reputation review scheduled 72 hours after completion
A bad campaign should never stop your password resets.
The campaign plane has its own isolated container at the provider, its own reputation policy, its own worker deployment and its own metrics. A campaign can be paused on its own numbers while the workspace stays healthy — and a workspace-wide problem never reaches the transactional plane by accident.