Infrastructure is a commodity. This part is the product.
Per-plane reputation isolation, a warm-up ladder that advances on health rather than time, thresholds that trigger below the provider's, and a 0–100 score shown with every contributing factor broken out.
- #Reputation
- #Warm-up
- #Postmaster-Tools
- #Seed-tests
- #Suppression
- #RFC-8058
Three isolated reputations
A compromised mailbox, a buggy password-reset loop and a purchased-list campaign are three different failure modes. Each plane gets its own container at the provider, with its own identities, metrics and automatic pause policy.
Our wall is inside theirs
Providers begin review around 5% bounce and 0.1% complaint. We flag at 2%, throttle at 3% and stop the offending plane at 4% — with a minimum sample size, because one bounce in twenty-five is 4% and means nothing.
The Gmail blind spot, addressed
Gmail has no per-message feedback loop, so a measured complaint rate systematically understates reality. We register every sending domain with Postmaster Tools, put a structured Feedback-ID on every message, seed-test before large sends, and treat a falling open rate with rising unsubscribes as a complaint signal.
A score you can argue with
0–100 per workspace per plane, recomputed every fifteen minutes, smoothed with a seven-day average — and shown with every contributing factor and its point impact. Opaque scoring generates support tickets and teaches nobody.
Blocks are not bounces
A rejection caused by receiver policy or sender reputation is about us, not the recipient. Treating it as a hard bounce would destroy a customer's list for a problem that was ours, so we classify it separately and raise a reputation alert instead of suppressing the address.
Honest open tracking
Apple Mail Privacy Protection pre-fetches every remote image whether or not a human looked. So we show three numbers — total, estimated human, and machine or proxy — compute geography and device only from non-proxy events, and weight clicks far above opens in scoring.
What happens when something goes wrong.
The incident playbook is written down in advance because writing it during an incident is how deadlines get missed.
- [01]
Detect
A threshold breach, a Postmaster Tools drop, a blacklist hit or a provider finding. Blacklist monitoring runs hourly across eight sources for every sending IP and every customer domain.
- [02]
Contain
Pause the offending plane for the offending workspace only. Never the whole account, never the other planes.
- [03]
Assess and act
Which campaign, which list, which import, what content — with the import quality report and the consent evidence pulled together. Then purge the segment, suppress the affected recipients and drop a warm-up rung.
- [04]
Recover
A controlled re-ramp at 25% of previous volume, daily monitoring for fourteen days, and a post-incident note on the workspace record.
You climb by being healthy, not by waiting.
Skipping warm-up is the most common cause of a new sender landing in spam. Every rung is conditional on the numbers, not on the calendar — and any threshold breach freezes the ladder for 48 hours and drops you a rung.
A verified business starts at rung four instead of rung one. A workspace migrating from another provider can submit evidence — previous volume, past 90-day bounce and complaint statistics — for an accelerated ladder, subject to review. The cap is per plane: transactional email to an existing app's engaged users is throttled far more gently than a cold campaign.
| Day | Daily cap | Advance requires |
|---|---|---|
| 1 | 500 | — |
| 2 | 1,000 | Bounce under 3%, complaint under 0.08% |
| 3 | 2,500 | Same |
| 4 | 5,000 | Same |
| 5 | 10,000 | Same |
| 6 | 20,000 | Same |
| 7 | 35,000 | Same |
| 8–14 | ×1.7 per day | Open rate at or above 8% |
| 15–30 | ×1.5 per day | Postmaster Tools reputation not Low or Bad |
| 30+ | Plan limit | Manual review above 1M a month |
- Reputation score recompute
- Every 15 minutes, per plane
- Score smoothing
- 7-day exponentially weighted average
- Evaluation windows
- Rolling 1 hour, rolling 24 hours, per-campaign live
- Minimum sample size
- 500 sent; below that, a Wilson lower bound at 95%
- Postmaster Tools spam rate targets
- Under 0.10% · alarm 0.20% · emergency 0.30%
- Seed providers
- Gmail, Outlook.com, Yahoo, Yandex, GMX, Zoho and two more
- Blacklist sources
- Spamhaus SBL/XBL/PBL/DBL, Barracuda, SURBL, SpamCop, Invaluement
- Blacklist check frequency
- Hourly
- Soft-bounce suppression
- After 5 soft bounces in 30 days
- Hard bounce and complaint
- Suppressed permanently, never auto-expired
- Dormant contacts
- Flagged at 180 days with no engagement, excluded from campaigns
- Unsubscribe handling
- RFC 8058 one-click, processed synchronously in under one second
Nobody else shows you the per-ISP numbers. We do.
Delivery, bounce and complaint rates broken down by receiving provider, the Postmaster Tools reputation trend, a DMARC aggregate-report summary showing who is sending as you, and live blacklist status. This is the view that keeps customers from leaving, because it is the one nobody else is willing to show.