Customer Vetting for ESPs
The M3AAWG Vetting BCP digested — pre-send vetting questionnaires (corporate entity, infrastructure, sending history, list practices), red flags, the test-send methodology, ongoing post-send monitoring triggers, and vetting tools (WHOIS, D&B, PACER).
The M³AAWG Senders BCP makes both pre-send and post-send customer vetting mandatory for ESPs. This article digests the document it points to: the MAAWG Vetting Best Common Practices (BCP), November 2011 — a "how-it's-done" methodology guide assembled from the vetting programs of M³AAWG member ESPs. It deliberately does not prescribe specific metrics (e.g., complaint-rate thresholds — for those see Metrics & Benchmarks); not every technique fits every size of ESP or client. Fraud-prevention practices from the M³AAWG Hosting Abuse BCP (March 2015) that generalize to ESP onboarding are folded in at the end.
Related: Abuse Desk Operations (what happens when vetting fails), Compromised Accounts (distinguishing bad customers from hijacked ones), Consent Methods (the list-quality spectrum vetting probes for).
Why vet
- ESPs sending on behalf of clients are at the mercy of their worst clients' worst practices: e-appending, poorly run affiliate programs, and past data corruption damage delivery and reputation not just for the problem sender but for all the ESP's other clients (shared IPs, shared domains, shared brand with mailbox providers).
- Pre-send vetting preempts damage to recipient domains and to the ESP's own sending reputation; post-send vetting catches bad clients who passed the initial assessment.
- Vetting is also a client-development tool: in-depth analysis of how a prospect builds and maintains lists reveals correctable issues, and the process is the ESP's best opening to coach prospects and existing clients on best practices and compliance.
Pre-send vetting questionnaires
Question sets for customer-facing staff (sales, compliance) to establish whether a prospect qualifies for service, with the rationale and red flags per question.
Corporate entity formation and history
- Name and address of the company?
- How long has the company operated?
- Any additional names or locations, now or in the past?
- Who are the principals?
- Who will be the primary point of contact?
Verification: commercial entities generally must file with their local taxation authority — articles of formation, business license, or DBA (assumed-name) filings; in the US these sit with the state Department of State, most of which offer free online access. Red flags: absence of filings (especially when the prospect claims a long business history); a very short history; principals who form and disband multiple entities within a short period.
Infrastructure and process
- Worked with an ESP before? Which, and why did you leave? — Multiple prior ESPs, or leaving "for deliverability reasons," should generally be treated as red flags; dig into the real reason for switching.
- Which IP addresses did you previously mail from? — Check the reputation history of the prior IPs; previously blocked or tainted IPs are a problem signal to investigate.
- Which domains do you own and use for mailing? How long owned? Registered with anonymized WHOIS? — Hiding behind anonymized registration is a common abusive-sender tactic; legitimate permission-based senders have no need to hide corporate contact information.
- Do you monitor role accounts (
postmaster@,abuse@)? Who manages this? — Complaints arrive at these addresses regardless of list quality; maintaining and monitoring them is an industry best practice per RFC 2142 (see Abuse Desk Operations). - Do you control your DNS? Any authentication protocols in use? — DNS control means the sender can publish SPF/DKIM records authorizing the ESP.
Sending history and patterns
- Message types and proportions? Samples? — Promotional/marketing mail draws higher complaint rates and more delivery issues than transactional/alert mail even at equal permission levels; the mix sets expectations for issue frequency and magnitude.
- Do you segment, or blast the whole list? Segmentation criteria? — Segmented, targeted campaigns outperform generic full-list sends.
- Mailing frequency, and date of last send? — Timely, relevant, expected mail with met frequency expectations produces fewer issues; a long-dormant list is itself a risk (see List Hygiene).
- Do you share your list with partners/advertisers/other brands, or send on behalf of third parties? Is sharing disclosed at collection, and how? — Unexpected third-party mail generates complaints even from strongly permissioned recipients.
- Affiliate marketing? Own program or third-party-managed (e.g., Commission Junction)? — Affiliate mail bears additional scrutiny: the category has historically been an abuse vector; programs run by well-known reputable third parties are typically less problematic than do-it-yourself ones.
- Ever appeared on a blocklist? Listing reason and how you addressed it? — Constructive answers involve reviewing list acquisition/hygiene and tightening practices. Any answer that hints at changing infrastructure to evade a listing is a red flag. (See Blocklists & Spamhaus.)
- Metrics for the last 3 months (deliverability, complaints, etc.)? — Historical performance indicates list quality; poor history means deficient list assembly/maintenance and warrants extra scrutiny.
List, data collection and management practices
- How do recipients opt in? List every collection point (online and offline) and how consent/notification is conveyed at each. — Senders should keep an auditable trail demonstrating the method, date, and source of permission for each recipient or group.
- Were you (or your prior ESP) on FBLs? What action did you take on complaints? — Best practice: unsubscribe complainers and investigate root cause. A complaint may reveal poor permission-gathering (expect the sender to have reviewed how permission was collected for that recipient and similarly sourced cohorts, possibly reconfirming them) or, where permission is strong, a malformed unsubscribe signaling unmet content/frequency expectations.
- How did you manage unsubscribes? Are unsubscribed addresses removed from the list you're bringing us? — Removal is a legal requirement in the US, Canada, and the EU; suppression lists must be maintained and portable to new sending platforms.
- How did you manage bounces? Hard (5xx) vs soft (4xx) treated differently? — Best practice: remove addresses hard-bouncing multiple times in a given period (the prior ESP may have done this automatically). Recurring high generic soft-bounce rates indicate content or reputation problems; expect the prospect to have resolved persistent soft-bouncing. (See DSNs.)
- Ever purchased a list? Rentals, affiliate marketing, co-registration? — Affirmative answers are red flags. Purchased lists are addresses that never consented; many ESPs prohibit them outright. Review all customer-supplied lists for purchase indicators — e.g., column headers containing terms like "jigsaw" or "append". Co-registration may technically be permission-based but the permission is usually uninformed; such lists perform about as badly as purchased ones.
- Does the list contain distribution/role accounts (
sales@,staff@,support@)? May we review the list before provisioning? — Role accounts are essentially never used to opt in; their presence indicates poor acquisition (including purchase). Review supplied lists for role accounts and known trap addresses (see Spam Traps). - Published privacy policy on your website? — Absence is a red flag; where one exists, verify it does not contradict the practices described in the questionnaire answers.
Post-send vetting
Test send
After satisfactory pre-send vetting, allow a test send to a small, randomly selected segment of the prospect's lists before unfettered production provisioning. Size varies with total list size, but tests under ~10,000 recipients may not yield statistically significant results. Metrics to review after the test (same set as ongoing customer monitoring):
- Overall bounce rate
- Relative percentage of the various bounce types
- Open and click-through rates
- Unsubscribe rate
- Direct complaints
- Opt-out comments
- Spam complaint rate
- Complaint rate by domain or FBL
Any metric that varies significantly from existing senders of similar mail bears additional scrutiny.
Ongoing monitoring triggers
Once vetted and provisioned, continuously monitor the same metrics, plus watch closely for:
- Significant, sudden increases in list size
- Content changes following significant changes in metrics
- Privacy-policy changes following significant changes in metrics or volume
- Frequent changes of customer contact or payment information
- Stops and starts in activity — possible attempts to dilute poor reputation metrics across more than one ESP
Tools and resources
WHOIS
Use WHOIS during vetting to verify the prospect represents its domains correctly and transparently. M³AAWG sender best practice: domain ownership should reflect verifiable information, not obfuscated or hidden behind a privacy proxy with a P.O. box. WHOIS also verifies contact information for a company's abuse desk.
- Good registration pattern: registrant is the actual company with a real street address; administrative and technical contacts name the organization with working role emails (
info@,dnsadmin@) and phone numbers. - Bad registration pattern: registrant is a privacy-proxy service ("I am a Proxy, Inc."), P.O. box address, contact emails routed through the proxy (
EXAMPLE.COM@iamaproxy.proxy), placeholder phone/fax numbers.
(2011 caveat: post-GDPR WHOIS redaction has made registrant data much less available than when the BCP was written; the principle — transparency of sender identity — still applies, via RDAP, business registries, and direct verification.)
Corporate-entity research
| Tool | Use |
|---|---|
| Dun & Bradstreet (dnb.com) | Business information |
| LexisNexis Risk Solutions | Financial and background information |
| Better Business Bureau | Complaints against a business |
| PACER (pacer.gov) | US appellate/district/bankruptcy court records — was the entity or a principal party to email-related legal action? |
| State Department of State filings | Formation documents, licenses, DBA filings (mostly free online) |
Fraud-prevention practices (Hosting Abuse BCP)
The hosting/cloud BCP's prevention chapter adds platform-side mechanics that generalize directly to ESP onboarding:
- Institute preauthorization of new accounts — no sending before review.
- Personally contact accounts deemed suspicious.
- Keep records of previously terminated fraud accounts and match new signups against them.
- Put limits on new accounts that require credible, demonstrated customer need to be raised.
- Fraud-score prospective accounts and auto-reject those below threshold where possible.
- Arm sales teams with specific questions and known red-flag statements to spot fraud at first contact; train customer-facing staff (support, sales, marketing) to recognize when a prospect's stated practices violate the AUP.
- Tiered rights allocation: restrict new accounts' API access, sending/domain-creation capacity, and bandwidth; widen access progressively with tenure and clean reputation. Reserve elevated privileges for customers who are proactive against abuse, hosted over ~12 months, and responsive to inquiries — and revoke them on repeated abuse or non-responsiveness.
- Collect a complete client identity during vetting and use it to authenticate ongoing communications (passphrases, PINs, last four digits of the payment card, named approved contacts).
- Contract for security: customer agreements should obligate clients to maintain a secure environment, keep software up to date, and notify the provider of breaches.
These feed the account-compromise and outbound-abuse controls in Compromised Accounts; registration-abuse detection patterns (mass signups, stolen/disposable cards, implausible business claims) are covered there as well.