emailmarketing.net

Customer Vetting for ESPs

The M3AAWG Vetting BCP digested — pre-send vetting questionnaires (corporate entity, infrastructure, sending history, list practices), red flags, the test-send methodology, ongoing post-send monitoring triggers, and vetting tools (WHOIS, D&B, PACER).

Operational9 min read

Who it is for ESP operators

If you run an email service provider (ESP), one customer with bad practices can damage delivery for all your other customers. Vetting customers before they send, and continuing to watch them once they do, is how you keep those customers off your platform.

The M³AAWG Senders BCP makes both pre-send and post-send customer vetting mandatory for ESPs. The document it points to is the MAAWG Vetting Best Common Practices (BCP) of November 2011, a methodology guide to "how it's done", assembled from the vetting programs of M³AAWG member ESPs. It deliberately does not prescribe specific metrics such as complaint-rate thresholds (for those, see Metrics & Benchmarks), because not every technique fits every size of ESP or client. The last section adds the fraud-prevention practices from the M³AAWG Hosting Abuse BCP (March 2015) that apply to ESP onboarding.

Why vet

  • ESPs that send on behalf of clients are at the mercy of their worst clients' worst practices. E-appending, badly run affiliate programs and past data corruption damage delivery and reputation not only for the problem sender but for all the ESP's other clients, because they share IP addresses, domains and the ESP's brand with mailbox providers.
  • Pre-send vetting prevents damage to recipient domains and to the ESP's own sending reputation. Post-send vetting catches bad clients who passed the initial assessment.
  • Vetting also helps develop clients. Analyzing in depth how a prospect builds and maintains its lists reveals issues that can be corrected, and the process is the ESP's best opportunity to coach prospects and existing clients on best practices and compliance.

Pre-send vetting questionnaires

These question sets help customer-facing staff (sales, compliance) decide whether a prospect qualifies for service. Each question comes with its rationale and red flags.

Corporate entity formation and history

  1. Name and address of the company?
  2. How long has the company operated?
  3. Any additional names or locations, now or in the past?
  4. Who are the principals?
  5. Who will be the primary point of contact?

Verification: commercial entities generally must file with their local taxation authority, in the form of articles of formation, a business license, or DBA (assumed-name) filings. In the US these filings sit with the state Department of State, and most states offer free online access. Red flags: no filings, especially when the prospect claims a long business history; a very short history; principals who form and dissolve several entities within a short period.

Infrastructure and process

  1. Have you worked with an ESP before? Which one, and why did you leave? Several previous ESPs, or leaving "for deliverability reasons", should generally be treated as red flags. Find out the real reason for switching.
  2. Which IP addresses did you mail from before? Check the reputation history of those IP addresses. IP addresses that were blocked or damaged before are a problem signal to investigate.
  3. Which domains do you own and use for mailing? How long have you owned them? Are they registered with anonymized WHOIS? Hiding behind anonymized registration is a common tactic of abusive senders. Legitimate permission-based senders have no need to hide their corporate contact information.
  4. Do you monitor role accounts (postmaster@, abuse@)? Who manages them? Complaints arrive at these addresses whatever the quality of the list. Maintaining and monitoring them is an industry best practice under RFC 2142 (see Abuse Desk Operations).
  5. Do you control your DNS? Do you use any authentication protocols? Control of DNS means the sender can publish SPF and DKIM records that authorize the ESP.

Sending history and patterns

  1. What types of messages do you send, and in what proportions? Can we see samples? Promotional and marketing mail draws higher complaint rates and more delivery issues than transactional or alert mail, even at the same level of permission. The mix sets expectations for how often issues will occur and how serious they will be.
  2. Do you segment, or send to the whole list? What are your segmentation criteria? Segmented, targeted campaigns perform better than generic sends to the full list.
  3. How often do you mail, and when was your last send? Mail that is timely, relevant and expected, at the frequency recipients expect, produces fewer issues. A list that has been dormant for a long time is itself a risk (see List Hygiene).
  4. Do you share your list with partners, advertisers or other brands, or send on behalf of third parties? Do you disclose sharing when you collect addresses, and how? Unexpected mail from third parties generates complaints even from recipients who gave strong permission.
  5. Do you do affiliate marketing? Is the program your own or managed by a third party (for example, Commission Junction)? Affiliate mail deserves extra scrutiny, because the category has historically been a vector for abuse. Programs run by well-known, reputable third parties are typically less problematic than programs companies run themselves.
  6. Have you ever appeared on a blocklist? Why were you listed, and how did you address it? Constructive answers involve reviewing how the list was acquired and cleaned, and tightening practices. Any answer that hints at changing infrastructure to evade a listing is a red flag. (See Blocklists & Spamhaus.)
  7. What were your metrics for the last 3 months (deliverability, complaints and so on)? Past performance indicates list quality. A poor history means the list was badly assembled or maintained, and it calls for extra scrutiny.

List, data collection and management practices

  1. How do recipients opt in? List every collection point, online and offline, and how consent or notice is given at each one. Senders should keep an auditable trail that shows the method, date and source of permission for each recipient or group.
  2. Were you, or your previous ESP, enrolled in feedback loops (FBLs)? What did you do about complaints? Best practice is to unsubscribe people who complain and investigate the root cause. A complaint may reveal that permission was gathered poorly. In that case, expect the sender to have reviewed how permission was collected for that recipient and for groups sourced the same way, and possibly to have asked them to confirm again. Where permission is strong, a complaint may instead be an unsubscribe in the wrong form, signaling that content or frequency did not meet expectations.
  3. How did you manage unsubscribes? Have unsubscribed addresses been removed from the list you are bringing to us? Removal is a legal requirement in the US, Canada and the EU. Suppression lists must be maintained and portable to new sending platforms.
  4. How did you manage bounces? Did you treat hard bounces (5xx) and soft bounces (4xx) differently? Best practice is to remove addresses that hard-bounce several times within a given period (the previous ESP may have done this automatically). Recurring high rates of generic soft bounces indicate content or reputation problems, and the prospect should have resolved persistent soft bounces. (See DSNs.)
  5. Have you ever purchased a list? Have you used rented lists, affiliate marketing or co-registration? A yes to any of these is a red flag. Purchased lists are addresses that never consented, and many ESPs prohibit them outright. Review every list a customer supplies for signs of purchase, such as column headers containing terms like "jigsaw" or "append". Co-registration may technically be based on permission, but that permission is usually uninformed, and such lists perform about as badly as purchased ones. Ask too whether the prospect sends cold email, meaning unsolicited mail to people with no prior relationship. Version 4.0 of the M3AAWG Sender Best Common Practices (August 2026) regards cold email as abusive, even from an otherwise legitimate business.
  6. Does the list contain distribution or role accounts (sales@, staff@, support@)? May we review the list before we provision your account? Role accounts are almost never used to opt in, so their presence indicates poor acquisition, including purchase. Review supplied lists for role accounts and known trap addresses (see Spam Traps).
  7. Do you publish a privacy policy on your website? No privacy policy is a red flag. Where one exists, check that it does not contradict the practices described in the answers to the questionnaire.

Post-send vetting

Test send

Once pre-send vetting is satisfactory, allow a test send to a small, randomly selected segment of the prospect's lists before you give it full production access. The size depends on the total size of the list, but tests to fewer than ~10,000 recipients may not give statistically significant results. After the test, review these metrics (the same set you use to monitor customers on an ongoing basis):

  • Overall bounce rate
  • Relative percentage of the various bounce types
  • Open and click-through rates
  • Unsubscribe rate
  • Direct complaints
  • Opt-out comments
  • Spam complaint rate
  • Complaint rate by domain or FBL

Any metric that differs significantly from existing senders of similar mail deserves extra scrutiny.

Ongoing monitoring triggers

Once a customer is vetted and provisioned, keep monitoring the same metrics, and watch closely for:

  • Significant, sudden increases in list size
  • Content changes following significant changes in metrics
  • Privacy-policy changes following significant changes in metrics or volume
  • Frequent changes of customer contact or payment information
  • Activity that stops and starts, which may be an attempt to spread poor reputation metrics across more than one ESP

Tools and resources

WHOIS

Use WHOIS during vetting to check that the prospect represents its domains correctly and openly. The M³AAWG best practice for senders is that domain ownership should show verifiable information, not information obscured or hidden behind a privacy proxy with a P.O. box. WHOIS also lets you verify the contact information for a company's abuse desk.

  • Good registration pattern: the registrant is the actual company with a real street address. The administrative and technical contacts name the organization, with working role email addresses (info@, dnsadmin@) and phone numbers.
  • Bad registration pattern: the registrant is a privacy proxy service ("I am a Proxy, Inc."), the address is a P.O. box, contact emails are routed through the proxy (EXAMPLE.COM@iamaproxy.proxy), and the phone and fax numbers are placeholders.

(A caveat from 2011: since GDPR, WHOIS redaction has made registrant data much less available than when the BCP was written. The principle, that a sender's identity should be transparent, still applies. Check it through RDAP, business registries and direct verification.)

Corporate-entity research

Tool Use
Dun & Bradstreet (dnb.com) Business information
LexisNexis Risk Solutions Financial and background information
Better Business Bureau Complaints against a business
PACER (pacer.gov) Records of US appellate, district and bankruptcy courts: was the entity or a principal a party to legal action about email?
State Department of State filings Formation documents, licenses, DBA filings (mostly free online)

Fraud-prevention practices (Hosting Abuse BCP)

The prevention chapter of the BCP for hosting and cloud providers adds controls on the platform side that apply directly to ESP onboarding:

  • Preauthorize new accounts, so no account sends before it has been reviewed.
  • Personally contact accounts that seem suspicious.
  • Keep records of accounts previously terminated for fraud, and match new signups against them.
  • Put limits on new accounts, and raise them only when the customer shows a credible, demonstrated need.
  • Give prospective accounts a fraud score, and automatically reject those below a threshold where possible.
  • Equip sales teams with specific questions and known red-flag statements, so they can spot fraud at first contact. Train customer-facing staff (support, sales, marketing) to recognize when a prospect's stated practices violate the acceptable use policy (AUP).
  • Allocate rights in tiers: restrict new accounts' API access, their capacity to send and to create domains, and their bandwidth. Widen access step by step as tenure and clean reputation build up. Reserve elevated privileges for customers who act against abuse proactively, have been hosted for more than ~12 months and respond to inquiries, and revoke those privileges after repeated abuse or unresponsiveness.
  • Collect a complete client identity during vetting, and use it to authenticate later communications (passphrases, PINs, the last four digits of the payment card, named approved contacts).
  • Make security a contract term: customer agreements should oblige clients to maintain a secure environment, keep software up to date, and notify the provider of breaches.

These practices support the controls against account compromise and outbound abuse in Compromised Accounts, which also covers patterns for detecting registration abuse, such as mass signups, stolen or disposable cards and implausible business claims.

Check your own record

The free check reads what your domain publishes in DNS.

In this topic

All 16 in ESP Operations →