# M3AAWG Documents for Senders and ESPs — Annotated Index

> What else M3AAWG publishes for senders and ESPs, plus the feedback-loop ecosystem — FBL format types and the per-provider FBL signup list.

Source: emailmarketing.net — https://emailmarketing.net/learn/industry-best-practices/m3aawg-document-index

If you send email or run an email service provider (ESP), much of the industry's operational guidance comes from one working group, and you need to know which of its documents exist and where to find them. The Messaging, Malware and Mobile Anti-Abuse Working Group (M³AAWG) maintains a "Documents for Senders and ESPs" page and a Feedback Loop resources page. Two of the documents have their own detailed summaries:

- [M3AAWG Sender Best Common Practices, Version 4.0 (August 2026)](https://emailmarketing.net/learn/industry-best-practices/m3aawg-senders-bcp)
- [M3AAWG Email Authentication Recommended Best Practices (2020)](https://emailmarketing.net/learn/industry-best-practices/m3aawg-email-authentication-bcp)

The tables below list the rest, with what each document covers and where it is published.

## Documents listed on the page for senders and ESPs

| Document | Date | What it covers | URL |
|---|---|---|---|
| Trust in Email Begins with Authentication | Feb 2015 | White paper on why and how email authentication (SPF, DKIM, DMARC) establishes trust. It is background reading that the 2020 Authentication BCP builds on. | https://www.m3aawg.org/sites/default/files/doc_files/M3AAWG_Email_Authentication_Update-2015.pdf |
| M3AAWG Sender Best Common Practices, Version 4.0 | Aug 2026 | The Senders BCP (M3AAWG-158), summarized in [M3AAWG Sender Best Common Practices](https://emailmarketing.net/learn/industry-best-practices/m3aawg-senders-bcp). It replaces versions 2.0 (2011) and 3.0 (2015). | https://www.m3aawg.org/senderbcp |
| M3AAWG Position on Email Appending | Sep 2019 | Position statement: email appending (matching customer records to email addresses the owner never provided or consented to) is a direct violation of core M³AAWG values. It is abusive, generates complaints, and carries legal risk under privacy and anti-spam laws. | https://www.m3aawg.org/sites/default/files/legacy/m3aawg_apending_position_update-2019-01.pdf |
| M3AAWG Vetting Best Common Practices | Nov 2011 | In-depth guide to customer vetting for ESPs: vetting before sending, to identify malicious senders before they mail, and monitoring after sending (the Senders BCP makes both mandatory). | https://www.m3aawg.org/sites/default/files/doc_files/MAAWG_Vetting_BCP_2011-11.pdf |
| M3AAWG Complaint Feedback Loop BCP | Aug 2010, replaced Nov 2011 | Superseded by **RFC 6449, Complaint Feedback Loop Operational Recommendations**, the operational standard for running and consuming FBLs. | https://tools.ietf.org/html/rfc6449 |
| Best Current Practices for Building and Operating a Spam Trap | Aug 2016 | How spam-trap networks are built and run. It helps senders understand how trap operators source addresses (recycled vs. pristine traps) and why hitting traps damages reputation. | https://www.m3aawg.org/sites/default/files/legacy/m3aawg-spamtrap-operations-bcp-2016-08.pdf |

The two BCPs summarized above also cite these M³AAWG documents, which belong to the same catalog but are not listed on the page for senders:

| Document | What it covers | URL |
|---|---|---|
| Best Practices for Managing SPF Records (2017-08) | Comprehensive SPF record management, including how to stay within the RFC 7208 DNS lookup limits. | https://www.m3aawg.org/sites/default/files/m3aawg_managing_spf_records-2017-08.pdf |
| DKIM Key Rotation BCP (2019-03) | How and how often to rotate DKIM keys. | https://www.m3aawg.org/sites/default/files/m3aawg-dkim-key-rotation-bp-2019-03.pdf |
| Best Practices for Implementing DKIM To Avoid Key Length Vulnerability (2017-07) | Minimum key lengths and implementation guidance. | https://www.m3aawg.org/sites/default/files/m3aawg-key-implementation-bp-revised-2017-07.pdf |
| Protecting Parked Domains BCP (2015-12) | Publish `v=spf1 -all` (and related records) on domains that never send mail. | https://www.m3aawg.org/sites/default/files/m3aawg_parked_domains_bp-2015-12.pdf |
| Email Forwarding Best Common Practices, version 2 (2015-03) | Running a mail-forwarding service (for example, an ESP forwarding replies to customers using addresses on the ESP's domain). | https://www.m3aawg.org/documents/en/m3aawg-email-forwarding-best-common-practices-version-2 |
| Recommendations for Senders Handling of Complaints | The document the Senders BCP (Version 4.0) points to for handling FBL reports and direct complaints. The BCP gives no link, and the document was not listed on M³AAWG's document pages when checked in September 2026. | Not located |
| Feedback Reporting Recommendation (2014-02) | Recommendations on feedback and complaint reporting between receivers and senders. Version 3.0 of the Senders BCP cited it; Version 4.0 cites the complaints document above instead. | https://www.m3aawg.org/sites/default/files/legacy/document/M3AAWG_Feedback_Reporting_Recommendation_BP-2014-02.pdf |
| DMARC Training Series (videos) | Extensive course on DMARC presented by DMARC.org experts. | http://www.maawg.org/activities/training/dmarc-training-series |

## Feedback loop (FBL) resources

A **Complaint Feedback Loop** is a mechanism by which a mailbox provider reports its users' spam complaints back to the verified sender of the message, so the sender can clean its database and fix the causes of the complaints. **RFC 6449** gives the operational recommendations, and reports use the **Abuse Reporting Format (ARF)** (RFC 5965; RFC 6650 is its applicability statement).

### Three FBL format types

| Type | How it works | Notes |
|---|---|---|
| Traditional (IP-based) | Follows RFC 6449. Reports use ARF, include the full message and identify the complaining user, and are keyed to the sending IP. | The classic model. The sender must control or register the sending IP addresses. |
| Aggregated | Rolls up complaint **counts** without personal data (PII) or full messages. | Designed for privacy, and still gives performance data for each stream. Examples: Gmail (spam-rate data in Postmaster Tools), Microsoft SNDS, Signal Spam. |
| Domain-based | Requires **DKIM signatures**. Reports use ARF and are keyed to the signing domain. | Lets senders on **shared IPs** get feedback about their own program. It works with the Senders BCP advice to DKIM-sign each entity in a shared pool with its own domain or subdomain. |

### FBL signup points by mailbox provider (as listed by M3AAWG)

Most traditional FBLs are operated through **Validity's Universal Feedback Loop** (https://fbl.validity.com): Bluetie (Excite), Comcast, Cox, Fastmail, Gandi, Italiaonline (Libero and Virgilio), La Poste, Locaweb, Mail.Ru, OpenSRS (Tucows), Rackspace, Seznam, SFR, SilverSky (USA.NET), Swisscom, Synacor, Telecom Italia, Telenet, Telenor, Terra, UOL, Virgin Media, Ziggo.

Exceptions and programs outside Validity:

| Provider | Type | Signup |
|---|---|---|
| Earthlink | Traditional | fblrequest@abuse.earthlink.net |
| Microsoft JMRP (Junk Mail Reporting Program) | Traditional | https://postmaster.live.com/snds/JMRP.aspx |
| QQ.com | Traditional | http://open.mail.qq.com (Chinese) |
| United Online (Juno and NetZero) | Traditional | http://www.unitedonline.net/postmaster/whitelisted.html |
| Gmail | Aggregated | https://support.google.com/mail/answer/6254652 (Postmaster Tools) |
| Microsoft SNDS | Aggregated | https://sendersupport.olc.protection.outlook.com/snds/index.aspx |
| Signal Spam (France) | Aggregated | https://www.signal-spam.fr (paid membership) |
| Yahoo! | Domain-based (DKIM) | https://senders.yahooinc.com/contact#complaint-feedback-loop |
| Comcast, Gandi, La Poste, SFR | Domain-based (also offer traditional) | https://fbl.validity.com |

**Gmail offers no traditional per-message FBL.** Its aggregated program (spam rate by identifier, in Postmaster Tools) is the only complaint signal it provides. You cannot suppress individual complainers at Gmail, so preventing complaints matters more there. **Yahoo's FBL is domain-based**, keyed to the DKIM `d=` domain.

M³AAWG provides this list as an industry service and does not endorse specific providers. The material comes from third parties and is offered "as is."

### How FBLs fit a sender's workflow

The [Senders BCP](https://emailmarketing.net/learn/industry-best-practices/m3aawg-senders-bcp) requires ESPs to have a system that ingests both FBL reports and complaints sent directly to the abuse mailbox, and a process to act on them. Version 4.0 adds that ESPs should join every FBL available to them and check that each one keeps delivering reports. The BCP treats complaints as a main way to spot customers breaking the sender's terms, but it leaves the process itself to the ESP. In common practice, that process suppresses the complaining recipient immediately (where the FBL identifies one) and tracks the complaint rate of each customer and stream to catch Terms of Service violations or list-hygiene problems.

## Related articles

- [M3AAWG Sender Best Common Practices](https://emailmarketing.net/learn/industry-best-practices/m3aawg-senders-bcp)
- [M3AAWG Email Authentication BCP](https://emailmarketing.net/learn/industry-best-practices/m3aawg-email-authentication-bcp)
- [Foundations of Email Deliverability](https://emailmarketing.net/learn/foundations/foundations-of-email-deliverability), on complaints as a core reputation input
