# Mandated and Regulatory Email

> How to send legally required bulk notices — breach notifications, recalls, policy changes — to entire databases (including suppressed and unengaged addresses) without destroying sender reputation.

Source: emailmarketing.net — https://emailmarketing.net/learn/operations/mandated-and-regulatory-email

Some messages must reach recipients regardless of engagement, consent status, or deliverability metrics: senders can be legally required or compelled to mail their entire database — including addresses that are long-unengaged, unsubscribed, or previously suppressed. This is exactly what normal deliverability practice forbids (see [List Hygiene and Sunset Policies](https://emailmarketing.net/learn/operations/list-hygiene-and-sunset-policies)), which is why these sends need a dedicated process. M3AAWG's guidance is explicit: this process is **only** for mandated messages that are an exception to normal sending practices and likely to be of special relevance to the recipient — never for standard marketing or transactional notices.

## Definition and examples

Mandated (high-risk) emails inform individuals of a significant change in policy, help them mitigate damage, offer assistance, or provide noncommercial information about their account. Typical examples:

| Type | Example |
|---|---|
| Breach notification | Account compromise disclosure with password reset / free credit monitoring offer |
| Product recall | Health and safety notices |
| Policy change | Privacy-policy or terms-of-service updates |
| Account status | Noncommercial notices about the recipient's account |

## Why these sends are deliverability-dangerous

- They are bulk messages **highly likely to exhibit poor delivery metrics** — elevated bounces (dead addresses back on the list) and complaints (recipients who unsubscribed or forgot the brand).
- They may need to go to individuals who were **previously suppressed or unsubscribed** — reintroducing exactly the negative signals that suppression exists to prevent (see [Metrics and Benchmarks](https://emailmarketing.net/learn/operations/metrics-and-benchmarks) for the thresholds at stake).
- Volume spikes to a whole database break normal sending patterns and can trigger anti-spam mechanics at receivers (see [Foundations](https://emailmarketing.net/learn/foundations/foundations-of-email-deliverability) on how providers score senders).

Each organization bears the responsibility to determine whether a high-risk send is necessary, balancing it against the potentially abusive nature of the messages and how frequently they occur. Keep them non-intrusive and minimally disruptive to users and mailbox providers.

## Pre-send preparation (sending organization)

**Notify mailbox providers in advance.** Use each MBP's preferred point of contact (`postmaster@mailboxprovider.com` or its postmaster contact page — see the [providers/](https://emailmarketing.net/learn/providers) articles for known channels). Send personalized notifications to the MBPs most relevant to the audience; where appropriate, use a personal contact or industry groups, at the discretion of the sending platform and the organization.

**Coordinate internally and externally:**

- Consult your ESP for technical requirements and solutions that maximize effectiveness and minimize impact on IP and domain reputation.
- Provide guidance, instructions, and timelines from the relevant regulators or legal team.
- Internal teams (social, call center, frontline staff) should coordinate a consistent message across all customer-service channels.
- Determine whether information is needed for auditing purposes, and what that entails.

## Infrastructure and authentication choices

| Practice | Detail |
|---|---|
| Dedicated alias | Use a new email alias for these notifications instead of the usual marketing alias (e.g., `notice@sub.example.com`) |
| Branded, verified domain | Send from a branded organization domain, unequivocally verified with domain authentication (per the [M3AAWG Email Authentication BCP](https://emailmarketing.net/learn/industry-best-practices/m3aawg-email-authentication-bcp)) |
| **No cousin domains** | Do **not** use a newly registered cousin domain (a variation of the normal sender domain) or register a new domain for these notices — that pattern is indistinguishable from phishing |
| SPF + DKIM + DMARC | All three configured on the sending domain — see [SPF](https://emailmarketing.net/learn/authentication/spf), [DKIM](https://emailmarketing.net/learn/authentication/dkim), [DMARC](https://emailmarketing.net/learn/authentication/dmarc) |
| TLS | Supported on the sending server for receivers that implement it |
| Dedicated IP range | Some mailbox providers encourage reserving an IP range exclusively for mandated-email notification addresses (see [Advanced IP Segmentation](https://emailmarketing.net/learn/ip-management/advanced-ip-segmentation)) |

## Message content and identification

- From name like "[Organization name]: Notification"; "Important notification" in the subject line.
- **Minimal tracked elements**: limit links to only those required — or none at all.
- Content exclusively relevant to the issue, **no marketing at all**.
- Plain or minimal template style appropriate to the notification type (see [Content and Design for Deliverability](https://emailmarketing.net/learn/operations/content-and-design-for-deliverability)).
- **Suspend marketing communications during the notification period** — the mandated message should not compete with promotional mail.

## Audience segmentation and list handling

Decide who must receive the message based on the actual requirements of the notification, and sequence the send **from least risky to most risky** communication groups:

1. Impacted users
2. Active users
3. Subscribed users
4. Unsubscribed users
5. Bounced users — **exclude known dead addresses entirely**; they will never reach the intended recipient and only generate reputation damage

For known bounce addresses and users who have previously reported the brand as spam, use **alternative contact channels** instead of email: postal mail, SMS, website notification, social media, or traditional media (newspaper, radio, TV). Some recipient groups are inherently complicated to reach by email; alternative methods may satisfy the mandate with zero deliverability cost.

## ESP tasks: coordinating with mailbox providers

ESPs often cannot influence message content much — it is typically written by legal counsel to satisfy the organization's obligations under the notice. The ESP's role is coordination and pacing. Advance notifications to MBPs should include:

- Contact details for the organization or agency where recipients can get more information, plus a copy of the message itself if possible
- Sending volumes and the days required
- The sending infrastructure to be used: sending domains/hostnames, IP addresses (ideally a reserved range), dates and times, volume expectations

During the send:

- **Throttle sending speed over time** to avoid volume peaks that burden receiving networks and trigger anti-spam mechanics.
- Verify SPF, DKIM, DMARC, and TLS are in place before the first message leaves.

**Contractual preparation:** consider defining a preferred breach/mandated-email process in the customer contract or Data Protection Agreement in advance, so the workflow exists before the emergency does.

## Post-send

Monitor the send like any high-risk event: bounce and complaint rates against the thresholds in [Metrics and Benchmarks](https://emailmarketing.net/learn/operations/metrics-and-benchmarks), blocklistings and provider dashboards per [Reputation Monitoring](https://emailmarketing.net/learn/operations/reputation-monitoring). Addresses that hard-bounce or complain during the mandated send go back into normal suppression — the mandate exception ends with the notification period, and normal [sunset policy](https://emailmarketing.net/learn/operations/list-hygiene-and-sunset-policies) resumes.

## Related

- [List Hygiene and Sunset Policies](https://emailmarketing.net/learn/operations/list-hygiene-and-sunset-policies) — the normal rules this send temporarily overrides
- [Foundations of Email Deliverability](https://emailmarketing.net/learn/foundations/foundations-of-email-deliverability) — why unengaged-database sends are penalized
- [M3AAWG Senders BCP](https://emailmarketing.net/learn/industry-best-practices/m3aawg-senders-bcp) — the baseline these practices deviate from, deliberately and narrowly
- [Provider articles](https://emailmarketing.net/learn/providers) — postmaster contact points for advance notification
