# Sender Certification Programs: Validity Certification and the CSA

> The two surviving commercial allowlist programs — Validity Sender Certification and the Certified Senders Alliance — with exact admission criteria, performance thresholds, costs structure, which receivers honor each, and an honest assessment of when certification pays off.

Source: emailmarketing.net — https://emailmarketing.net/learn/reference/sender-certification-programs

If you are considering paying for sender certification, whether it helps depends on which mailbox providers you need to reach and on whether you send as a brand or as a platform. Formal third-party allowlisting is [largely historical](https://emailmarketing.net/learn/reference/glossary), but two commercial programs survive with real support from receivers.

**Validity Sender Certification** is the former Return Path Certification. It is an allowlist of IP addresses, honored mainly by Microsoft, Yahoo and AOL, Comcast, and networks filtered by Cloudmark. The **Certified Senders Alliance (CSA)** is a German program of eco and DDV, and its allowlist is used by GMX and WEB.DE and most of the German-speaking mailbox market. The two programs target different senders. Validity certifies **brands on dedicated IP addresses and explicitly excludes ESPs**. The CSA certifies **sending platforms, including ESPs, at the infrastructure level**.

**Neither program influences Gmail.** Gmail runs its own reputation systems and [largely ignores third-party signals](https://emailmarketing.net/learn/operations/reputation-monitoring). No certification, paid or otherwise, improves placement at Gmail.

---

## Validity Sender Certification

Source: "Sender Certification Requirements" (Validity, © 2024, published for 2025; fetched July 2026). Certified IP addresses are placed on Validity's allowlist, mailbox provider partners are notified, and Validity starts monitoring the IP addresses 24×7. Validity claims relationships with "75+ global mailbox and security providers". The partners for which it states thresholds are Microsoft, Yahoo and AOL, Comcast, and Cloudmark.

### Application and pre-approval process

1. You subscribe, and Validity starts a comprehensive audit of the email program.
2. You complete the **Sender Certification Questionnaire** (typically within the first day). This unlocks the certification data feeds (complaint rates, spam trap hits, and sending volume for each IP address, from Validity's provider and filter partners) and starts the audit.
3. If the program meets the Business Model, Measurability and Infrastructure requirements, the account may get **preliminary activation** of Certified status **before the audit is complete**. This is the "pre-approved" state marketed at validity.com/sender-certification/get-pre-approved. The preliminary benefits last **up to 60 days** while the audit runs.
4. If the remediation the audit requires is not complete after the 60-day preliminary period, or if requirements are breached at any point during the subscription, the IP addresses are **suspended from the allowlist** (access to the data feeds continues). They are activated again once the corrections are made.

Ongoing obligations: respond to any program notice within **3 days**, and start the required actions within **10 days**. Notify Validity in writing within **2 business days** if an IP address or domain is compromised, and enable it again only after Validity has reviewed the mitigation.

### Eligibility (business model)

- The business can be verified through a public third-party source (a country registry, Dun & Bradstreet), has a physical address on record, has been **legally registered and operating for at least 1 year**, and does not use a registered agent that hides its ownership.
- Every approved brand has a valid HTTPS website or landing pages, and has had them **for at least the past 6 months**.
- **Dedicated IP addresses only.** Shared IP addresses are not eligible, and the applicant must have been the only entity on the IP addresses for **at least 60 days**.
- Certified IP addresses may carry only **transactional and commercial email built from templates**. Corporate or 1:1 mail is not allowed, and neither is free-form content in messages (for example, text entered in a web form).

**Excluded business categories** (cannot be certified): Email Service Providers (senders mailing on behalf of brands they do not own, such as ESPs, brand licensing, publishers and white-label services), agencies, third-party and affiliate mailers, lead generation, list rental providers, penny-bid auctions, illegal activities, and human trafficking. For an ESP, this means you cannot certify your own platform or your shared pools. Only customers on dedicated IP addresses who fully own their brand can enroll, each one individually.

### Volume minimums and IP limits

- Each IP address must deliver **at least 100 messages to each of Microsoft and Yahoo in every rolling 30 days** (as measured in Validity's data). IP addresses without measurable, consistent volume are not reviewed. Once certified, such IP addresses are **suspended after 30 days and removed from the program after 90 days**.
- An IP address may not target a single mailbox provider (with occasional exceptions, only with Validity's prior written approval).
- The maximum number of certified IP addresses depends on the contracted annual volume:

| Annual sending volume | Max IPs | | Annual sending volume | Max IPs |
|---|---|---|---|---|
| 1,200,000 | 2 | | 120,000,000 | 8 |
| 3,000,000 | 2 | | 180,000,000 | 9 |
| 7,500,000 | 3 | | 240,000,000 | 10 |
| 12,000,000 | 4 | | 420,000,000 | 13 |
| 36,000,000 | 5 | | 600,000,000 | 16 |
| 60,000,000 | 6 | | 1,200,000,000 | 18 |
| 90,000,000 | 7 | | More than 1,200,000,000 | 22 |

### Technical and program requirements (summary)

- **Infrastructure**: no open relays. [Forward-confirmed reverse DNS (FCrDNS)](https://emailmarketing.net/learn/ip-management/basic-ip-allocation). [SPF](https://emailmarketing.net/learn/authentication/spf) on all Return-Path domains, with no `+all` or `?all` and no `ptr` mechanism. All mail [DKIM](https://emailmarketing.net/learn/authentication/dkim)-signed, with keys of at least 1024 bits (2048 recommended) and **no `l=` tag** (use `x=` instead). [DMARC](https://emailmarketing.net/learn/authentication/dmarc) of at least `p=none` on the From domain, aligned, with a working `rua`. ARC recommended for forwarding. The role accounts `abuse@` and `postmaster@` on all sending and Return-Path domains. Proof of domain ownership through a Validity TXT token that must stay in DNS for as long as the membership lasts. Hard bounces removed from all future mailings. TLS recommended.
- **Content**: clear branding. Accurate subject lines, without "RE:" or "FWD:". A physical mailing address in commercial and transactional mail. **No URL shorteners** (Bitly, TinyURL and similar). **No attachments of any kind.** No hidden content. A valid Message-ID. Headers that comply with RFC 5322.
- **Unsubscribe**: [List-Unsubscribe (RFC 2369) covered by the DKIM signature, RFC 8058 one-click](https://emailmarketing.net/learn/list-management/list-unsubscribe), and a link in the body. Requests processed within **2 days**. Links that keep working for **at least 60 days** after sending. Requests made in other ways (by post, by phone, to abuse@) are also honored.
- **Consent**: [double opt-in, or single opt-in with notification](https://emailmarketing.net/learn/list-management/consent-methods). Another legal basis, such as documented legitimate interest, needs written evidence. Prohibited: pre-selected opt-in, plain single opt-in without notification, harvesting, renting, buying or appending lists, and email prospecting. Co-registration requires separate unchecked sign-ups for each brand and consent that can be proven. Forward-to-a-friend requires a CAPTCHA on the form, one email and at most one follow-up, no external links, a personal comment of no more than 140 characters, and no more than 100 messages per user in 24 h.
- **FBLs**: sign up for every available [feedback loop](https://emailmarketing.net/learn/list-management/complaint-feedback-loops). The mandatory minimum is Microsoft JMRP, the Comcast IP & Domain FBL, and the Yahoo FBL.

### Performance thresholds (exceeding any leads to partial or full suspension)

**Microsoft SRD (Sender Reputation Data junk votes), cumulative over 30 days:**

| Individual IP SRD volume | 0–4 | 5–10 | 11+ |
|---|---|---|---|
| Allowed SRD rate | not enforced | 5 junk votes | 45% |

| Group SRD volume (all certified IPs) | 0–9 | 10–30 | 31–50 | 51+ |
|---|---|---|---|---|
| Allowed SRD rate | not enforced | 75% | 65% | 55% |

Group enforcement applies when at least 2 IP addresses are certified. If the group threshold is exceeded, every IP address with at least 1 junk vote is suspended.

**Complaint rates, averaged over 30 days across all sending volume** (enforced only above a minimum number of complaints):

| Source | Threshold | Enforced above |
|---|---|---|
| Microsoft complaint rate | 0.2% | 200 complaints |
| Yahoo and AOL inbox complaint rate | 0.2% | 200 complaints |
| Comcast complaint rate | 0.3% | 100 complaints |
| Cloudmark complaint rate | 1.0% | 100 complaints |

**Spam traps, cumulative over 30 days:**

| Trap class | Allowed hits |
|---|---|
| Critical spam traps | 3 |
| Significant spam traps | 5 |
| RP Trap Network | 100 |
| Cloudmark traps | 100 |

**Blocklists (current listings):** 1 listing on a critical blocklist, or 2 on significant blocklists, breaches the threshold. Repeated or excessive listings can lead to suspension or termination.

---

## Certified Senders Alliance (CSA)

The CSA was founded in 2004 and is run by **eco** (Association of the Internet Industry) together with the **DDV** (German Dialogue Marketing Association). It **certifies IP platforms** (IPv4 only). The certified party is the company that operates and controls the sending platform, which describes an ESP exactly, the opposite of Validity's model.

The CSA maintains a list of certified IP addresses that it distributes to participating mailbox and security providers, which build it into their filters. Those partners send back live compliance data, which certified companies see in the **Certification Monitor**. The contract documents (Criteria, Conditions of Participation, Rules of Procedure, Price List) are published at certified-senders.org/resources. German law applies, and the place of jurisdiction is Cologne.

> About the documents: the older 2017 PDF URLs cited above now serve the **June 2026** editions of the Criteria and the Conditions of Participation (the older documents expired on 19 July 2026). The figures below are therefore current as of the June 2026 versions, fetched July 2026.

### Who can participate

- The company **operates the technical platform** that controls the sending of bulk email, and is responsible for it. It generally needs **at least 3 months of sending history** on the infrastructure.
- Certification covers **all IP addresses used for commercial bulk email**. Every IPv4 address and its FQDN must be uploaded to the Certification Monitor, and the declared IP addresses may be used only for commercial bulk email (not for internal corporate mail).
- For ESPs and other platform providers, only IP addresses under the company's **sole control** can be certified, and certified outbound servers must be clearly separable from servers that are not certified.
- Brands that run their own platform must fully control and monitor delivery on it. Otherwise they cannot be certified.
- **Hosting providers are excluded** for servers that customers rent and use on their own.
- The business model must not conflict with the ethical principles of eco and DDV (a separate ground for rejection).

### Certification process, fees, and contract

1. Return the signed individual offer and pay the **assessment fee** (set by the CSA Price List, and **not refunded** if certification fails).
2. Assessment: a reputation check of the declared IP addresses using the participating partners' data, and a review of documents (sample newsletters, the IP list). Errors that are repeatedly left uncorrected can lead to a deadline. If the deadline is missed, the CSA may charge a new assessment fee.
3. The decision is made by the **Complaints and Certification Committee (CCC)**, which has four members, two elected from eco and two from DDV. Certification requires a majority. After a rejection (because of doubts about compliance or an ethical conflict), the company **may apply again after 6 months**.
4. Monthly contributions (invoiced quarterly, pro-rated) start on approval. The price category depends on the **total annual revenue** of the company or of its parent company (from an annual revenue survey; a company that does not respond is placed in the highest category). The contract lasts 1 year, renews automatically, and has a **3-month notice period**.
5. Payment arrears of **more than 30 days** lead to temporary delisting of the IP addresses (reinstatement about 5 working days after payment). Arrears of **more than 60 days** lead to termination for good cause. After the contract ends, all references to the CSA must be removed within 4 weeks (6 months for print), with a **contractual penalty of €500 per week** after that.

IP statuses on the certified list: **Active** (full benefits, plus monitoring and reporting), **Failed** (technical requirements not met; no benefits), **Delisted** (a sanction; no benefits, but monitoring continues), **Monitored** (during certification) and **Parked** (set by the company for unused IP addresses; listed, but sending is prohibited, which lets you prepare DNS in advance).

For the duration of certification, the company must prove control of each IP address, either with a DNS TXT record on the server's FQDN in the form `CSA-certified-host=<token>`, or with a WHOIS registrant organisation that matches the contracted company name. Outgoing servers need full FCrDNS (the PTR record gives the FQDN, and the FQDN's A record gives back the same IP address), the FQDN announced in HELO or EHLO, and hostnames that do not look like coded dial-up identifiers (`server-80-12-54125.example.org` fails). Missing verification or broken lookups result in the status "failed".

### Mandatory criteria (June 2026)

**Trust & transparency:** a postal address and a digital contact that are easy to find on the website, accessible privacy information, and messages and SMTP dialogue that comply with the RFCs (currently RFC 6532, 2142, 2369, 5321, 5322, 7208, 6376, 8058).

**Abuse prevention:**
- A role account for abuse (preferably `abuse@org-domain.tld`) registered in the Certification Monitor. Respond to the **eco Complaints Office within 24 hours on business days**.
- Platform providers must be able to enforce compliance for each customer (blocking, rate limiting, volume caps, caps on sending domains) and must protect customer accounts (for example, with 2FA).
- Redirect and click-tracking links must be able to be deactivated **within 24 hours** of a notification of phishing or misuse.
- The **`X-CSA-Complaints: csa-complaints@eco.de`** header, inserted and DKIM-signed on certified servers only, within 4 weeks of certification, and confirmed by a test mailing.
- No open relay, no public proxy and no backscatter. Continuous monitoring. Delivery over **TLS** that reflects the current state of the art.

**Authentication:**
- SPF for the MAIL FROM domain, ending in **`-all` or `~all`**.
- A valid DKIM signature on every email (RFC 6376). For ESPs, `d=` must be attributable to the customer's sending domain (an additional signature with the ESP's domain is allowed). The signature must cover at least **From, X-CSA-Complaints, Date, To**, and the **`l=` length parameter is prohibited**.
- **Relaxed DKIM alignment** is required: the organizational domain of `d=` must match the domain in the header From (with an exception for ESPs only when the customer has no domain of its own).

**List hygiene:**
- The platform must be able to insert **List-Unsubscribe** (the RFC 2369 URL method with POST over HTTPS, which can be combined with **List-Unsubscribe-Post**, RFC 8058 one-click) and **List-Help** (a mailto: or HTTPS link; HTTP is not permitted) in every email.
- Every advertising email must carry a working unsubscribe that requires **no login**. ESPs must give customers an easy unsubscribe feature using a link in the body (preference and selection pages are allowed).
- Bounce handling as specified in RFC 5321, with an **MX record (or an A record as fallback) on the envelope-from domain**. Further delivery to mailboxes known not to exist must be prevented.

**Performance thresholds (7-day windows):**

| Indicator | Threshold | Basis |
|---|---|---|
| Spam complaint rate | At most **0.3%** per IP or per company | Complaints divided by emails reaching the inbox |
| DKIM missing rate | At most **3.0%**, company average | Unsigned emails divided by total emails sent (data validated by partners) |
| Hard bounce rate | At most **1.0%** per IP or per company | |
| General reputation | No significant IP or DKIM reputation problems with participating providers (trap hits, content scanners, spam rates) | |

**Recommended (not mandatory):** register for public FBLs and implement the **CFBL header (RFC 9477)**. Send multipart HTML and text. Publish DMARC with a `rua` that can be processed, and `p=reject` is recommended. Use **DANE (RFC 7671, with DNSSEC), with MTA-STS (RFC 8461) as the fallback** where DNSSEC is not feasible. Use DKIM with 2048-bit keys and SHA-256. Use double opt-in (the confirmation email must contain **no advertising**). State the mailing frequency at sign-up. Provide a working reply-to address. Use **separate IP addresses for newsletters and for transactional mail**. Avoid URL shorteners. Extend DKIM alignment to the MAIL FROM domain, and keep the domains in the List, Reply-To and Sender headers consistent.

The CSA publishes a self-assessment **checklist** (certified-senders.org/csa-checklist) that turns these criteria into yes-or-no readiness questions. It is useful to go through it before paying the assessment fee.

### The CSA Email Directive: German legal baseline encoded as certification content

The CSA's certification criteria refer to its "Email Marketing Directive", which summarizes German and EU law. This is what makes CSA certification legally meaningful in Germany. It matters even to senders who are not certified but mail German users (compare the double opt-in (DOI) expectation noted in [GMX and WEB.DE requirements](https://emailmarketing.net/learn/providers/gmx-web-de-postmaster)).

**Permission (directive ch. 2)**, based on the General Data Protection Regulation (GDPR) and the ePrivacy Directive 2002/58/EC as implemented in the Act against Unfair Competition (UWG), the TMG and TTDSG (telemedia laws) and the Federal Data Protection Act (BDSG):
- "Advertising" is interpreted broadly (newsletters, birthday greetings, market research, brand promotion, requests for donations). Transactional mail needs no consent, until any advertising element is added. From that point, the full consent rules apply.
- Consent must be **transparent** (which company, which products, which channels, with no blanket consent; the Federal Court of Justice (BGH) found that consent naming about 8 companies can be valid, while the Higher Regional Court (OLG) of Frankfurt found 59 sponsors to be too many), **active** (no pre-checked boxes or opt-out constructions), **freely given**, and **documented** (the consent text, the place, and the timestamp and IP address of the sign-up and of the DOI confirmation click).
- **Double opt-in is the de facto standard of evidence** (recognized by the BGH as proof that the request came from the address). The DOI confirmation email must contain **no advertising** (courts have objected even to logos in the footer). Sign-ups that are not confirmed should be deleted within **about 2 weeks**.
- Consent has no legal expiry date, but the Regional Court (LG) of Munich I has treated consent **unused for about 1.5 years** as lapsed.
- Withdrawing consent must be easier than giving it. Consent records are kept for **3 years after withdrawal** (the limitation period in §195 BGB) to defend against claims.
- **The existing-customer exception in §7(3) UWG** (email advertising without consent) requires all four conditions: the address was obtained in connection with a completed sale, the advertising is only for the sender's own similar goods or services, a clear notice of the right to object is given when the address is collected and in every email, and the customer has not objected.
- **B2B is not exempt.** German law requires opt-in for business-to-business (B2B) email advertising as well. The relaxed rule of presumed consent for B2B exists only for telephone marketing.

**Legal notice, or Impressum (directive ch. 3)**, based on the E-Commerce Directive 2000/31/EC and the Telemedia Act: every commercial email needs a **complete legal notice, in full text, in the email itself** (not behind links). It includes the company name with its legal form, the full street address, the authorized representatives, the register court and number, an email address (a phone number is recommended), and the VAT ID where applicable. The sender's identity and the commercial nature of the message must be evident. Violations can be fined up to **€50,000**.

### Which receivers honor the CSA

The participating mailbox providers (listed at certified-senders.org/participants, fetched July 2026) include the entire German-speaking consumer market (**GMX, WEB.DE, mail.com, 1&1, freenet, mail.de, T-Online, Arcor, Kabel Deutschland (Vodafone), unitymedia, Swisscom**) and international names: **Microsoft (Outlook.com, Office 365), Yahoo, AOL, Comcast, Orange, Seznam.cz, Fastmail** and various hosting companies. Security and filtering participants include **Cloudmark, Cisco Talos, abusix, Hornetsecurity, Open-Xchange, Halon, and Excello (virusfree)**.

The weight given to certification varies. German providers treat it as a first-class signal: GMX and WEB.DE actively send bulk senders to the CSA and route complaint feedback through it, and they run no public FBL of their own. For the large international participants, it is one input among many, not a way around the filters.

---

## Is certification worth it?

For an ESP operator, the costs and benefits look like this:

- **Gmail: no.** Gmail takes part in neither program, and it ignores third-party certification and blocklists in favor of its own systems. If your problem is placement at Gmail, certification buys nothing. Fix the [fundamentals of engagement and spam rate](https://emailmarketing.net/learn/providers/gmail-sender-requirements) instead.
- **Certification is a floor, not a boost.** The admission criteria of both programs are essentially the [M3AAWG senders BCP](https://emailmarketing.net/learn/industry-best-practices/m3aawg-senders-bcp) plus monitoring, and a sender who genuinely meets them usually already delivers well. The extra value is (a) the data feeds (Validity's feeds on traps, complaints and SRD, and the CSA Certification Monitor with partner data, which matters because complaint feedback from GMX and WEB.DE is not available any other way), (b) the benefit of the doubt during incidents and [warm-up](https://emailmarketing.net/learn/ip-management/ip-warm-up), and (c) a documented record of compliance.
- **The CSA is worth evaluating for any ESP with meaningful volume in Germany, Austria and Switzerland (DACH).** It is the only program designed to certify platforms and ESPs. It is the de facto FBL and escalation channel for GMX and WEB.DE, and its criteria encode the German legal requirements (DOI, Impressum) that you must meet anyway to mail Germany safely. Costs grow with company revenue (the assessment fee plus monthly contributions). Take the compliance obligations seriously (a 24 h response to abuse reports, 24 h to deactivate links, thresholds over 7-day windows), because losing certification after taking part publicly is itself a reputation signal.
- **Validity is a decision for each brand, not for the ESP.** ESPs are an excluded category. Only customers on dedicated IP addresses qualify, and they must own their brand, have at least 1 year of corporate history, have been alone on their IP addresses for at least 60 days, and send sustained volume to Microsoft and Yahoo. It suits high-volume B2C brands whose problems are at Microsoft (SRD and JMRP), Yahoo and AOL, Comcast, or regional ISPs filtered by Cloudmark. Its thresholds (0.2% complaints at Microsoft and Yahoo, 3 critical trap hits in 30 days, 1 critical blocklisting) are stricter than typical operating targets. Treat them as a service level you must keep, or expect suspension in the middle of the contract.
- **Neither program replaces good consent.** Both prohibit purchased, rented and appended lists outright. Certification cannot clean up a bad acquisition practice, and both programs revoke certification faster than mailbox providers forgive.
