Deliverability & compliance
The best flow in the world earns nothing from the spam folder. Since February 2024, Gmail and Yahoo require SPF, DKIM, and DMARC authentication plus one-click unsubscribe from bulk senders, and enforce spam-complaint thresholds at 0.3% with 0.1% as the safe line. For Canadian senders, CASL adds consent obligations with penalties up to $10 million. This service keeps you on the right side of all of it.
What does the monitoring stack look like?
Four instruments, checked on a schedule. DNS authentication (SPF, DKIM, DMARC with a real enforcement policy, not p=none forever). GlockApps seed tests for actual inbox placement across Gmail, Outlook, and Yahoo. Google Postmaster Tools for domain reputation and complaint trends. And your ESP's bounce and unsubscribe data, read weekly rather than after something breaks.
The distinction that matters: ESP dashboards report delivery, not placement. A message accepted by Gmail and filed as spam still counts as "delivered." Seed testing is the only way to see the difference before revenue does.
What does the CASL consent audit cover?
Three questions, per segment. What consent basis applies (express, or implied from a business relationship within the last two years)? Where is it recorded? And does every message carry the required identification and functioning unsubscribe? The output is a consent register your team keeps, plus fixes ranked by exposure. CRTC enforcement is real, and the two-year implied-consent clock quietly expires segments that were once mailable.
When should you bring us in?
Before a migration, before a volume ramp, or the day Postmaster Tools shows reputation sliding. Repair is slower than prevention: a referenced six-week repair cut complaints from 0.42% to 0.08% but required suppressing 38% of send volume while reputation recovered. The audience-analysis layerexists partly to keep you out of that situation, and theengagement process sequences both services when repair is unavoidable.
What did the 2024 Gmail and Yahoo rules change?
Since February 2024, senders over 5,000 emails a day to Gmail must authenticate with SPF, DKIM, and DMARC, offer RFC 8058 one-click unsubscribe, and keep spam complaints low. Google enforces at 0.3% and tells senders to stay under 0.1%. Miss those and mail gets rejected or spam-foldered regardless of content quality.
How is CASL different from the US CAN-SPAM rules?
CAN-SPAM lets you mail until someone opts out. CASL requires consent before the first commercial message: express consent, or implied consent from a business relationship within the last two years. Penalties reach $10 million per violation for corporations and directors can be personally liable, which is why our audit documents the consent basis per segment.
How do you actually measure inbox placement?
With GlockApps seed-list tests: we send to a controlled panel of Gmail, Outlook, and Yahoo addresses and record where each message lands. ESP dashboards report "delivered," which includes the spam folder. One SaaS audit we reference showed 99% delivered while only 71% reached the inbox. Seed testing catches that gap.
Can a damaged sender reputation be repaired?
Usually, but slowly and by sending less. Repair means suppressing the segments generating complaints, fixing authentication, warming the remaining volume, and watching Google Postmaster Tools until reputation recovers. Expect weeks, not days. In one referenced repair, complaints fell from 0.42% to 0.08% over six weeks, with send volume down 38% during the suppression phase.
Get a placement read before it costs you
A working session includes a live look at your authentication records and Postmaster data. Ten minutes usually surfaces the first fix.
Book a working session