Email deliverability and sender protection for MSPs

Sender profiles with sending caps, a warm-up ramp, nightly health checks and DNS graded on six checks, so one bad send cannot burn the domain you bill from.

Deliverability

Protect the domain your invoices come from.

A normal CRM gives you one mail setting and a send button, and you find out about a bad list when your invoices start landing in spam. MADDOX sends through named sender profiles — your own SMTP server, Postmark or Mailgun — each with its own sending cap, an optional warm-up ramp and a health check run every night. Before a campaign launches, the sender it uses is graded on six checks and the ones that matter by law or by mailbox rules can stop the launch, each with a link to the fix. A sender that starts bouncing is paused before it does more damage.

How it works

How a sender earns the right to send

Three layers, in the order a send meets them. The second is where most deliverability problems are caught before they cost anything.

Set up a named sender

Add a sender profile for each identity you mail from: the newsletter from one domain, tech tips from another. Each has its own from address, reply-to, transport and limits, and one is the workspace default an unassigned campaign falls back to.

Check it before it sends

The sender is graded on SPF, DKIM, DMARC, a postal address, a working unsubscribe and its recent health. DNS is re-read automatically once a reading is a day old, and a failed SPF, DKIM, postal address or unsubscribe stops a launch with a link to the fix.

Govern every send

Each send reserves room under the sender’s per-minute, per-hour and per-day caps before it is written, so two workers cannot both squeeze past the last slot. Over the cap, the send waits for the next window rather than being dropped, and the reason is written down.

In the product

Every sender, its checks and its health, on one screen.

sender_profiles: 3 checks_per_sender: 6 senders_paused: 0 Sample data — illustrative product UI, not a performance claim.

Sender profiles

One identity per sender, not one setting per workspace.

An MSP rarely mails from just one place. The newsletter, the security alerts and the sales follow-ups are different reputations and deserve different senders.

SMTP, Postmark or Mailgun, under your own name.

A profile wraps a transport: a generic SMTP server with its host, port and encryption, or a Postmark or Mailgun account. Credentials are stored encrypted, and the settings screen reports whether a secret is present without ever decrypting it to draw the list. Every profile can send itself a test before it sends anything else.

A profile can also wrap a connected Microsoft 365 mailbox. That needs the Microsoft 365 integration switched on, which is opt-in and ships off, and it comes with a limit worth knowing before you choose it, covered under delivery receipts below.

A default, and what happens when a sender is switched off.

Exactly one profile is the workspace default. A campaign can name its own sender; one that names none uses the default. Switching a profile off is reversible and separate from deleting it, and a campaign that pointed at a disabled profile still shows it, marked disabled, rather than silently pretending nothing changed.

The six checks

Graded on six checks, and only four of them can stop you.

A check that blocks on a guess is a check people learn to route around. So the grade separates what is wrong from what we could not find out.

What is checked.

Each sender is graded pass, warn or fail on:

  • SPF — whether the sending domain authorises this transport
  • DKIM — whether messages from it are signed under your selector
  • DMARC — whether a policy is published and aligned
  • A postal address — the physical address CAN-SPAM requires in every marketing email
  • Unsubscribe — whether the opt-out link and its handler actually work, and whether the transport can carry the one-click unsubscribe header the big mailbox providers expect from bulk senders
  • Health — the sender’s recent bounce and complaint rates

What blocks a launch, and what only warns.

A failed SPF, a failed DKIM, a missing postal address or a broken unsubscribe can refuse a launch, because each one is either a legal obligation or the thing that sends your mail to junk. DMARC that is missing or set to monitor-only, a transport that cannot carry the one-click header, and degraded health all warn loudly and never block.

A DNS lookup that fails on our side is graded “Couldn’t check” and never blocks. That distinction matters: an operator told “SPF: amber” spends twenty minutes in a DNS console hunting a record that is already correct.

Re-read automatically, so a DNS change cannot go unnoticed.

An hourly sweep re-reads each sender’s DNS once its last reading is a day old, so somebody editing the domain’s records for an unrelated reason shows up as a changed grade rather than as a quiet drop in opens a fortnight later. A sender can also be re-checked on demand from its profile, from an email step and from the email template editor.

The governor

Caps that hold under load, and a warm-up you choose.

Reserve first, then send.

Most cap schemes count what has been sent and then send another, which leaves a gap two workers can both pass through. Here each send reserves its place under every cap in one atomic step before the email is written, so a cap of a thousand a day means a thousand, not a thousand and some. Caps run per minute, per hour and per day, and the day is the sender’s own day in its own time zone.

Over the cap means later, not lost.

A send that finds no room is deferred to the next window with a little jitter, so a large launch spreads out instead of stampeding at the top of the hour. The deferral is written to the same ledger as every other reason a send did not go, which is what lets you answer “why has this contact not had email three yet”.

Warm-up is recommended, never forced.

A new sender is offered a warm-up ramp. Start it, and the day cap is held lower and raised each day until it reaches the limit you set. Skip it — because the domain has been sending for years and you are just moving it over — and the skip is recorded as an answer, so you are not asked again. A ramp only ever lowers a cap; it never pauses a sender.

Health

A sender going bad is stopped before it takes the domain with it.

Measured every night on sends old enough to have bounced.

Each night every sender is judged on its last hundred sends that are more than an hour old — recent enough to be current, old enough that a bounce has had time to arrive. Two rates come out of that window: hard bounces and complaints. Below a minimum sample the rate is reported as not enough data, never as zero, because “0% bounces” and “too few sends to say” are opposite pieces of news.

Cross the warning line and the sender is flagged on its profile and in the launch panel. Cross the pause line and it stops sending. A provider rejecting the sender outright pauses it immediately, without waiting for the nightly pass.

Resuming is a person’s decision.

A paused sender stays paused until somebody resumes it, and a campaign whose sender is paused cannot launch until that happens or the campaign is pointed at another sender. Saving a new cap on the profile cannot un-pause it by accident either; the health fields are written only by the governor.

Compliance and receipts

Unsubscribes, addresses, signatures and what actually arrived.

One-click unsubscribe and the CAN-SPAM address.

Marketing sends carry a visible unsubscribe link and, wherever the transport can carry it, the machine-readable one-click header. The one-click endpoint works without a login because a mail client posts to it on the recipient’s behalf. An unsubscribe lands in the suppression ledger every send path consults, not in one campaign’s settings.

The postal address in the footer comes from the workspace setting, with a per-profile override for the case that makes the workspace address wrong: a sender mailing on behalf of a separate legal entity. The launch check and the footer read the same resolved address, so the check can never pass while the footer prints nothing.

Per-profile webhooks, receipts and bounces.

Each sender profile gets its own signed webhook address for your provider to report back to. Delivery receipts and bounces are recorded against the email they belong to; a reply ends that contact’s cadence, and a bounce suppresses the address everywhere. A campaign’s Recipients tab shows each recipient’s delivery state — sent, delivered, bounced or unknown — with a sentence saying what that state means on that transport.

Microsoft 365 is the exception, and the product says so plainly: sending through a Microsoft 365 mailbox returns no delivery receipt, so those emails read as unknown, and that is the final answer rather than a pending one.

Per-user email signatures.

Each user keeps their own email signature in their settings, and the launch panel flags a campaign whose emails would go out signed by nobody. It is a warning rather than a block, because some campaigns are meant to come from the company rather than from a person.

Who it is for

For MSPs whose marketing domain is also their billing domain

For most managed service providers it is the same domain. A newsletter that lands in spam is annoying; an invoice that lands in spam is a cash-flow problem.

  • Owners who want marketing email without risking the domain clients pay from
  • Marketers moving an existing sender over, who do not need a warm-up forced on them
  • Anyone who has been asked “why did that not arrive” and had no answer

Questions

The things people actually ask.

Which email services can MADDOX send through?

Your own SMTP server, Postmark or Mailgun, as named sender profiles. A connected Microsoft 365 mailbox can be a sender too once the Microsoft 365 integration is switched on; it is opt-in and ships off, and it does not report delivery receipts.

Will a deliverability problem stop my campaign launching?

Four can: a failed SPF, a failed DKIM, a missing postal address or a broken unsubscribe, plus a sender that has been paused for health. DMARC gaps and other warnings never block. Each blocker in the launch panel links straight to where it is fixed.

Do I have to warm up a new sender?

No. A warm-up ramp is recommended for a sender that has never mailed in volume, and you can start it or skip it. Skipping is recorded, so you are not asked again, and a running ramp only lowers the daily cap — it never pauses anything.

What happens when a sender starts bouncing?

It is flagged once its bounce or complaint rate crosses the warning line and paused once it crosses the pause line, measured nightly on its last hundred mature sends. A provider rejection pauses it at once. Only a person can resume it.

Can MSPs use a different postal address per brand?

Yes. The workspace holds the default CAN-SPAM postal address, and a sender profile can carry its own for mail sent on behalf of a separate legal entity. The footer and the launch check read the same resolved address.

Grade your sending domain before your next newsletter.

Add a sender profile, run the check, and read what it says about SPF, DKIM and DMARC. It costs nothing and sends nothing.