- Authentication
- SPF, DKIM and DMARC are published for a business’s subdomain at provisioning, before the first message. A subdomain that is not fully verified cannot send.
- Isolation
- One business, one subdomain. Client mail is also kept on separate sending infrastructure from the operator’s own mail, so neither can affect the other’s standing.
- Consent basis
- Inbound-initiated. The recipient of any message wrote to that business first, at an address the business published. There is no other way for an address to enter the system.
- Automatic suspension
- Sending pauses for a business that crosses 5% hard bounces or 0.3% complaints over a rolling 30 days — or 3 complaints at any volume at all, which deliberately applies from the very first send. A paused business keeps its drafts; it just cannot send them.
- Operator stop
- A single manual control halts sending for every business at once, taking effect immediately and without a deployment. It exists for the failure the thresholds did not anticipate.
- Duplicate protection
- Each outbound message carries a unique identifier enforced at the database level, so a retry or a double-click cannot put two copies of a reply in someone’s inbox.
- Threading
- Replies carry correct
In-Reply-To, References and Reply-To headers, so the conversation stays in one thread and the customer’s answer reaches a monitored inbox.
- Delivery outcomes
- Bounces and complaints are recorded per message against a rolling window, not as a counter that only ever climbs — a business that had a bad week can recover, and a business with a live problem is visible while it is live.
- Message content
- Used to classify the message and draft a reply for that business’s owner. It is not sold, not shared between businesses, and not used to train models.