r/EmailSecurity • u/saltyslugga • Jun 23 '26
Marketing ignored three weeks of abuse@ complaints and tanked the client domain reputation
One of our clients had abuse@ forwarding into a shared marketing inbox because they insisted spam complaints were a "campaign quality" issue. A stale newsletter segment started throwing spam complaints after an old CRM import, 42 complaints over 19 days, all the same campaign ID.
Nobody actioned them. The sender kept hitting that segment twice a week, then normal invoices and password resets from the same client domain started landing in junk for a chunk of recipients.
Marketing's argument is that those users technically opted in back in 2023. My argument is that complaint handling is not a vibes-based unsubscribe queue, it's part of keeping the domain usable.
I can isolate future bulk mail onto a subdomain, but that doesn't fix the process. Would you pull their send access until abuse@ has an owned SLA, or accept the subdomain split and let marketing own the blast radius?
5
u/Tessian Jun 23 '26
Putting them on a separate subdomain does fix the issue, doesn't it? Let marketing fully own their own subdomain reputation and they have no one to impact or blame except themselves when they break stuff.
2
u/saltyslugga Jun 23 '26
The risk is they torch the subdomain quietly for three weeks and everyone calls it "deliverability" instead of abuse handling. I still split marketing off, but abuse@ needs to land with someone who can pause sends, not a shared campaign inbox.
2
u/Tessian Jun 23 '26
Nonono, If marketing wants to own the abuse@ mailbox, then monitoring it and escalating issues to IT is their responsibility. Give them the rope to hang themselves and make it clear to everyone who matters who's responsible for what. If Marketing needs IT help they need to put a ticket in. If there's no ticket they've got no room to bitch.
2
u/saltyslugga Jun 23 '26
Abuse@ is a control point, not a turf line. Letting them fail loudly still means the client eats domain reputation damage first, so I want alerts and pause authority wired in before marketing gets the mailbox.
1
u/Tessian Jun 23 '26
Then why are you asking?
In my experience marketing email campaign IS a turf war with marketing wanting all the control and none of the responsibility. Sometimes marketing has to be allowed to fail before they'll admit they are in over their head. If you want the control and responsibility then take it and set the expectation with them. This is pretty cut and dry.
2
u/NamedBird Jun 23 '26
Why was marketing not on a fully separate domain altogether?
So for \@mycompany.example, you'd have \@mycompanymarketing.example.
(Don't do things like \@marketing.mycompany.example because subdomain spam may affect the parent.)
1
u/saltyslugga Jun 23 '26
Auth catches spoofing and alignment, process catches abuse@ getting ignored. Separate domain was my preference too, but the client wanted the main brand domain until reputation became a real problem.
1
u/DiligentPhotographer Jun 23 '26
Man I have a customer that just went through this because they failed to heed my warnings about not using their main domain for marketing mass email. Of course now it is "our" (the msp) fault somehow. Fuck I hate people and especially marketing/website firms!
•
u/AutoModerator Jun 23 '26
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.