Trust & deliverability
Between “Send” and an arrival, six things happen — in this order, every time. Nothing is sent inline.
Queued, not sent inline
Your campaign enters a send queue. The editor returns immediately; dispatch is a separate, rate-controlled process you can watch from the campaign page.
Plan quota checked
Before anything is enqueued, the send is counted against your plan's monthly send allowance. Over quota, the campaign waits — it never bills you silently.
Every recipient filtered against suppression
Unsubscribes, hard bounces and spam complaints are removed before dispatch — on every send, on every plan. There is no setting to skip this.
Signed by your authenticated domain
Each message is DKIM-signed with the domain you verified — or the shared platform subdomain if you haven't added one yet.
Handed to the sending provider
The signed message passes to the mail provider over a warmed, monitored connection. Bounces and complaints flow back into your suppression list automatically.
The receiving mailbox decides
From here, placement is the recipient's mailbox provider's decision — not ours. What happens before this step is what we control, and it's everything above.
On Starter and above, you authenticate your own sending domain through a guided wizard: we show you the exact records to publish — SPF, DKIM, DMARC — and poll until each one verifies. Your own authenticated domain is what separates your sender reputation from everyone else's on the platform.
Specimen — records for a sample domain
2 of 3 verified| Record | Type | Host | Value | Status |
|---|---|---|---|---|
| SPF | TXT | @ | v=spf1 include:mail.sendora.saascode.ai ~all | Verified |
| DKIM | CNAME | s1._domainkey | s1.dkim.sendora.saascode.ai | Verified |
| DMARC | TXT | _dmarc | v=DMARC1; p=none; rua=mailto:dmarc@example.com | Pending |
No domain? You still send today. Entry-tier accounts send from a shared platform subdomain — a real, working configuration with zero DNS work on day one. Your own domain is the upgrade, not the entry gate.
The mechanism
Mail privacy features — Apple Mail Privacy Protection most visibly — preload tracking pixels on the recipient's behalf. A large share of recorded “opens” are machines, and there is no official way to filter them.
The consequence
Industry measurements put the machine share of opens at roughly 40–49%. So an open rate is a number with a hole in it — and we label it that way everywhere it appears.
The decision
Clicks are the primary engagement metric. A click is a real human action recorded at redirect time — no preloading, no inference. Open tracking exists as a per-org toggle, off by default.
Specimen — a campaign report row, as it renders
2.3%
Click rate
Human actions, counted at redirect.
—
Open rate
Nothing recorded — open tracking is off.
0.6%
Bounce rate
Hard bounces auto-suppressed.
0.04%
Complaint rate
Well under the 0.1% warn line.
0.2%
Unsubscribe rate
Each one lands in suppression.
Open tracking — off by default
Per-organization toggle. Every figure it produces ships with its caveat attached inline.
Every contact carries a consent record from the moment it enters your account. Forms support double opt-in. And when consent ends, the record of that is kept just as carefully.
Specimen — one consent record
Proof of consent is exportable per contact — timestamp and source, ready when someone asks.
Unsubscribes
Suppressed for this organization from the moment the link is hit. Consent belongs to the list a person joined.
Hard bounces
Suppressed platform-wide. A dead address is bad for every sender, so it's held everywhere.
Spam complaints
Suppressed platform-wide, fed back automatically from the mailbox providers' complaint loops.
Enforcement
Checked against every recipient before dispatch, on every send, on every plan. The suppression list is exportable whenever you need to prove it.
And because you're billed per send, not per stored contact: unsubscribed and bounced contacts never count toward any plan limit.
A click is measured at a redirect, and that redirect is logged. Every tracked link routes through a redirect on this platform before it reaches its destination, so recording the click means recording the request that made it — the recipient's IP address, the coarse location derived from it, the user agent and the timestamp — retained for campaign reporting and abuse investigation. Under ePrivacy that logging is disclosed separately from the consent record above, which is why it is written here rather than left implied.
A shared sending platform is only as good as its worst sender. These rules protect everyone on it — including you, on the day your own list goes stale.
| Policy | Threshold | What happens |
|---|---|---|
| Quota check | Plan allowance | Counted before anything is queued. Over quota, the campaign waits — never a silent overage. |
| Complaint rate — warn | 0.1% | A banner on your dashboard with the campaigns driving it. Nothing is paused at this line. |
| Complaint rate — auto-pause | 0.3% | Sending pauses. You keep full access to contacts, campaigns and exports; queued sends wait. |
| Complaint rate — block | 1% | Sending is blocked pending review. Your data stays yours and exportable throughout. |
| Domain warmup | New domains | A newly verified domain ramps on a schedule — volume rises over the first sends instead of arriving all at once. |
Complaint thresholds run on a 24-hour rolling window. A paused org is un-paused by cleaning the segment that drove complaints and confirming the fix — a human reviews blocks, not a form letter.
Sendora controls
Sendora does not control
That is why this page publishes no inbox-placement rate and no deliverability percentage. Placement is decided on the receiving side, by systems we don't operate — so no number we could print here would be honestly verifiable, and an unverifiable number on a page about honest measurement would be the worst kind. What we publish instead is the mechanism, the thresholds, and the caveats.
Check the mechanism yourself — the first campaign will show you exactly what this page describes.