This guide assumes transactional email is already deployed and passing. It covers what breaks at scale and how mature teams operate it.
Edge cases that break a working setup#
- Adding upsell banners to receipts, which reclassifies them as marketing under many laws.
- Using one shared IP pool for both streams.
- Mail forwarded through mailing lists or personal forwarders, which alters headers and content.
- Acquisitions and rebrands that introduce domains nobody audited.
- Vendors silently changing their sending infrastructure.
Operating it as infrastructure#
- Assign an owner for each sending domain and each vendor relationship.
- Put DNS records under version control or a change-review process.
- Alert on authentication pass rate drops and reputation changes, not just outages.
- Run a quarterly audit against the setup steps below.
- Document runbooks for the three most common failures.
Reference: the baseline setup#
- Send transactional mail from a dedicated subdomain (for example mail.yourdomain.com) or separate stream.
- Send marketing from a different subdomain (news.yourdomain.com).
- Keep promotional content out of transactional messages to preserve their exemption.
- Apply DMARC to the organizational domain so both subdomains are covered.
Frequently asked questions#
Do transactional emails need an unsubscribe link?
Not under CAN-SPAM if purely transactional. Gmail's bulk-sender rules still expect one-click unsubscribe for anything sent at volume, so many senders include it anyway.