Sender protection
A domain’s reputation takes months to build and days to spend, and the tools that optimise for volume put the entire cost of that on the customer: they send what you tell them to send, and managing the consequences is your problem.
The position here is the opposite. The system enforces its own limits, refuses sends it can’t make compliant, and treats a degrading mailbox as something to fix rather than something to report. None of that is gated behind a higher plan — it is what the product is.
Each of these describes something the system does or refuses to do. None of them is a promise about an outcome, because an outcome depends on your content and your recipients as much as on our infrastructure.
A newly connected mailbox does not start at full volume. It moves through new, warming, and stable, and the daily cap ramps with it. The cap is computed by the system, not typed in by the sender.
What it refuses
While a mailbox is still ramping, the pipeline will not exceed its current cap even if drafts are queued and approved.
Every candidate address goes to a paid verification service — an SMTP probe, not a syntax check — and comes back valid, risky, invalid, or unverifiable. The check runs when the account is researched and again when a draft is written, not at the moment the company was discovered.
What it refuses
An address confirmed invalid is never drafted to, whatever its origin. An address we constructed from a name pattern is held to a stricter standard than one published on the company's own site, because production measured those bouncing at 29% against 7.5%.
Daily send limits are enforced by the sender itself, not left to the operator's judgement or to a setting somebody can nudge upward on a good day. Quiet hours resolve in the recipient's timezone, not yours.
What it refuses
The pipeline refuses to send past the ceiling. There is no override that makes it send more.
Bounce rate is measured continuously over a rolling window of sends, and three tiers act on it: a warning, a lockout that stops guessed addresses while verified ones continue at a halved cap, and a full halt of the mailbox.
What it refuses
Each tier releases at a lower rate than it trips at. A gate that released at its own trip point would flap every time the rate hovered, and a send gate that flaps is worse than one stuck in either state.
A halt freezes its own denominator: no new sends means the rate cannot move, so release depends on old sends ageing out. Recovery grants a small allowance to a deliberately clean cohort whose results do count toward the window, so doing the right things measurably shortens the halt.
What it refuses
Recovery stages are earned by clean sends, never by elapsed time. A timer would rebuild exactly the brake-with-no-pedal that recovery exists to remove.
Google Postmaster reputation data and DMARC aggregate reports are ingested and tracked per domain, so a reputation problem is visible as a trend rather than as the day the replies stopped.
What it refuses
A monitor that has stopped reporting is shown as stale, not as healthy.
Unsubscribe links are signed, so they cannot be forged or enumerated. An opt-out is recorded against the address and consulted on every send, under every identity and mailbox the workspace owns — and it survives the company being rediscovered later.
What it refuses
A message that cannot carry a sender identity and a working unsubscribe link does not send at all. The send fails rather than going out non-compliant.
You will see a version of that sentence on a lot of competitors’ pages, and it is not something any vendor can promise. Complaint rate is driven by who you write to and what you say to them. Infrastructure can cap volume, verify addresses, and stop when bounces climb — it cannot make a message welcome.
So we describe what the system enforces and let you judge whether that is enough. It is a weaker sentence and a stronger claim.
Related reading: cold email deliverability and sender reputation in the glossary, and how consent and opt-out are handled.
We launch on 1 October 2026. Join the waitlist for early access in order, with launch pricing locked for your first 12 months.