Skip to main content

Compliance

Commercial email is regulated almost everywhere, and mailbox providers add rules of their own. Mumara ONE gives you the tools to meet them, and handles the technical parts, such as authentication, unsubscribe processing and bounce handling, for you. What you send and who you send it to remain your responsibility.

This isn't legal advice

This page explains what Mumara ONE does and names the main laws that apply to email. It doesn't tell you what the law requires in your situation. Check that with your own legal adviser.

Who does what​

AreaWhat Mumara ONE doesWhat you do
ConsentWeb forms that can require email confirmation, a Confirmed status on every contact, and Skip unconfirmed when you sendCollect permission from everyone you mail, keep a record of it, and never use bought or scraped lists
UnsubscribingAn unsubscribe link, the one-click List-Unsubscribe header, and immediate processingKeep a working unsubscribe option in every marketing email, and respect requests across all your lists
Bounces and complaintsProcessed automatically, and those contacts are left out of your campaignsDon't re-import addresses that bounced, complained or unsubscribed
Identifying yourselfDKIM signing and SPF on your own domain, and support for DMARCUse an honest From name and subject line, and include your postal address
Personal dataStores your contacts on Mumara's own infrastructure and processes them under a Data Processing AgreementHave a lawful basis for holding the data, and handle requests from the people in your lists
Acceptable useWatches your bounce and complaint rates and handles abuse reportsFollow the Acceptable Use Policy

Mumara's Acceptable Use Policy requires explicit, verifiable permission from everyone you send marketing email to. Bought, rented, shared and scraped lists are prohibited, whatever the seller promises.

Mumara ONE helps you collect and respect that permission:

  • Double opt-in on web forms. Under Setup → Web Forms, switch on Require email confirmation for a form. New subscribers are sent a confirmation email and are only confirmed when they click its link, so mistyped, fake and malicious sign-ups never become confirmed contacts.
  • Confirmation status on every contact. Each contact is Confirmed or unconfirmed. When you import contacts, Confirmation Status sets which. Only import contacts as confirmed if they really did confirm.
  • Skip unconfirmed. When you schedule a campaign, switch on Skip unconfirmed to leave out every contact who hasn't confirmed.

Keep your own record of where, when and how each person signed up. If a complaint suggests someone never agreed to hear from you, Mumara may ask you for that evidence, and sending stops if it can't be produced.

Unsubscribing​

Every marketing email needs a clear, working way to unsubscribe. Mumara ONE gives you two, and you should use both:

  • An unsubscribe link in the message. When you schedule a campaign, Insert Unsubscribe Link adds one to the bottom of the email. You can also place the link in your own design with the unsubscribe link from the editor's Variables menu. If the switch shows Force Enabled, the link is always added.
  • One-click unsubscribe. Add List-Unsubscribe header is on by default when you schedule a campaign. It lets Gmail, Yahoo, Apple Mail and others show their own Unsubscribe button, which unsubscribes the recipient without visiting a page. See One-click unsubscribe for what your sending domain needs.

Unsubscribes take effect immediately, on the list the message was sent to. If someone asks to stop receiving all your email, add them to Email Suppression with Global selected. See Bounces and Complaints.

Purely transactional messages, such as receipts and password resets, generally don't need an unsubscribe link. A message that mixes transactional content with promotion is usually treated as marketing, so it needs one.

Identifying yourself​

  • Send from your own verified domain. Every message is signed with DKIM for your sending domain, and bounces use a return path on that domain, so mailbox providers can see who really sent it. See Sending Domains.
  • Be honest in the From name and subject line. Recipients should recognise who you are and what the email is about.
  • Include your postal address. CAN-SPAM and CASL require a valid postal address in commercial email. Mumara ONE doesn't add one for you, so put it in the footer of your templates.

The main laws​

These are the laws that come up most often. Each has more detail than this summary, and other countries have their own rules.

LawWhereIn broad terms
GDPR and UK GDPR, with the ePrivacy rules and the UK's PECREuropean Union, United KingdomYou need a lawful basis, usually consent, to send marketing email, a record of that consent, and a way for people to exercise their rights over their data, such as access and erasure
CAN-SPAM ActUnited StatesNo deceptive headers or subject lines, a clear opt-out that you honour promptly, and a valid postal address in every commercial email
CASLCanadaExpress or implied consent before sending, identification of the sender with contact details, and a working unsubscribe that you honour promptly

Mumara's own GDPR page explains how Mumara meets its obligations as your processor.

Gmail, Yahoo and Microsoft sender requirements​

The largest mailbox providers have their own rules for bulk senders, and they enforce them by filtering or rejecting mail that doesn't comply. Google and Yahoo publish theirs, and Microsoft applies similar rules to Outlook.com.

RequirementHow Mumara ONE covers itWhat you do
SPF and DKIMEvery message is DKIM-signed for your sending domain, and SPF is checked against your bounce subdomainPublish the DKIM and bounce domain records for each sending domain
DMARCSupported. Enable DMARC on your sending domain shows the record to publish.Publish a DMARC record, starting with p=none. See DMARC Authentication.
Alignment with the From domainDKIM and the return path both use your sending domainSend from an address on a verified sending domain
Valid reverse DNS for sending IPsEvery sending IP has a reverse DNS name that resolves back to itNothing. If you set your own hostname on a Dedicated IP, follow IP Settings.
TLSMail is delivered over TLS whenever the receiving server supports itNothing
One-click unsubscribe, honoured within two daysAdd List-Unsubscribe header is on by default, and unsubscribes take effect immediatelyKeep the header on, and keep your tracking domain verified with a valid SSL certificate
A low spam complaint rateComplaints are processed automatically, and complaining contacts are never mailed again from that listMail only people who asked. Google asks bulk senders to keep the spam rate shown in its Postmaster Tools below 0.1% and never to reach 0.3%, and Yahoo uses 0.3% as its limit.

Gmail doesn't report individual complaints back to senders, so its spam rate for your domain only appears in Google Postmaster Tools. Verifying your sending domain there is worth the few minutes it takes.

Personal data​

Your role and Mumara's​

For the contacts you upload or collect, you're the controller: you decide what data to hold and why. Mumara processes that data on your behalf as your processor. The terms are set out in Mumara's Data Processing Agreement, and Mumara's own use of personal data in its Privacy Policy.

Access and export​

When someone asks what you hold about them, or you need a copy of your data:

  • Find a contact under Contacts → View/Search Contacts, and choose Email History from the contact's actions menu to see what they've been sent.
  • Export a list from Lists → Contact Lists, with Export contacts in the list's actions menu. Segments and suppression lists can be exported too.
  • Download exports under Tools → Exported Files.

To automate requests from your own systems, use the API. See API overview.

Erasure​

To erase someone, delete their contact from every list they're on. For many contacts at once, Contacts → Bulk Update Contacts has a Delete selected contacts action.

Deleting a contact doesn't stop the address from being added again by a later import or sign-up. Many senders keep the address in Email Suppression for that reason, which keeps the address itself on file. Whether that's right for you is a question for your adviser.

Log retention​

Delivery logs and the engagement records in Analytics are kept for as long as your plan allows, then deleted. The Log Retention card on the Dashboard shows how many days that is for your plan. See How long data is kept.

When your account is terminated​

When your Mumara ONE service is terminated, your account and everything in it, including lists, contacts, campaigns, statistics and logs, are permanently deleted. Export anything you need to keep before you cancel. See Subscription and Plans.

Acceptable use​

Everyone who sends through Mumara ONE agrees to Mumara's Acceptable Use Policy, which is part of the Terms of Service. In short, it covers:

  • Permission. Explicit, documented consent from every recipient. No bought, rented, shared, scraped or appended lists.
  • Prohibited content. Nothing that's phishing, malware, fraud or a scam, infringes someone else's rights, harasses or incites hatred or violence, sexually exploits children, or is illegal where the recipient lives.
  • Restricted industries. Categories such as gambling, adult content, cryptocurrency promotion, pharmaceuticals and debt relief need Mumara's approval before you send, and some are refused. Contact Mumara with the subject "Use-case review" to have yours checked first.
  • Enforcement. Breaches can lead to a warning, throttling, suspension or termination of your account.

Recipients and mailbox providers who receive email from any Mumara IP can report abuse through the public postmaster page. Reports are traced to the account that sent the email. See Sending Reputation.