What changed
Changes that can affect a send.
Provider, platform, regulation and measured ecosystem changes. Emailrules corrections and publishing notes live in Trust.
Worth your time
Regulator moves and changes at Klaviyo, Mailchimp and Braze — one timeline, because a number that moved does not tell you which system caused it.
14 entries
- Something changedGlobal · Gmail
Gmail enforces authentication, PTR, TLS and a 0.30 percent spam rate
What changed: Expanded to the all-sender PTR, TLS and RFC 5322 requirements that were missing.
Why it matters: If this is wrong, Gmail can reject mail with a clear bounce code or quietly file you in spam.
Do next: Open Google Postmaster Tools and look at user-reported spam over 30 days.Full rule →
- Something changedEU
AI-written marketing email needs no label, but AI product imagery might
What changed: Status moved to In force as of 2 August 2026.
Why it matters: Teams waste budget on blanket “AI generated” footers that the law may not require — or ship fake product shots with no disclosure.
Do next: Ask your designer which product images from the last quarter were AI-generated and photorealistic.Full rule →
- Your platformKlaviyo
Campaign batches can be scheduled by the minute
What changed: Gradual sending moved from hourly intervals to batches as small as one percent of the audience per minute.
Why it matters: Klaviyo frames this as protecting your website from traffic spikes. The deliverability use is the more interesting one. Complaint rate is measured against what actually lands, and a single-shot send to a cold or unusually large audience is how a programme crosses the 0.3 percent line at Gmail and Yahoo before anyone has seen a report. Batching by the minute buys you the time to stop a send that is going badly.
Do next: Pick your next campaign to a re-engagement or newly imported audience and schedule it gradually rather than all at once. Watch the complaint rate on the first batches before the rest goes.Full entry →
- Something changedFR · EU
In France, tracking email opens needs its own consent
What changed: Transition period ended. Status moved from Upcoming to In force.
Why it matters: EU brands (and anyone mailing France) risk non-compliance and ugly vendor surprises.
Do next: If you are on Klaviyo, open the open-tracking settings and check whether anyone has ever used the per-recipient control.Full rule →
- Your platformKlaviyo
API revision 2026-07-15 added a backfill flag and a sending domains API
What changed: Two parts of this revision matter outside engineering. Create Event and Bulk Create Events took a top-level backfill flag that records historical events without triggering flows, which Klaviyo points at CRM migrations and bulk replay. Separately, a Sending Domains API arrived in beta on the same revision: it registers a domain, returns the DNS records to publish, re-runs verification while DNS propagates, and promotes a verified domain from pending to active. Klaviyo warns that activation is a cutover which replaces the account’s previous dedicated domain.
Why it matters: The backfill flag is the one to remember, because the failure it prevents is one people only notice from the replies. Replaying years of order history into a platform is how a welcome flow fires at customers who joined in 2021. Until this revision there was no supported way to load that history without arming the flows. On the domain side, DKIM setup stops being a screen someone clicked through once and becomes something you can script, verify and re-check.
Do next: If a migration or a bulk replay is anywhere on the roadmap, confirm whoever is writing it is on revision 2026-07-15 and using backfill. Klaviyo supports each revision for two years from release, so an integration pinned to an older one does not have this.Full entry →
- Your platformKlaviyo
Open tracking can be switched off per recipient
What changed: Klaviyo added controls that stop it recording email opens, either across the whole account or for individual recipients, and its help centre names France’s CNIL and Italy’s Garante as the reason. The pixel is still inserted and the recipient’s mail client still loads it; Klaviyo checks the incoming request against your settings and, when tracking is off, discards it without writing an Opened Email event. Open tracking consent is stored per recipient and per email address, and it is separate from email marketing consent.
Why it matters: Two rules on this site said no mainstream platform shipped a per-recipient path for this. One now ships part of it. Read the limits before you relax: Klaviyo is explicit that it does not remove the pixel, and that it has no recipient-facing way to collect an objection — no footer link, no preference page — so identifying who must be untracked, and setting them, is still yours. Turning it off also removes those people from open rate, from open-based segments and from any flow triggered on an open.
Do next: Settings → Email → Tracking is the account-wide switch, and any user with access to email settings can change it. For the per-recipient version, agree who is in scope with whoever owns privacy, then set them by CSV import, SFTP or API before the send, not after.Full entry →
- Your platformBraze
Microsoft SNDS data appears in the Deliverability Center for Amazon SES senders
What changed: For workspaces that send email through Amazon SES, Braze’s Deliverability Center now displays Microsoft SNDS metrics for dedicated sending IPs, and backfills up to 90 days of history when the feature is switched on for the workspace.
Why it matters: SNDS is the only place Microsoft tells you what it thinks of your IP — complaint rate, trap hits, filter result — and most senders never look, because it lives behind a separate registration on a Microsoft site nobody has open. Putting it in the tool people already have open is the difference between knowing and guessing. Read the scope before you celebrate: dedicated IPs, and only for workspaces on Amazon SES.
Do next: Switch it on and read the backfilled 90 days before you read anything else. If your complaint rate at Outlook was already high, the history will show you the week it started, which is usually the week something else changed.Full entry →
- Something changedGlobal · Gmail
Gmail enforces authentication, PTR, TLS and a 0.30 percent spam rate
What changed: Noted the Postmaster v2 reputation dashboard retirement.
Why it matters: If this is wrong, Gmail can reject mail with a clear bounce code or quietly file you in spam.
Do next: Open Google Postmaster Tools and look at user-reported spam over 30 days.Full rule →
- Your platformKlaviyo
Transactional and service mail can have their own branded sending domains
What changed: Klaviyo added separate branded sending domains per send type, so transactional and service email no longer share a sending domain — and therefore a reputation — with marketing volume.
Why it matters: Receipts, password resets and shipping notices are the mail people actually need, and they are the mail that suffers when a marketing campaign lands badly on the same domain. Splitting the domains is the standard fix and it is now a setting rather than a project. Worth being precise about what it does not do: moving a message to a service domain does not make it transactional. That is decided by content and by why you are sending it.
Do next: List what your account sends that a customer would call for if it went missing. If those messages leave on the same domain as your campaigns, this is the setting you came for.Full entry →
- Your platformBraze
Orphaned subscription records stopped being inherited by new profiles
What changed: Braze now manages what it calls orphaned subscription state records — subscription data held against a phone number or email address that is not attached to any user profile — to stop a newly created profile inheriting subscription state from a deleted or unrelated user. Braze files the item under SMS; its own description of the record covers a phone number or an email address.
Why it matters: Inherited subscription state is a consent bug wearing the costume of a data bug. A profile created on an address that once belonged to someone else could arrive already subscribed, and nothing in your records would explain why. Every regime that requires provable consent requires it for a person, not for a string of characters that has had two owners.
Do next: If you have ever deleted and recreated users on the same addresses — a migration, a de-duplication, a tidy-up of test accounts — spot-check a handful of those profiles for a subscription nobody gave.Full entry →
- Your platformBraze
The Email Open event started carrying a machine_open field
What changed: Braze’s Email Open event now generates a machine_open field value, which reports into a Machine Open metric.
Why it matters: Apple’s Mail Privacy Protection fetches images on the recipient’s behalf, so a large share of every open a platform records is a proxy server rather than a person. Until the two are separated, open rate is a number describing Apple’s infrastructure. A flag in the event stream is what lets you take machine opens out of a report, a segment or a re-engagement trigger — but the flag does nothing until somebody changes the report.
Do next: Find the segments and flows that treat an open as engagement, starting with the sunset policy. One that counts a machine open will keep mailing people who have not looked at you in a year, and will report that as success.Full entry →
- Your platformMailchimp
New Audiences endpoints put consent mapping back on the caller
What changed: Mailchimp released Audiences endpoints in beta as an alternative to List Members, so a contact can be created from an SMS number with no email address at all. The release note carries a condition in its own words: consent must be accurately mapped to the supported marketing consent values, and unsupported values, including opt-outs, must be updated manually.
Why it matters: That sentence is the whole entry. A migration that maps consent loosely is how unsubscribed people quietly reappear as subscribed, and this note is telling you in advance that the endpoint will not carry an opt-out across for you. Under CASL and under ePrivacy the burden of proving consent sits with the sender, and “the API did not support that value” is not a record of consent.
Do next: If anyone is loading contacts through these endpoints, ask what happens to a consent value the endpoint does not support. If the answer is that it is dropped, the opt-outs need their own pass before the first send, not after the first complaint.Full entry →
- Your platformMailchimp
Mailchimp began overwriting campaign_id and outreach_id on orders
What changed: Mailchimp started writing over the campaign_id and outreach_id values on orders to match its own attribution model and the account’s settings, and told integrations that send those values with Add Order or Update Order to deprecate that logic.
Why it matters: If you have ever tried to reconcile platform revenue against the shop’s own numbers and lost an afternoon, this is the shape of change that causes it. The platform, rather than your integration, now decides which message a purchase belongs to. Nothing about the emails changed. The number you report did, and it changed on a date.
Do next: Before comparing this year’s attributed revenue with last year’s, check whether the series crosses 6 December 2024. If it does, you are comparing two different attribution models and the trend line is telling you nothing.Full entry →
- Your platformMailchimp
Transactional sending domains had to publish DKIM and DMARC
What changed: Mailchimp told Transactional (Mandrill) users that from 15 March 2024 it would enforce new sending domain authentication requirements, citing the Google and Yahoo announcements. Two DKIM CNAMEs — mte1._domainkey and mte2._domainkey, pointing at dkim1.mandrillapp.com and dkim2.mandrillapp.com — plus a DMARC TXT record at _dmarc, for which the note gives the value v=DMARC1; p=none. Domains that did not comply would have their mail sent from a mandrillapp.com subdomain instead, with replies still routed to the original address.
Why it matters: This is the clearest example on the site of a platform doing the mechanical half and leaving the judgement. The record Mailchimp asks for is p=none, which is monitoring: it asks receivers to report and instructs them to reject nothing. A domain that followed this instruction to the letter and then stopped is authenticated as far as the platform is concerned and still unprotected against someone spoofing it. The fallback is worth knowing too — your mail keeps going out, but from a domain that is not yours, which is not what anyone reading the From line expects.
Do next: Read your own _dmarc record today. If it still says p=none and nobody is reading the reports, you completed the platform’s task and not the one that protects you.Full entry →
Wrong or stale? Read or report a correction.