Resources
Frequently asked questions
A living document. Missing something? Ask us directly and we will answer — and add the question here if it is one that comes up often.
Company & engagement
Do you publish pricing?
No. Every project is scoped individually and priced against the specific infrastructure and operating envelope required. Contact us for a proposal.
Do you accept every prospective client?
No. We evaluate every prospective engagement against our operating policy. Content, list source, jurisdiction, vertical and expected deliverability outcome all factor in. Declining a project is not unusual.
What is a typical engagement length?
Retainers are monthly with no fixed term. Most clients remain for years; some for over a decade. There is no penalty for leaving.
Do you have a minimum monthly volume?
Not formally. In practice, dedicated infrastructure below roughly 250k messages/month rarely pays off; consulting is a better fit at those volumes.
What regions do you operate in?
US-East, US-West, UK, Netherlands, Germany, Switzerland and Singapore. Additional regions on request for enterprise engagements.
Who owns Northbound?
Northbound is privately owned by its founders. There is no external investment, no board, and no acquisition intent.
Do you sign NDAs?
Yes. Mutual NDA is routine before scoping conversations for confidential programmes.
Can you white-label?
Yes, for agency and reseller engagements. WHOIS, PTR, nameservers and support attribution can reflect the client's brand.
Infrastructure
Which MTA software do you run?
PowerMTA is our default for high-volume marketing. Postfix and OpenSMTPD are used for transactional and lower-volume deployments where their operational profile is better suited.
Can we bring existing IPs?
Sometimes. Clean history, BGP-announcable through our AS, and passing an initial reputation check. Otherwise a fresh allocation with a warm-up plan is recommended.
Do you offer IPv6?
Yes for outbound where the receiving provider supports it well. Many providers still throttle IPv6 more aggressively; we default to IPv4 for transactional streams.
Do you run open relays?
No. All submission requires authentication or explicit IP allow-listing.
Can we access the servers directly?
Not by default. Audited SSH access can be arranged for a nominated engineer on request. Most clients prefer scheduled reports.
How much log retention do you provide?
60 days hot, 12 months archived by default. Longer on request.
What is your uptime target?
99.95% acceptance uptime, monitored externally. Historical performance has been higher.
Do you provide DDoS protection?
Yes. All transit is scrubbed. Application-layer protections are in place for public endpoints.
Can we deploy in our own data centre?
Yes, for enterprise engagements. We can operate infrastructure on client-owned hardware in client-owned facilities.
Do you run PowerMTA Movable Ink or integrations?
We do not resell third-party creative tooling. Clients running these products integrate them upstream of our submission endpoints.
Deliverability practice
Do you guarantee inbox placement?
No responsible provider does. We measure placement, own the infrastructure that most influences it, and commit to a defined operating envelope. Guarantees on filter behaviour are marketing, not engineering.
How do you measure inbox placement?
Seed panels across Gmail, Outlook, Yahoo, Apple, and O365 corporate tenants, sampled per major send. Correlated with Postmaster and SNDS data for triangulation.
Do you help with content?
We advise on how content will be treated by classifiers. We do not write marketing copy. Compliance copy remains the client's responsibility.
Can you help recover a reputation collapse?
Yes, though depending on severity it may require rebuilding on fresh IPs and domains, with 4–12 weeks of warm-up. We say honestly what is recoverable and what is not.
How often should we rotate DKIM keys?
Every 6 months as a default. More frequently if there is any suspicion of key compromise.
What is a healthy complaint rate?
Below 0.1% at Gmail and Outlook. Excellent programmes sit under 0.05%. Above 0.3% you should expect reputation issues.
What is a healthy bounce rate?
Under 2% steady-state. Higher during warm-up. Sustained rates above 5% indicate a list hygiene problem.
Should we use dedicated or shared IPs?
Dedicated once sustained volume exceeds roughly 50–100k recipients/day per stream. Below that, dedicated IPs cannot sustain the reputation signal they need.
How long does warm-up take?
10–45 days for most programmes; longer for target volumes above 5M/day. Duration is driven by reputation signals, not calendar days.
Do you handle blocklist delisting?
Yes, where the source is our infrastructure. Where the source is client content or list, we coordinate the delisting request and remediate the root cause together.
What is a reasonable delivery time for transactional email?
Sub-30-second median at Gmail, Outlook and Yahoo. Sub-60-second p95. Longer than that indicates a deliverability or throughput problem.
Do you enforce DMARC?
We help clients migrate to enforcement. Rushing to p=reject without a monitoring phase reliably blocks legitimate mail.
Domains, DNS & authentication
Should we use a subdomain for marketing?
Usually yes. mail.brand.com or send.brand.com keeps marketing reputation separate from corporate mail flow while retaining brand alignment.
Do we need a new domain for each stream?
No. Different subdomains of a shared organisational domain are sufficient for reputation isolation.
Can you manage our DNS?
Yes. We can operate authoritative DNS for the sending domains or apply changes on your existing authoritative servers under our specification.
What happens if we hit the 10 DNS lookup limit for SPF?
We flatten. See our SPF knowledge base article.
Is BIMI worth doing?
For consumer brands with strong recognition and enforcing DMARC, yes. The VMC process is not trivial but the inbox logo has measurable open-rate impact for some verticals.
What DKIM key length should we use?
2048-bit RSA.
Should we sign with multiple selectors?
Yes — per stream, and rotate on schedule. Independent rotation is the main benefit.
Content & lists
Can we send cold email through Northbound?
No. Unpermissioned outreach is outside our AUP.
Can we send to purchased lists?
No. Ever.
Can we send to opt-in lists we have not mailed in years?
Only after a careful re-engagement plan; typically a small warm segment first, aggressive suppression of non-responders, and gradual expansion. Cold-blasting stale lists is a reputation attack on yourself.
Do you review our content?
We advise on how content will be treated by classifiers on the first three campaign families in a new deployment. Ongoing content is the client's responsibility.
Are HTML-only emails a problem?
Not intrinsically. Missing plaintext parts, hidden text, and low-text-to-image ratios are problems. Include a well-formed plaintext part.
Should we suppress non-openers?
Yes, from broadcast streams, once they have been non-opening for 90–120 days. Continuing to mail them produces complaints out of proportion to their volume.
Providers
What is different about sending to Gmail?
Gmail weights user engagement heavily. Complaint rate is decisive above 0.3%. Postmaster is the only official window into Gmail's view of your reputation.
What is different about sending to Microsoft?
Microsoft's filters are stricter on gambling, adult and financial verticals, and SNDS is the reference dataset. JMRP is essential.
What is different about sending to Yahoo?
Yahoo's response codes carry particularly rich diagnostic information; a well-classified bounce processor extracts a lot from them.
What is different about sending to Apple iCloud?
Apple has become stricter with authentication in recent years. DMARC alignment is close to mandatory.
How do corporate O365 tenants differ from consumer Outlook?
Corporate O365 layers a per-tenant filter on top of the standard Microsoft filter. Placement varies per tenant based on their policies.
Support & operations
What are your support hours?
Business hours by default; 24/7 on-call for retained clients on the managed tier.
What are your response times?
P1 — 15 minutes; P2 — 1 hour; P3 — next business day. Retained clients only.
Do we get a named engineer?
Yes on the managed and private-infrastructure tiers. Consulting engagements are staffed against the engagement scope.
Do you attend our internal reviews?
Yes, on retainer engagements where relevant.
How do we escalate a live incident?
Retained clients receive a private incident channel — Signal or Telegram — plus phone escalation. All incidents are triaged within the response-time SLA.
Security, compliance & abuse
Are you GDPR-compliant?
Northbound acts as a data processor for message metadata. A DPA is included with every engagement. See our GDPR page.
Do you have SOC 2 or ISO certifications?
Formal certification is not a fit for our operating scale. We provide a written security posture document on request and undergo client-driven audits as needed.
How do you handle abuse reports?
abuse@northboundmail.net is monitored by engineers. Reports are triaged and remediated per our AUP.
Do you cooperate with law enforcement?
Legal requests are handled through counsel. Where a legal request is compliant and enforceable, we respond within its scope.
How is data segregated between clients?
Clients on dedicated deployments are on isolated hosts and network segments. Shared infrastructure uses per-account credentials, per-account queues and per-account log stores.
Do you encrypt data at rest?
Yes — full-disk encryption on all hosts, plus per-secret encryption for credentials, keys and API tokens.