Email Compliance
Everyone's Fav Topic!
KiddinG! But also Important
 

TLDR;
Too Long Didn't Read
Google and Yahoo are updating their email requirements starting February. If you’re sending from a custom domain email, make sure you have DKIM records setup and verified. Bonus points for SPF and DMARC records. 

 
Hi First name / friend!
 
I’m popping into your inbox today with an important heads up (or reminder) that Google and Yahoo (likely among others) are tightening their email compliance requirements REALLY SOON (like February soon). What this means for you is to keep your email flowing smoothly, there are some important steps you’ll need to complete.
 
Before I dive further into this email, note that I am 100% NOT a super pro at this. After completing the processes myself, I felt like sharing some of my learnings might help make the process feel ever-so-slightly less daunting. I hope that's the case :-) 
 
Let's get into it shall we!
 
What is this compliance update? 
Major email providers are trying to improve email authentication and focused on 4 main updates to do this :
  1. If you send more than 5000 emails per day, you must send from a custom domain you own, not a free address (for example: I couldn't send from a “@gmail. com” address, it has to be “@ldotdesigns .com”).
  2. If you send more than 5000 emails per day, you must authenticate your custom domain email with DKIM, SPF, and DMARC records (more on this in a minute). If less than 5000 emails, it's still highly recommended. Note : if you’re using a free domain, your email can’t be authenticated.
  3. It must be easy to unsubscribe from your list. There are new requirements for this but most EMS are implementing these for you. Check your provider.
  4. Spam complaints must be under 0.3% and should be below 0.1% (this is when someone marks an email as SPAM NOT UNSUBSCRIBE)
What will happen if you don’t make this update?
If you send more than 5000 email at a time / in a day : your email deliverability will take a big hit and could eventually end up in your email being blacklisted.
 
If you send less than 5000 emails a day : then you’re probably going to be just fine for now. That said, most services are recommending you take action anyways and advising that you may see more emails marked as spam / undelivered if you don’t. 
Ok…So What the heck are SPF, DKIM, and DMARC records?
I feel like numbers 1, 3, and 4 above are pretty self explanatory while number 2 instantly gives WHAT IN THE JARGON feels. 
 
Before you start to panic sweat… know that the main purpose of these records is simply to verify whether an email is legitimate (and not coming from a sneaky scammer). Here's a breakdown of each to make it a bit more easy peasy:
 
*DKIM*
DKIM records act as a digital signature in your email header to let providers know the email is actually coming from you and not a spammer. *This one seems to be the most important for this compliance update.*
 
SPF
SPF records are like a permission slip stating that a sender is aloud to send email on your behalf (think your email account, EMS, LMS, CRM, CMS, etc.).
 
DMARC
DMARC records give instructions for what to do if an email received fails authentication. It also helps to prevent email spoofing which is when spammers send email that looks like it’s from your domain.
 
Abbreviations Mentioned Above :
DKIM = DomainKeys Identified Mail
SPF = Sender Policy Framework
DMARC = Domain-based Message Authentication, Reporting, and Conformance
 
EMS = Email Marketing System
LMS= Learning Management System
CRM = Client Relationship Management
CMS = Content Management System
 
Where do I find these records & how do I add them?
Where you'll find these records and how you'll verify them will change from platform to platform. In most cases it will look something like this:
  • These records / the verification process will live in the settings of the account you’re trying to verify (usually under an “email” topic).
  • Once you find them, login to your website domain host and navigate to your DNS settings.
  • You’ll then copy / paste the records from the account you’re trying to verify into your DNS settings.
  • Once they’ve all been added, you’ll go back to the account you’re verifying and click done (or whatever the button says).
If you’re unsure about how to get to these records in your provider OR how to access your DNS settings, I usually find google-ing it really helpful. Alternatively, both the platform you're trying to add as well as your domain host should be able to support you (Squarespace, GoDaddy, Namecheap, Bluehost etc.).  

Something Important I Learnt 
You can only have ONE DMARC and ONE SPF record but as many DKIM records as necessary. 
 
You shouldn’t need to add more than one DMARC record but if you need to add multiple SPF records, than you’ll need to merge the tags. This is WAY less scary than it sounds. I found this Dubsado help article really easy to follow.

 
Examples places to add records for
Again, this will look different for every person. Start by looking at any platforms that send or receive email on your behalf. Some examples could be:
  • Custom email provider such as Google Workspace
  • EMS : Mailchimp, Flodesk, CovertKit, etc.
  • CRM : Dubsado, Honeybook, etc.
If you’re unsure, a good place to start is in your custom DNS settings. It can be hard to decipher these but you might get some idea of which third party accounts are already linked to your domain but need further records added.
 
I have also found that most relevant companies have been sending emails to let you know. Some have even told me when I’ve not been up-to-date with compliance and given instructions on how to fix it. 
 

 
PHEW YOU MADE IT!
 
At the end of the day, this sounds SCARY and TRICKY but remember that’s just because it’s new :-) Don’t let this long email overwhelm you.
 
As I mentioned previously, if you need any support with this, your domain provider should be able to give it to you. In many instances, the service provider you’re trying to connect should also be able to help.
 
If you’d prefer my support, although I’m not a super pro at this, I'm happy to try. Reach out and we can try to figure it out together. My hourly rate is currently $50 CAD with a 1 hour minimum.
 
I know this one is a bit of a doozy and a bit dry. Give yourself a big pat on the back for making it through and hopefully you found some tidbit that was helpful. 
 
Sending you brave vibes as you dive into a bit of the scary feeling tech!
 
Image item
 
Lauren Fortier · ldotdesigns.com · @ldotdesigns
 

 
P.S. NEED SUPPORT? I’D LOVE TO HELP YOU OUT!
Here are some ways we can work together :
  • Mini Squarespace Website — for the DIY’er who wants to move to a more robust platform 
  • Fluid Engine Update — Move on up to Squarespace’s epic new builder.
  • Actionable Audits — Take your website to the next level with actionable feedback.
  • Get It Done VIP Design Days — Knocking things off your to-do list has never been easier.
  • Custom Squarespace Lessons — Get super cozy with DIY-ing website updates and more.
  • Custom Brand Design — Create a consistent look and feel with ease using fresh branding.
  • Custom Website — Say goodbye to DIY and hello to watching your new website come to life.
 

 
If Instagram is more your jam . . .
 
 
 
Instagram
Facebook
Pinterest