wtf( )unctionsystem design, drawn
← all problemsEmailMedium

One bad campaign, and the password resets stopped arriving

Everything sends under one name: password resets, receipts, and the monthly campaign to two hundred thousand addresses.

Receivers score reputation against the identity a message authenticated as. A campaign with a bad complaint rate spends standing that the password reset then does not have — and the reset is the one message a person is sitting there waiting for.

Separate the reputation of the mail you must deliver from the mail you merely want to deliver.
Components — tap one, then tap a slot on the diagram
!A campaign hit a spam-trap list. Password reset mail started landing in spam the same week.

Boundaries, outermost first: Same organisational domain: Policy at the parent (p= and sp=), an empty slot for the must not lose standing, an empty slot for the may spend its own Outside every boundary: The campaign (complaints happen), Password resets (must arrive), Receiver reputation (scored per domain; FAILED: one score, two streams) Connections: Password resets calls must not lose standing (step 1) The campaign calls may spend its own (step 2) must not lose standing calls Receiver reputation (step 3) may spend its own calls Receiver reputation — its own to spend (step 4) Policy at the parent controls must not lose standing Policy at the parent controls may spend its own — sp= decides this

The campaigncomplaints happen
Password resetsmust arrive
Receiver reputationscored per domainone score, two streams
Policy at the parentp= and sp=