PageSourceSearch

https://www.spamhaus.org/_nuxt/index.DFLsuMxc.js

js spamhaus.org collected 2026-09-24 06:37:03 UTC 52,197 bytes, 7 lines download raw bytes

1import{a1 as A,U as o,i as n,n as w,an as $,m as L,f as e,o as C,Z as E,d as _,aq as j,ao as K,D as P,ab as s,y as G,ag as W,g as O,h,a6 as g,F as D,$ as H,T as z,ah as V,P as X,R as Y,ak as Q,C as Z}from"./swiper-vue.CT7r2VF_.js";import{b as U,m as J,E as ee,C as te,A as se}from"./entry.C6NAXwym.js";const oe={},ae={class:"bg-[url('~/assets/img/resource-hub/bg-header.webp')] bg-no-repeat bg-cover bg-bottom pb-20"},ne=e("span",{class:"text-lg font-medium"},"Spamhaus Project’s mission is to strengthen trust and safety on the internet. To achieve this, we believe there should be a clear, simple set of guidelines that are consistently enforced and adhered to. These are the Spamhaus Sender Guidelines.",-1);function ie(k,v){const r=A("ShHeading"),p=A("ShGrid");return o(),n("section",ae,[w(p,{ySpace:"",narrow:"",class:"text-center"},{default:$(()=>[w(r,{size:"h1",class:"mb-5"},{default:$(()=>[L("Spamhaus Sender Guidelines")]),_:1}),ne]),_:1})])}const re=U(oe,[["render",ie]]),le={class:"bg-[url('~/assets/img/backgrounds/bg-check.webp')] bg-no-repeat bg-cover bg-bottom -mt-[10rem] pt-40 pb-24 text-white"},de=e("div",{class:"flex items-start gap-4 text-left bg-white border border-[rgba(238,194,22,0.3)] border-l-4 border-l-[#eec216] rounded-lg py-5 px-6 mt-2 mx-auto animate-[callout-in_0.4s_ease_both] [animation-delay:0.2s]"},[e("div",{class:"shrink-0 w-[1.375rem] h-[1.375rem] text-brand-blue mt-[0.15rem]"},[e("svg",{xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 24 24",fill:"none",stroke:"currentColor","stroke-width":"2.5","stroke-linecap":"round","stroke-linejoin":"round","aria-hidden":"true",class:"w-full h-full"},[e("path",{d:"M10.29 3.86L1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z"}),e("line",{x1:"12",y1:"9",x2:"12",y2:"13"}),e("line",{x1:"12",y1:"17",x2:"12.01",y2:"17"})])]),e("div",{class:"flex flex-col gap-[0.35rem]"},[e("span",{class:"text-[0.7rem] font-bold tracking-[0.12em] uppercase text-brand-blue"},"Note"),e("p",{class:"text-[0.9rem] leading-[1.65] text-brand-blue m-0 [&_strong]:text-brand-blue [&_strong]:font-semibold"},[L(" Spamhaus will be enforcing strict HELO — reverse DNS and A record checks from "),e("strong",null,"July 2026"),L(". Use the below HELO checker tool to check if your DNS passes the DNS best practices and follow the guidelines to avoid being listed. ")])])],-1),ce={class:"flex justify-center mt-4"},ue=e("p",{class:"font-bold text-white"},"Check your DNS setup",-1),he={class:"flex-1 w-full"},me={class:"relative"},pe=["disabled"],ge={key:1,class:"block w-4 h-4 border-2 border-white/30 border-t-white rounded-full animate-spin"},fe={key:0,class:"mt-1.5 text-xs text-red-400"},be={class:"bg-white rounded-2xl p-6 w-full max-w-3xl max-h-[80vh] flex flex-col relative"},ye={class:"text-lg font-semibold mb-4"},ve={class:"overflow-auto flex-1"},xe={key:0,class:"flex items-start gap-3 p-4 rounded-lg bg-red-50 border border-red-200"},we=e("svg",{xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 24 24",fill:"none",stroke:"currentColor","stroke-width":"2","stroke-linecap":"round","stroke-linejoin":"round",class:"shrink-0 w-5 h-5 text-red-500 mt-0.5","aria-hidden":"true"},[e("circle",{cx:"12",cy:"12",r:"10"}),e("line",{x1:"12",y1:"8",x2:"12",y2:"12"}),e("line",{x1:"12",y1:"16",x2:"12.01",y2:"16"})],-1),_e=e("p",{class:"text-sm font-semibold text-red-700"},"Check failed",-1),ke={class:"text-sm text-red-600 mt-0.5"},Se={key:0},Pe=e("p",{class:"text-lg font-bold mb-2"},"Most recently seen HELO values",-1),De={class:"w-full text-left divide-y divide-gray-200"},Ie=e("thead",null,[e("tr",null,[e("th",{class:"py-2 text-start text-xs font-medium text-gray-500 uppercase"}," Timestamp (UTC) +/- 5 minutes "),e("th",{class:"py-2 text-start text-xs font-medium text-gray-500 uppercase"}," HELO Value ")])],-1),Ee={class:"divide-y divide-gray-200"},He={class:"py-2 whitespace-nowrap text-sm font-medium text-gray-800"},Ae={class:"py-2 whitespace-nowrap text-sm font-medium text-gray-800"},Fe=e("p",{class:"mt-2 text-sm"},[L(" If the most recent HELOs above are unrecognised, please check for possible "),e("a",{class:"text-brand-yellow-6 font-semibold",target:"_blank",href:"https://www.spamhaus.org/faqs/residential-proxies/"},"compromise/malware"),L(". ")],-1),Ce={key:0,class:"my-4 border-brand-yellow bg-brand-yellow/30 rounded-r border-l-4 p-4"},Re=e("p",{class:"text-sm font-semibold"}," We are seeing multiple HELO values from this IP. This is typically seen with IPs having Malware issues or being abused by Residential PROXY services. Please check the above link and resolve the HELO issue before opening a ticket. ",-1),$e=[Re],Le={key:1},Oe=e("div",{class:"h-[1px] my-4 bg-grey-2 w-full"},null,-1),Te=e("p",{class:"text-lg mb-2 font-bold"},"PTR Record/HELO Check",-1),Me={class:"py-2 px-3 rounded bg-gray-100"},Ne={class:"flex justify-between items-center"},qe=e("div",{class:"w-1/4 whitespace-nowrap font-bold text-brand-blue"},"HELO",-1),je={class:"w-1/2 whitespace-nowrap text-sm font-medium text-gray-800"},Be={class:"w-1/4 whitespace-nowrap text-sm font-medium text-gray-800 flex justify-end gap-4 items-center"}
1,Ke={key:0,class:"text-xs font-medium mt-4 py-2 px-4 bg-signifiers-light-attention/10 rounded"},Ue={class:"text-sm font-bold text-signifiers-light-attention"},Ge={class:"flex justify-between py-1 mt-2"},We=e("div",{class:"font-medium"},"HELO",-1),ze={key:0,class:"flex justify-between py-1 border-t border-signifiers-light-attention/20"},Ve=e("div",{class:"font-medium"},"IPv4 Record",-1),Xe={class:"mt-4 py-2 px-3 rounded bg-gray-100"},Ye={class:"flex justify-between items-center"},Qe=e("div",{class:"w-1/4 whitespace-nowrap font-bold text-brand-blue"}," PTR for this IP ",-1),Ze={class:"w-1/2 whitespace-nowrap text-sm font-medium text-gray-800"},Je={class:"w-1/4 whitespace-nowrap text-sm font-medium text-gray-800 flex justify-end gap-4 items-center"},et={key:0,class:"text-xs font-medium mt-4 py-2 px-4 bg-signifiers-light-attention/10 rounded"},tt={class:"text-sm font-bold text-signifiers-light-attention"},st={key:0,class:"mt-4 py-2 px-3 rounded bg-gray-100"},ot={class:"flex justify-between items-center"},at=e("div",{class:"w-1/4 whitespace-nowrap font-bold text-brand-blue"}," PTR resolves to ",-1),nt={class:"w-1/2 whitespace-nowrap text-sm font-medium text-gray-800"},it={class:"w-1/4 whitespace-nowrap text-sm font-medium text-gray-800 flex justify-end gap-4 items-center"},rt={key:0,class:"text-xs font-medium mt-4 py-2 px-4 bg-signifiers-light-attention/10 rounded"},lt={class:"text-sm font-bold text-signifiers-light-attention"},dt={key:0,class:"flex justify-between py-1 mt-2"},ct=e("div",null,"A Record",-1),ut={key:1,class:"flex justify-between py-1 border-t border-signifiers-light-attention/20"},ht=e("div",null,"IPv4 Record",-1),mt={key:1,class:"text-xs font-medium mt-4 py-2 px-4 bg-signifiers-light-attention/10 rounded"},pt=e("div",{class:"text-sm font-bold text-signifiers-light-attention"}," The reverse DNS does not have an A record. Set an A record for the reverse DNS matching the sending IP address. ",-1),gt=[pt],ft={key:1},bt=e("div",{class:"h-[1px] my-4 bg-grey-2 w-full"},null,-1),yt=e("p",{class:"text-lg mb-2 font-bold"},"Resolution Steps",-1),vt=e("p",{class:"text-sm mb-2"}," Please align the mail server's HELO/EHLO and PTR with correct DNS (forward and reverse) values for a mail server. ",-1),xt=e("p",{class:"text-sm mb-4"},"Example of correct HELO/DNS/rDNS alignment:",-1),wt=e("table",{class:"w-full text-left"},[e("thead",{class:"sr-only"},[e("tr",null,[e("th",{class:"py-2 text-start text-xs font-medium text-gray-500 uppercase"}," Key "),e("th",{class:"py-2 text-start text-xs font-medium text-gray-500 uppercase"}," Value 1 "),e("th",{class:"py-2 text-start text-xs font-medium text-gray-500 uppercase"}," Value 2 ")])]),e("tbody",{class:"divide-y divide-gray-200"},[e("tr",null,[e("td",{class:"py-2 whitespace-nowrap text-sm font-semibold text-gray-800"}," HELO "),e("td",{class:"py-2 whitespace-nowrap text-sm font-medium text-gray-800"}," mail.example.com ")]),e("tr",null,[e("td",{class:"py-2 whitespace-nowrap text-sm font-semibold text-gray-800"}," IP address "),e("td",{class:"py-2 whitespace-nowrap text-sm font-medium text-gray-800"}," 192.0.2.12 ")]),e("tr",null,[e("td",{class:"py-2 whitespace-nowrap text-sm font-semibold text-gray-800"}," DNS (A) "),e("td",{class:"py-2 whitespace-nowrap text-sm font-medium text-gray-800"}," mail.example.com "),e("td",{class:"py-2 whitespace-nowrap text-sm font-medium text-gray-800"}," 192.0.2.12 ")]),e("tr",null,[e("td",{class:"py-2 whitespace-nowrap text-sm font-semibold text-gray-800"}," DNS (PTR) "),e("td",{class:"py-2 whitespace-nowrap text-sm font-medium text-gray-800"}," 192.0.2.12 "),e("td",{class:"py-2 whitespace-nowrap text-sm font-medium text-gray-800"}," mail.example.com ")])])],-1),_t=e("div",{class:"my-4 border-brand-yellow bg-brand-yellow/30 rounded-r border-l-4 p-4"},[e("p",{class:"text-sm font-semibold"}," If this is a shared hosting IP address, please contact your hosting provider and ask them to open a support request. ")],-1),kt=[bt,yt,vt,xt,wt,_t],St=C({__name:"index",props:{introText:{},rfcReference:{},sections:{}},setup(k){const v=ee(),r=E(""),p=E(!1),m=E(!1),t=E(null),f=E(null),l=E([]),b=_(()=>{const i=r.value.trim();if(!i)return!0;const d=/^((25[0-5]|2[0-4]\d|[01]?\d\d?)\.){3}(25[0-5]|2[0-4]\d|[01]?\d\d?)$/,x=/^(([0-9a-fA-F]{1,4}:){7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|::(ffff(:0{1,4})?:)?((25[0-5]|(2[0-4]|1?\d)?\d)\.){3}(25[0-5]|(2[0-4]|1?\d)?\d)|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1?\d)?\d)\.){3}(25[0-5]|(2[0-4]|1?\d)?\d))$/;return d.test(i)||x.test(i)}),y=_(()=>l.value),S=_(()=>!y.value||y.value.length<2?!1:y.value[0].helo!==y.value[1].helo),R=_(()=>{var d,x;if(!t.value)return!0;const i=t.value;return i&&i.helo_ptr_match&&((d=i.helo_validation)==null?void 0:d.ipv4_records[0])===r.value&&((x=i.ptr_resolutions)==null?void 0:x.length)&&i.ptr_resolutions[0].ipv4_records[0]===r.value}),a=async i=>((await $fetch(`${v.public.CHECKER_API_URL}
1helo-history`,{method:"POST",body:{query:i,list:"css"}})).helos??[]).slice(0,5),u=async()=>{if(r.value.trim()){p.value=!0,f.value=null,t.value=null,l.value=[];try{const[i,d]=await Promise.all([$fetch(`${v.public.CHECKER_API_URL}helo-ptr`,{method:"POST",body:{query:r.value.trim()}}),a(r.value.trim())]);t.value=i,l.value=d}catch(i){const d=i&&typeof i=="object"&&"data"in i?i.data:null;d&&typeof d=="object"&&"message"in d?f.value=d.message:f.value=i instanceof Error?i.message:"An error occurred. Please try again."}finally{p.value=!1,m.value=!0}}};return(i,d)=>{var I,M,N,q;const x=A("ShIcon"),c=A("ShGrid");return o(),n("section",le,[w(c,{ySpace:"",narrow:"",class:"text-center"},{default:$(()=>[de,e("div",ce,[e("form",{class:"flex flex-col medium:items-center gap-3 text-left mt-4 mx-auto w-full animate-[callout-in_0.4s_ease_both] [animation-delay:0.35s]",onSubmit:j(u,["prevent"])},[ue,e("div",he,[e("div",me,[K(e("input",{"onUpdate:modelValue":d[0]||(d[0]=F=>G(r)?r.value=F:null),type:"text",placeholder:"Enter an IP address to check its HELO/DNS setup",class:P(["py-2 border-2 rounded appearance-none outline-none w-full px-3 bg-brand-blue-3 placeholder:text-grey-5 text-white border-brand-blue-1 hover:border-white focus:border-brand-yellow",s(b)?"border-white/25 focus:border-[#eec216]":"border-red-400 focus:border-red-400"])},null,2),[[W,s(r)]]),e("button",{type:"submit",disabled:s(p)||!s(r).trim()||!s(b),class:"absolute right-2.5 top-1/2 -translate-y-1/2 text-white/50 hover:text-white disabled:opacity-30 transition-opacity","aria-label":"Check DNS setup"},[s(p)?(o(),n("span",ge)):(o(),O(x,{key:0,icon:"search",color:"white"}))],8,pe)]),s(b)?h("",!0):(o(),n("p",fe," Please enter a valid IPv4 or IPv6 address. "))])],32)])]),_:1}),(o(),O(z,{to:"body"},[s(m)?(o(),n("div",{key:0,class:"fixed inset-0 bg-black/80 z-[210] flex items-center justify-center p-4",onClick:d[2]||(d[2]=j(F=>m.value=!1,["self"]))},[e("div",be,[e("button",{class:"absolute top-3 right-3 text-brand-yellow hover:opacity-70 transition-opacity","aria-label":"Close",onClick:d[1]||(d[1]=F=>m.value=!1)},[w(x,{icon:"close",color:"black"})]),e("h3",ye,"DNS Setup Check — "+g(s(r)),1),e("div",ve,[s(f)?(o(),n("div",xe,[we,e("div",null,[_e,e("p",ke,g(s(f)),1)])])):h("",!0),s(t)?(o(),n(D,{key:1},[s(y).length?(o(),n("div",Se,[Pe,e("table",De,[Ie,e("tbody",Ee,[(o(!0),n(D,null,H(s(y),F=>(o(),n("tr",{key:F.timestamp},[e("td",He,g(s(J)(F.timestamp*1e3,"yyyy-MM-dd HH:mm:ss")),1),e("td",Ae,g(F.helo),1)]))),128))])]),Fe,s(S)?(o(),n("div",Ce,$e)):h("",!0)])):h("",!0),s(S)?h("",!0):(o(),n("div",Le,[Oe,Te,e("div",Me,[e("div",Ne,[qe,e("div",je,g(s(t).helo_validation.helo),1),e("div",Be,g(s(t).helo_validation.ipv4_records.length&&s(t).helo_validation.ipv4_records[0]===s(r)?"✅":"❌"),1)]),!s(t).helo_validation.ipv4_records||s(t).helo_validation.ipv4_records[0]!==s(r)?(o(),n("div",Ke,[e("div",Ue,g(s(t).helo_validation.error?s(t).helo_validation.error.includes("not a valid domain")?`The HELO value - ${s(t).helo_validation.helo} is not valid. Please set a valid Fully qualified domain name (FQDN) as the HELO value.`:"The HELO does not resolve in public DNS to the sending IP address.":"The A record for the HELO domain does not match the sending IP address."),1),e("div",Ge,[We,e("div",null,g(s(t).helo_validation.helo),1)]),s(t).helo_validation.ipv4_records.length?(o(),n("div",ze,[Ve,e("div",{class:P({"text-signifiers-light-attention font-bold":s(t).helo_validation.ipv4_records[0]!==s(r),"text-green-700":s(t).helo_validation.ipv4_records[0]===s(r)})},g(s(t).helo_validation.ipv4_records[0]),3)])):h("",!0)])):h("",!0)]),e("div",Xe,[e("div",Ye,[Qe,e("div",Ze,g(s(t).ptr_validation.ptr_records[0]??"N/A"),1),e("div",Je,g(s(t).helo_ptr_match?"✅":s(t).ptr_validation.ptr_records.length&&s(t).ptr_validation.ptr_records[0]!==""?"❓":"❌"),1)]),s(t).helo_ptr_match?h("",!0):(o(),n("div",et,[e("div",tt,g(s(t).ptr_validation.ptr_records.length&&s(t).ptr_validation.ptr_records[0]!==""?"The reverse DNS domain does not match the HELO domain.":"The reverse DNS does not exist. Set a reverse DNS that matches the HELO domain."),1)]))]),s(t).ptr_validation.ptr_records.length&&s(t).ptr_validation.ptr_records[0]!==""?(o(),n("div",st,[e("div",ot,[at,e("div",nt,g((I=s(t).ptr_resolutions)!=null&&I.length?s(t).ptr_resolutions[0].ipv4_records[0]:"N/A"),1),e("div",it,g((M=s(t).ptr_resolutions)!=null&&M.length&&s(t).ptr_resolutions[0].ipv4_records[0]===s(r)?"✅":"❌"),1)]),(N=s(t).ptr_resolutions)!=null&&N.length&&s(t).ptr_resolutions[0].ipv4_records[0]!==s(r)?(o(),n("div",rt,[e
1("div",lt,g(s(t).ptr_resolutions[0].ptr_record!==""?"The reverse DNS does not resolve to the sending IP address. We recommend setting an A record for the domain matching the sending IP address.":"The reverse DNS does not have an A record. Set an A record for the reverse DNS matching the sending IP address."),1),s(t).ptr_resolutions[0].ptr_record!==""?(o(),n("div",dt,[ct,e("div",null,g(s(t).ptr_resolutions[0].ptr_record),1)])):h("",!0),s(t).ptr_resolutions[0].ipv4_records.length?(o(),n("div",ut,[ht,e("div",{class:P({"text-red-800 font-bold":s(t).ptr_resolutions[0].ipv4_records[0]!==s(r)})},g(s(t).ptr_resolutions[0].ipv4_records[0]),3)])):h("",!0)])):h("",!0),(q=s(t).ptr_resolutions)!=null&&q.length?h("",!0):(o(),n("div",mt,gt))])):h("",!0),s(R)?h("",!0):(o(),n("div",ft,kt))]))],64)):h("",!0)])])])):h("",!0)]))])}}}),Pt={class:"large:block mobile:hidden w-[210px] shrink-0 sticky top-[104px] self-start"},Dt=e("span",{class:"uppercase font-bold text-xs mb-3 block text-brand-blue"}," Sections ",-1),It=["onClick"],Et=["onClick"],Ht={class:"large:hidden mobile:block w-full"},At=["value"],Ft=["value"],Ct=C({__name:"index",props:{items:{},activeHash:{},activeSubHash:{},openSubs:{default:()=>new Set}},emits:["navigate"],setup(k,{emit:v}){const r=k,p=v,m=_(()=>{var t;return((t=r.items.find(f=>f.hash===r.activeHash))==null?void 0:t.subcategories)??[]});return(t,f)=>(o(),n(D,null,[e("div",Pt,[Dt,(o(!0),n(D,null,H(t.items,l=>(o(),n("div",{key:l.hash},[e("button",{"data-testid":"section-btn",class:P(["w-full text-left px-3 py-[6.5px] text-[12.5px] border-l-4 transition-colors duration-150 mb-1",l.hash===t.activeHash?"bg-blue-lagoon text-white font-semibold  border-brand-blue":"text-brand-blue font-medium hover:bg-[#f0f0f0] border-brand-yellow"]),onClick:b=>p("navigate",l.hash)},g(l.heading),11,It),l.hash===t.activeHash&&m.value.length?(o(!0),n(D,{key:0},H(m.value,b=>(o(),n("button",{key:b.hash,"data-testid":"sub-btn",class:P(["w-full text-left pl-5 pr-3 py-1 text-[11.5px] transition-colors duration-150 mb-0.5 border-l-2",b.hash===t.activeSubHash&&t.openSubs.has(b.hash)?"bg-blue-lagoon/10 text-brand-blue font-semibold border-blue-lagoon":"text-brand-blue hover:bg-[#f0f0f0]  border-brand-yellow"]),onClick:y=>p("navigate",b.hash)},g(b.heading),11,Et))),128)):h("",!0)]))),128))]),e("div",Ht,[e("select",{"data-testid":"mobile-select",class:"w-full border border-gray-300 rounded px-3 py-2 text-sm",style:{color:"#1a2740"},value:t.activeHash,onChange:f[0]||(f[0]=l=>p("navigate",l.target.value))},[(o(!0),n(D,null,H(t.items,l=>(o(),n("option",{key:l.hash,value:l.hash},g(l.heading),9,Ft))),128))],40,At)])],64))}}),Rt={key:0,class:"flex items-center gap-1.5 px-4 py-3 text-[#5EEAD4]"},$t=e("i",{class:"fi fi-ss-check text-xs"},null,-1),Lt=e("span",{class:"text-xs font-bold uppercase tracking-wider"},"Do",-1),Ot=[$t,Lt],Tt=e("i",{class:"fi fi-ss-cross text-xs"},null,-1),Mt=e("span",{class:"text-xs font-bold uppercase tracking-wider"},"Don't",-1),Nt=[Tt,Mt],qt=e("div",{class:"flex items-center gap-1 text-blue-lagoon large:hidden"},[e("i",{class:"fi fi-ss-check-circle text-base"}),e("p",{class:"text-xs font-bold uppercase tracking-wider"}
1,"Do")],-1),jt={class:"blocklist-explanation"},Bt={class:"marker:text-blue-lagoon"},Kt={key:1,class:"p-4 flex flex-col gap-2 bg-[#FFF5F5]"},Ut=e("div",{class:"flex items-center gap-1 text-red-800 large:hidden"},[e("i",{class:"fi fi-ss-cross-circle text-base"}),e("p",{class:"text-xs font-bold uppercase tracking-wider"},"Don't")],-1),Gt={class:"blocklist-explanation"},Wt={class:"marker:text-red-800"},zt={key:2,"data-testid":"row-footer",class:"px-4 py-2 bg-white border-t border-gray-200 text-gray-700 large:col-span-2 blocklist-explanation"},Vt=C({__name:"table",props:{group:{},hasBorder:{type:Boolean}},setup(k){const v=k,r=_(()=>{var t;return!!((t=v.group.dos)!=null&&t.length)}),p=_(()=>{var t;return!!((t=v.group.donts)!=null&&t.length)}),m=_(()=>r.value&&p.value);return(t,f)=>{const l=A("ShMarkdown");return o(),n("div",{class:P(["overflow-hidden",{"border border-gray-200 rounded-md":v.hasBorder}])},[r.value||p.value?(o(),n("div",{key:0,"data-testid":"table-header",class:P(["hidden large:grid bg-[#1a2740]",m.value?"large:grid-cols-2":"large:grid-cols-1"])},[r.value?(o(),n("div",Rt,Ot)):h("",!0),p.value?(o(),n("div",{key:1,class:P(["flex items-center gap-1.5 px-4 py-3 text-[#FCA5A5]",{"border-l border-white/10":m.value}])},Nt,2)):h("",!0)],2)):h("",!0),e("div",{class:P(["flex flex-col large:grid",m.value?"large:grid-cols-2":"large:grid-cols-1"])},[r.value?(o(),n("div",{key:0,class:P(["p-4 flex flex-col gap-2 bg-[#F0FAF9]",{"large:border-r border-gray-200":m.value}])},[qt,e("div",jt,[e("ul",Bt,[(o(!0),n(D,null,H(t.group.dos,(b,y)=>(o(),n("li",{key:y,class:"mb-2 last:mb-0","data-testid":"do-item"},[w(l,{content:b.text,class:"text-sm leading-relaxed",style:{color:"#1a2740"}},null,8,["content"])]))),128))])])],2)):h("",!0),p.value?(o(),n("div",Kt,[Ut,e("div",Gt,[e("ul",Wt,[(o(!0),n(D,null,H(t.group.donts,(b,y)=>(o(),n("li",{key:y,class:"mb-2 last:mb-0","data-testid":"dont-item"},[w(l,{content:b.text,class:"text-sm leading-relaxed",style:{color:"#1a2740"}},null,8,["content"])]))),128))])])])):h("",!0),t.group.footer_text?(o(),n("div",zt,[w(l,{content:t.group.footer_text,class:"text-xs leading-relaxed"},null,8,["content"])])):h("",!0)],2)],2)}}}),T=k=>k.trim().toLowerCase().replace(/[^a-z0-9]+/g,"-").replace(/(^-|-$)/g,""),Xt=["id"],Yt={class:"text-xl font-bold",style:{color:"#1a2740"}},Qt={key:0,class:"text-sm leading-relaxed mt-2 blocklist-explanation text-grey-8"},Zt={key:1,"data-testid":"key-requirements",class:"mt-6 rounded-md border border-[#d7e3e2] border-l-4 border-l-[#00858b] bg-[#F0FAF9] px-5 py-4"},Jt=e("div",{class:"mb-3 flex items-center gap-2 text-xs font-extrabold uppercase tracking-wider text-[#00636b]"},[e("i",{class:"fi fi-ss-check text-xs"}),e("span",null,"Key Requirements")],-1),es={class:"flex flex-col gap-2.5"},ts={class:"font-bold",style:{color:"#1a2740"}},ss={style:{color:"#5b6472"}},os={key:2,class:"mt-6 flex justify-end"},as={key:3,class:"mt-2 flex flex-col gap-2.5"},ns=["id"],is=["aria-expanded","aria-controls","onClick"],rs={class:"text-[13px] font-bold uppercase tracking-wide",style:{color:"#1a2740"}},ls=["id"],ds={key:4,class:"mt-6 flex flex-col gap-6"},cs=C({__name:"section",props:{section:{},openSubs:{}},emits:["toggleSub","toggleAll"],setup(k,{emit:v}){const r=k,p=v,m=_(()=>T(r.section.title)),t=a=>`${m.value}--${T(a)}`,f=_(()=>(r.section.groups??[]).filter(a=>a.subcategory)),l=_(()=>(r.section.groups??[]).filter(a=>!a.subcategory)),b=_(()=>f.value.map(a=>t(a.subcategory))),y=_(()=>b.value.length>0&&b.value.every(a=>r.openSubs.has(a))),S=a=>r.openSubs.has(t(a)),R=()=>p("toggleAll",b.value,!y.value);return(a,u)=>{var x;const i=A("ShMarkdown"),d=Vt;return o(),n("div",{id:m.value,class:"scroll-mt-28"},[e("h2",Yt,g(a.section.title),1),a.section.description?(o(),n("div",Qt,[w(i,{content:a.section.description},null,8,["content"])])):h("",!0),(x=a.section.keyRequirements)!=null&&x.length?(o(),n("div",Zt,[Jt,e("ul",es,[(o(!0),n(D,null,H(a.section.keyRequirements,(c,I)=>(o(),n("li",{key:I,"data-testid":"key-req",class:"text-sm leading-relaxed"},[e("span",ts,g(c.term),1),e("span",ss," — "+g(c.definition),1)]))),128))])])):h("",!0),f.value.length?(o(),n("div",os,[e("button",{type:"button","data-testid":"expand-all",class:"text-xs font-semibold text-[#00858b] hover:underline",onClick:R},g(y.value?"Collapse all":"Expand all"),1)])):h("",!0),f.value.length?(o(),n("div",as,[(o(!0),n(D,null,H(f.value,c=>(o(),n("div",{key:c.subcategory,id:t(c.subcategory),"data-testid":"subsection",class:"scroll-mt-28 overflow-hidden rounded-md border border-gray-200"},[e("button",{type:"button","data-testid":"subsection-header",class:P(["flex w-full items-center justify-between px-4 py-3 transition-colors",S(c.subcategory)?"bg-[#eef6f6]":"bg-[#f4f6f8] hover:bg-[#eef1f4]"]),"aria-expanded":S(c.subcategory)?"true":"false","aria-controls":`${t(c.subcategory)}
1--panel`,onClick:I=>p("toggleSub",t(c.subcategory))},[e("span",rs,g(c.subcategory),1),e("div",{class:P(["size-4 flex items-center justify-center transition-transform",{"rotate-180":S(c.subcategory)}])},[e("i",{class:P(["fi fi-ss-angle-small-down text-base transition-colors size-4 -mt-0.5",S(c.subcategory)?" text-[#00858b]":"text-[#8a94a6]"]),"aria-hidden":"true"},null,2)],2)],10,is),K(e("div",{id:`${t(c.subcategory)}--panel`,"data-testid":"subsection-panel"},[w(d,{group:c},null,8,["group"])],8,ls),[[V,S(c.subcategory)]])],8,ns))),128))])):h("",!0),l.value.length?(o(),n("div",ds,[(o(!0),n(D,null,H(l.value,(c,I)=>(o(),O(d,{key:`plain-${I}`,group:c,hasBorder:""},null,8,["group"]))),128))])):h("",!0)],8,Xt)}}}),us={class:"pb-32"},hs={class:"flex large:flex-row mobile:flex-col gap-6"},ms={class:"flex flex-col flex-1 min-w-0"},ps={key:0,class:"my-12"},B=200,gs=C({__name:"index",props:{sections:{}},setup(k){const v=k,r=te(),p=_(()=>v.sections.map(a=>{const u=T(a.title);return{heading:a.title,hash:u,subcategories:(a.groups??[]).filter(i=>i.subcategory).map(i=>({heading:i.subcategory,hash:`${u}--${T(i.subcategory)}`}))}})),m=E(v.sections.length?p.value[0].hash:""),t=E(""),f=E(null),l=E(new Set),b=a=>{const u=new Set(l.value);u.has(a)?u.delete(a):u.add(a),l.value=u},y=(a,u)=>{const i=new Set(l.value);a.forEach(d=>u?i.add(d):i.delete(d)),l.value=i},S=()=>{if(f.value)return;for(const u of p.value){const i=document.getElementById(u.hash);if(!i)continue;const d=i.getBoundingClientRect();if(d.top>=0&&d.top<B){if(u.hash!==m.value){m.value=u.hash;const x=window.location.toString().split("#")[0];history.replaceState(null,"",`${x}#${u.hash}`)}break}}const a=p.value.find(u=>u.hash===m.value);if(a!=null&&a.subcategories.length){let u=a.subcategories[0].hash;for(const i of a.subcategories){const d=document.getElementById(i.hash);d&&d.getBoundingClientRect().top<B&&(u=i.hash)}t.value=u}else t.value=""},R=a=>{var x;const u=a.includes("--"),i=u?a.split("--")[0]:a;if(m.value=i,f.value=a,u){t.value=a;const c=new Set([...l.value].filter(I=>!I.startsWith(`${i}--`)));c.add(a),l.value=c}else{const c=p.value.find(I=>I.hash===i);t.value=((x=c==null?void 0:c.subcategories[0])==null?void 0:x.hash)??""}const d=window.location.toString().split("#")[0];history.replaceState(null,"",`${d}#${a}`),Z(()=>{var c;(c=document.getElementById(a))==null||c.scrollIntoView({behavior:"smooth"})})};return X(()=>{const a=r.hash.replace("#","");if(a)if(a.includes("--")){const u=a.split("--")[0];if(p.value.some(i=>i.hash===u)){m.value=u,t.value=a;const i=new Set(l.value);i.add(a),l.value=i}}else p.value.some(u=>u.hash===a)&&(m.value=a);document.addEventListener("scroll",S)}),Y(()=>document.removeEventListener("scroll",S)),Q(f,a=>{a!==null&&setTimeout(()=>{f.value=null},500)}),(a,u)=>{const i=Ct,d=cs,x=A("ShGrid");return o(),n("section",us,[w(x,{ySpace:""},{default:$(()=>[e("div",hs,[w(i,{items:s(p),"active-hash":s(m),"active-sub-hash":s(t),"open-subs":s(l),onNavigate:R},null,8,["items","active-hash","active-sub-hash","open-subs"]),e("div",ms,[(o(!0),n(D,null,H(a.sections,c=>(o(),n("div",{key:c.title},[w(d,{section:c,"open-subs":s(l),onToggleSub:b,onToggleAll:y},null,8,["section","open-subs"]),c!==a.sections[a.sections.length-1]?(o(),n("hr",ps)):h("",!0)]))),128))])])]),_:1})])}}}),fs={},bs={class:"bg-[url('~/assets/img/backgrounds/bg-grunge-torn.webp')] bg-no-repeat bg-cover bg-top pt-[7rem] mt-[-8rem] pb-16"},ys=e("div",{class:"text-white text-center"},[e("h2",{class:"text-2xl font-bold mb-6"},"Spamhaus Tools & Resources"),e("div",{class:"grid grid-cols-1 medium:grid-cols-2 gap-4 mx-auto"},[e("a",{href:"/ip-reputation/",class:"flex items-center text-center rounded-lg gap-3 bg-gradient-to-t from-gradient-yellow-dark to-gradient-yellow-light border border-white/20 hover:border-[#eec216]/60 px-3 py-5 transition-all group"},[e("div",{class:"flex-1 min-w-0"},[e("div",{class:"text-lg font-bold text-brand-blue"},"IP Reputation"),e("div",{class:"text-brand-blue mt-0.5"},"Check if an IP is listed")]),e("svg",{xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 24 24",fill:"none",stroke:"currentColor","stroke-width":"2","stroke-linecap":"round","stroke-linejoin":"round",class:"w-4 h-4 text-white/30 group-hover:text-[#eec216] transition-colors flex-shrink-0","aria-hidden":"true"},[e("path",{d:"M9 18l6-6-6-6"})])]),e("a",{href:"/domain-reputation/",class:"flex items-center text-center rounded-lg gap-3 bg-gradient-to-t from-gradient-yellow-dark to-gradient-yellow-light border border-white/20 hover:border-[#eec216]/60 px-3 py-5 transition-all group"},[e("div",{class:"flex-1 min-w-0"},[e("div",{class:"text-lg font-bold text-brand-blue"},"Domain Reputation"),e("div",{class:"text-brand-blue mt-0.5"},"Check if a domain is listed")]),e("svg",{xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 24 24",fill:"none",stroke:"currentColor","stroke-width":"2","stroke-linecap":"round","stroke-linejoin":"round",class:"w-4 h-4 text-white/30 group-hover:text-[#eec216] transition-colors flex-shrink-0","aria-hidden":"true"},[e("path",{d:"M9 18l6-6-6-6"})])])])],-1);
1function vs(k,v){const r=A("ShGrid");return o(),n("section",bs,[w(r,{narrow:"",ySpace:""},{default:$(()=>[ys]),_:1})])}const xs=U(fs,[["render",vs]]),ws={intro_text:"Spamhaus Project's mission is to strengthen trust and safety on the internet. To achieve this, we believe there should be a clear, simple set of guidelines that are consistently enforced and adhered to. These are the Spamhaus Sender Guidelines.",rfc_reference:"Defined in accordance with RFC 5321 and RFC 5322, these guidelines apply to anyone sending email at scale.",sections:[{title:"1. Infrastructure and DNS",description:"All sending infrastructure must have the following DNS and mailserver configuration in place. Failure to do so will result in IPs being listed on the Combined SpamSources (CSS), Exploits Blocklist (XBL), or Policy Blocklist (PBL).",keyRequirements:[{term:"Reverse DNS (rDNS) and FCrDNS",definition:"All sending IP address should have a valid reverse DNS (PTR) record. Spamhaus also requires the IP is configured to have FCrDNS (Forward-Confirmed reverse DNS)."},{term:"HELO/EHLO",definition:"The HELO/EHLO hostname is the domain name a sending server presents during the SMTP handshake, and this must resolve to the sending IP address. Multiple HELO values resolving to different IPs are treated as an indicator of proxy or malware behaviour, and can trigger additional scrutiny."},{term:"IPv6 allocation",definition:"IPv6 allocation size determines how much address space is assigned to an individual sending customer. Per RFC 4291 and RFC 6177, Spamhaus expects a minimum /64 allocation with a valid rDNS entry, in line with industry standard."}
1,{term:"Envelope/Header FROM domain",definition:"The Header FROM domain identifies the sender in the message header, and must have a correctly configured SPF record pointing to your infrastructure."}],groups:[{subcategory:"Reverse DNS (rDNS)",dos:[{text:"Ensure the sending IP address has a valid **reverse DNS (rDNS)** entry resolving to a fully qualified domain name (FQDN) for the sending IP address. Spamhaus will treat emails originating from IP addresses without rDNS as suspicious and will be subject to additional filtering."},{text:"Ensure the rDNS hostname resolves back to the connecting IP address via a corresponding **forward DNS (A) record**."}],donts:[{text:"**Do not** use generic or auto-generated rDNS entries for static IPs that point to your hosting (e.g., static-ip.hosting.com, ip-fixed.ISP.com etc). These can negatively impact your reputation."}],footer_text:"Abusive actors often rely on the reputation of upstream DNS records to hide their identity. Instead, configure a branded reverse DNS that reflects your own domain, to improve trust signals for the IP address."},{subcategory:"HELO/EHLO",dos:[{text:"Ensure the hostname used in the **HELO/EHLO** command resolves to the sending IP address."},{text:"Where possible, ensure the HELO/EHLO hostname is consistent with the rDNS hostname. *(recommended)* Maintain a consistent HELO value that resolves to the sending IP address. Multiple HELO values resolving to different IP addresses may indicate residential proxy and/or malware behaviour."},{text:"Add routes for all IP space you own to reduce vulnerability to [BGP hijacking](https://www.spamhaus.org/resource-hub/network-security/fighting-abuse-at-the-edge/#how-do-bad-guys-acquire-control-of-ip-address-ranges), which can allow hackers to send email that appears to originate from your IP space."},{text:"Ensure **IPv6** allocations are a minimum of /64, inline with the industry standard for the smallest IPv6 allocation to individual customers and have a valid rDNS. This includes home-uses such as cable, DSL or wireless. This requirement originates from RFC4291 and is further discussed in RFC6177 and [M3AAWG best practices](https://www.m3aawg.org/sites/default/files/document/M3AAWG_Inbound_IPv6_Policy_Issues-2014-09.pdf)."},{text:"We recommend the domain used in HELO/EHLO has a public web page or a redirect to the owner domain, to signify who the owner is."}],donts:[{text:'**Do not** use placeholder values such as "localhost" or generic hostnames that point to your hosting company/ISP as the HELO value.'},{text:"**Do not** resolve HELO hostname to infrastructure owned by a different provider — this behaviour is associated with spoofing and misconfiguration."},{text:"**Do not** impersonate the HELO value of well-known mailbox providers like Gmail or Hotmail."},{text:"**Do not** use generic or auto-generated names provided by your hosting provider, use your own domain where possible."}]},{subcategory:"From Domain (Envelope/Header FROM)",dos:[{text:"Make sure SPF is set up correctly for the domain you use in the envelope sender, and points to your infrastructure. Do not use envelope From domains from others. Use SRS if necessary to rewrite from address when forwarding."},{text:"We recommend the domain used in FROM/HELO/rDNS has a public page or redirects to a page where one can check for any available information."}],donts:[{text:"**Do not** allow freemail addresses such as gmail.com or hotmail.com as your 'Header FROM.'"},{text:"**Do not** use the NULL envelope sender `<>` for anything other than indirect out-of-bound delivery reports."},{text:'**Do not** send bounces when rejecting email, especially if the reason for rejection is "spam", or when SPF on the incoming message does not validate. Instead, reject the message after the DATA phase of the SMTP transaction. Sending bounces means you are likely sending indirect spam and can severely harm your reputation.'}],footer_text:"This [article](https://www.wordtothewise.com/2024/07/sending-domains-and-hostnames/) explains sender authentication terminology and hostname alignment in email."}]},{title:"2. Permission and List Hygiene",description:"Send email to people who want to re
1ceive it — once the technical infrastructure is in place, the next step is to have a legitimate list of email addresses who have provided explicit permission to receive the email. Lack of permission is one of the underlying reasons for being listed at Spamhaus.",keyRequirements:[{term:"Confirmed Opt-In (COI)",definition:"This is a permission practice where a recipient must explicitly confirm their subscription, usually by clicking a link in a verification email, before being added to a mailing list. Spamhaus requires all bulk email to be sent only to COI recipients, as this prevents bot signups, typo addresses, and unwanted subscriptions from entering the list."},{term:"Spam trap",definition:"An email address with no legitimate owner, used to identify senders with poor list acquisition or hygiene practices. Hitting a spam trap is treated as a strong negative signal, since it indicates the list was purchased, harvested, or not properly maintained."}],groups:[{subcategory:"Permission",dos:[{text:"Ensure all bulk email is ONLY sent to recipients that have [**Confirmed Opted In (COI)**](https://www.spamhaus.org/resource-hub/deliverability/confirmed-opt-in-or-opt-out/). Send a confirmation email asking recipients to explicitly opt-in to verify their email address."},{text:"Utilise available signals like bounce data, feedback loop, postmaster tools and engagement data to ensure your mailing list is up to date and email is sent to an engaged audience."},{text:"Implement a robust [email sunset policy](https://www.spamhaus.org/resource-hub/deliverability/what-is-an-email-sunset-policy-and-why-do-you-need-one/) to help remove temporary email sign-ups and email addresses that no longer exist."},{text:"Keep a timestamped record of when and how permission was obtained."}],donts:[{text:"Permission is NOT transferable. **Do not** grant or assume permission retrospectively or transfer it between organisations or domains."},{text:"**Do not** send emails to purchased, rented, or harvested lists, as these are the most common source of spam trap hits."},{text:"**Do not** continue sending to addresses that are not engaged with your emails."}]},{subcategory:"Spam traps",dos:[{text:"Audit your acquisition process to identify which list segment or collection method introduced the problematic address, and remove that source entirely."},{text:"Refer to the [guidelines from M3AAWG](https://www.m3aawg.org/sites/default/files/doc_files/help_i_hit_a_spam_trap.pdf) for managing spam traps, and follow the best practices outlined in our [resources](https://www.spamhaus.com/resource-center/spamtraps-fix-the-problem-not-the-symptom/)."}],donts:[{text:"**Do not** attempt to identify or suppress a spam trap address. Audit your acquisition process to identify which list segment or collection method introduced the problem address, and remove that source entirely."}]}]},{title:"3. Authentication",description:"Authentication is how receiving mail servers verify that your emails are legitimate. Without SPF, DKIM, and DMARC properly configured, your domain is exposed to spoofing and phishing and your emails are more likely to be rejected or flagged by Spamhaus.",keyRequirements:[{term:"SPF (Sender Policy Framework)",definition:"A DNS TXT record that specifies which IPs and hosts are authorised to send email on behalf of a domain. Spamhaus requires a valid SPF record on both the HELO domain and the envelope From domain, and treats mail from IPs not listed in SPF as a failed authentication check."},{term:"DKIM (DomainKeys Identified Mail)",definition:"A cryptographic signature added to an outbound message that allows a receiving server to verify the message wasn't altered in transit and is associated with the signing domain. Spamhaus expects every outbound message to carry a valid DKIM signature, with the signing (d=) domain matching the header From domain."},{term:"DMARC (Domain-based Message Authentication, Reporting & Conformance)",definition:"A DNS policy record that tells a receiving server what to do with a message that fails SPF or DKIM alignment, and enables reporting on messages sent using the domain. Spamhaus expects a published DMARC record with a minimum of monitoring (p=none) policy."}],groups:[{subcategory:"SPF (Sender Policy Framework)",dos:[{text:"Publish an [SPF TXT record](https://www.spamhaus.org/glossary/#spf-sender-policy-framework) in your domain's DNS zone file that specifies exactly which IPs and hosts are authorised to send email on your behalf."},{text:"Keep the SPF record as narrow as possible. Only include the sending infrastru
1cture you actually use."},{text:"Ensure your sending IP is explicitly included in the SPF record. Email sent from IPs not included in SPF will fail authentication checks."},{text:"Keep your SPF record within the **10 DNS lookup limit** (this includes all nested include: statements). Exceeding this causes a PermError, which means SPF fails entirely as mentioned in RFC7208 section 4.6.4."},{text:"Make sure both your HELO domain and the envelope From domain have a valid SPF record."}],donts:[{text:"**Do not** use overly permissive qualifiers like +all or broad include: ranges that authorise IP space you do not control."},{text:"Use SPF macros only when necessary, such as to avoid exceeding the 10-DNS-lookup limit."}]},{subcategory:"DKIM (DomainKeys Identified Mail)",dos:[{text:"Ensure every outbound message carries a valid [DKIM](https://www.spamhaus.org/glossary/#dkim-domainkeys-identified-mail) signature, using a minimum 1024-bit key length."},{text:"Ensure that the `d=` domain on the DKIM signature matches the domain on the header From."},{text:"Rotate your DKIM keys at least annually, or immediately if you suspect a key has been compromised."},{text:"ESPs must double-sign their email with DKIM using both their domain and the customer domain."}],donts:[{text:"**Do not** use the same DKIM key indefinitely. Stale, unrotated keys are a security risk."}]},{subcategory:"DMARC",dos:[{text:"Publish a [DMARC record](https://www.spamhaus.org/glossary/#dmarc-domain-based-message-authentication-reporting-and-conformance) for your sending domain. Start at p=none to monitor, then move to p=quarantine and ultimately p=reject once all legitimate sending sources are identified."},{text:"Set up a DMARC aggregate report address (rua=) from day one as this will help you audit email sent from your domain."},{text:"Ensure your Header From domain aligns with your DKIM signing domain (d=) so that DMARC alignment passes."}],donts:[{text:"**Do not** remain at p=none permanently. It provides reporting but offers no protection against spoofing or phishing of your domain."}]}]},{title:"4. Sending Best Practices",description:"How you send emails matters as much as what you send. Warming your IP and domain, maintaining a consistent volume, using trusted sources inside the email and providing clear and legit options for users to opt-out of emails will help improve your overall deliverability.",keyRequirements:[{term:"IP/Domain Warm-up",definition:"The process of gradually increasing sending volume on a new or dormant IP and domain, rather than sending at full volume immediately. Spamhaus subjects HELO domains with no sending history to additional filtering, and treats any change in IP or HELO hostname as a new asset requiring the same warm-up process."},{term:"Bounce management",definition:"The practice of monitoring and acting on delivery failures both permanent failures and temporary failures reported by receiving servers. Spamhaus expects hard bounces to be suppressed immediately and the overall bounce rate kept below 5%."},{term:"One-click unsubscribe",definition:"A mechanism, defined in RFC 8058, that allows a recipient to unsubscribe from an inbox with a single action rather than visiting a separate page. Spamhaus requires bulk commercial senders to support this alongside a visible unsubscribe link, with requests honoured within 2 business days."}],groups:[{subcategory:"Warm Up",dos:[{text:"HELO domains which DO NOT have a sending history will be subjected to additional filtering. Please read our [best practices](https://www.spamhaus.org/faqs/marketing-email#do-i-need-to-warm-up-my-ip-and-domain-before-sending) around IP/Domain warm-up."},{text:"Start sending slowly, and consistently for any IP address or domain that has not sent email in the past 90 days, before gradually increasing volume. Domains which have been recently registered will be part of Spamhaus ZRD list."},{text:"Treat any change in IP or the HELO hostname as a new asset if no prior sending history is available, and apply the same [warm-up process](https://www.spamhaus.org/faqs/marketing-email/#do-i-need-to-warm-up-my-ip-and-domain-before-sending) as you would for a new IP or domain."},{text:"Begin with initial few campaigns sent to your most engaged recipients to reduce the risk of hitting older invalid addresses. Maintaining a slow and consistent email volume will help build a strong sender reputation."},{text:"Where available, test a portion of triggered mail before adding the entire volume."}],donts:[{text:"**Do not** send inconsistent email volumes or trigger a sudden spike in sending, as this could negatively impact reputation."},{text:"**Do not** send to aged addresses that have had no recent direct activity with your IP/domain."}]},{subcategory:"Bounce Management",dos:[{text:"Suppress [hard bounces](https://www.spamhaus.org/resource-hub/deliverability/how-to-handle-bounced-emails/) immediately."},{text:"Investigate and remove repeated soft bounces after a defined threshold; this is typically 3–5 consecutive bounces."},{text:"Keep your overall bounce rate below 5%."}],donts:[{text:"**Do not** send to email addresses that have hard-bounced."}],footer_text:"According to [M3AAWG spam trap best practices](https://www.m3aawg.org/sites/default/files/doc_files/help_i_hit_a_spam_trap.pdf), mailboxes that remain inactive for more than 18 months can be repurposed as spam traps."},{subcategory:"Unsubscribe",dos:[{text:"**Bulk commercial senders:** Implement the List-Unsubscribe-Post header enabling one-click unsubscribe directly from the inbox ([RFC 8058](https://datatracker.ietf.org/doc/html/rfc8058))."},{text:"Include a clearly visible unsubscribe link in the body of every commercial email."},{text:"Action unsubscribe requests within 2 business days and add them to a global suppression list."}],donts:[{text:"**Do not** hide or obfuscate unsubscribe links."},{text:"**Do not** require recipients to authenticate to unsubscribe."}]},{subcategory:"Content",dos:[{text:"Ensure only system created links are functional to prevent malicious actors from modifying URLs for unintended redirects."}],donts:[{text:"**Do not** use free or unbranded URL shorteners in the content of your email."}],footer_text:"URLs and/or domains used in the content of an email will affect the overall reputation of the sending domain."}]},{title:"5. IP and Domain Reputation",description:`The reputation of your [IP](https://www.spamhaus.org/ip-reputation/) and [domain](https://www.spamhaus.org/domain-reputation/) can be checked via our [reputation checker](https://check.spamhaus.org).
2
3Spamhaus looks at multiple signals before assigning a reputation score — a strong negative signal can outweigh the absence of positive ones, so following all email best practices consistently is essential.
4
5Factors that influence your reputation include: who your service provider is, what your IP neighbourhood looks like, what infrastru
5cture your IPs are associated with, what upstream networks connect to internet backbones, when the IP or domain was first seen, when it was last used, and how it was used.`,keyRequirements:[{term:"Check proactively",definition:"review your IP/domain reputation regularly rather than waiting for a delivery issue."},{term:"Treat new assets as unproven",definition:"start at low volume with engaged recipients and build up gradually."},{term:"Give new domains time",definition:"hold them back from sending for at least 30 days after registration."}],groups:[{dos:[{text:"Check your [IP reputation](https://www.spamhaus.org/ip-reputation/) and [domain reputation](https://www.spamhaus.org/domain-reputation/) regularly and do not wait for a delivery issue or listing to discover an issue."},{text:"Associate your domain with network providers and registrars that maintain a good reputation. You can check the reputation of your hosting provider or registrar on our [reputation statistics page](https://www.spamhaus.org/reputation-statistics/registrars/domains/)."},{text:"Maintain a slow, steady, and predictable sending pattern. Consistent volume builds a positive sending history against your IP and domain over time and strengthens your reputation."},{text:"Treat newly seen IPs or domains as having no reputation history. Start sending at low volumes to your most engaged recipients and increase gradually."},{text:"Ensure newly registered domains are not used for at least 30 days from registration. The domain can be used for non-email purposes during this period, and establishing a web-presence prior to sending email will help improve the credibility of the domain."},{text:"Refer to our recommendations for best practices when using [newly registered domains](https://www.spamhaus.com/resource-center/best-practice-for-owners-of-a-newly-registered-domain-part-3/)."}],donts:[{text:"**Do not** use newly registered domains in SMTP as a FROM domain or a HELO domain unless the domain is properly warmed up. Similarly, using a newly registered domain in the content of the email can also look suspicious. The age of the domains used in the email can affect the overall sending reputation."}]}]},{title:"6. ESPs & Large Senders",description:`As an Email Service Provider or shared infrastructure host, you are responsible for the email sent across your infrastructure. Hosting abusive senders will negatively impact reputation for your shared domains and infrastructure.
6
7Follow these recommendations and requirements to maintain a healthy reputation.`,keyRequirements:[{term:"Segregate everything",definition:"traffic type, customer subdomains, and IPs, so one bad sender can't sink another."},{term:"Gate access on authentication",definition:"require SPF, DKIM, and DMARC before a customer can send."},{term:"Stay reachable and accountable",definition:"a monitored abuse address, current WHOIS contacts, and an enforced AUP."}],groups:[{subcategory:"Infrastructure",dos:[{text:"Have a customer delegate a sub-domain for exclusive use in your platform."},{text:"Maintain an active, monitored abuse address (e.g. [email protected]) and ensure your WHOIS record and abuse.net listing reflect current contact details."},{text:"Separate IPs by traffic type so that transactional email (receipts, alerts, password resets) is distinct from marketing email."},{text:"Utilise subdomains for each mailing stream so receivers can identify them."},{text:"Register for feedback loops (FBLs) at all major mailbox providers. Route complaint data back to the responsible customer account and into suppression lists automatically."},{text:"Enable [RFC8058](https://datatracker.ietf.org/doc/html/rfc8058) for one click unsubscribe for all your users sending bulk emails."},{text:"Monitor key signals such as sudden volume spikes, bounce rates above 2%, or complaint rates above 0.03% at a customer account level, and trigger automatic throttling or review when thresholds are exceeded."},{text:"Ensure all technical domains, like click tracking domains, redirect to the primary domain."}],donts:[{text:"**Do not** redact or obfuscate headers, as this can make email appear suspicious. The connecting received line must be visible."},{text:"**Do not** leave your abuse address unmonitored. If hosted on a cloud platform, ensure the mailbox is unfiltered, so it can receive ALL abuse reports."},{text:"**Do not** mix transactional and marketing email on the same IP ranges."},{text:"**Do not** use cousin domains to segregate email traffic; instead use sub-domains."}]},{subcategory:"List & Engagement Hygiene",dos:[{text:"Ensure customers implement Confirmed Opt-in and periodically verify this."},{text:"Perform proper bounce management, action unsubscribes, and suppress invali
7d and unengaged recipients at the platform level. Provide continual feedback to your customers on these actions."},{text:"Provide engagement data to customers so they can take relevant action."},{text:"Recommend a strong sunset policy for recipients who are no longer engaging with emails."}]},{subcategory:"Authentication",dos:[{text:"Double-sign all outbound email with DKIM for the ESP domain and sender domain."},{text:"Ensure all customers have SPF, DKIM, and DMARC configured before they are permitted to send email."}],donts:[{text:"**Do not** allow customers to purchase, rent, or harvest email lists. This must be explicitly prohibited in your AUP."}]},{subcategory:"Customer Onboarding & Compliance",dos:[{text:"Vet new customers prior to onboarding, by reviewing list sources, how permission was obtained, and sending history."},{text:"Educate customers on Email best practices and compliance."},{text:"Maintain a strict Acceptable Use Policy (AUP) that is enforced during onboarding, with clearly defined thresholds for suspension and termination applied consistently."},{text:"Maintain a compliance team that actively monitors abusive behaviour and is empowered to take corrective action promptly."}]}]}]},Ss=C({__name:"index",setup(k){const{setBreadcrumbs:v,setPageTitle:r,setPageDescription:p}=se();v([{text:"Resources"},{text:"Sender Best Practices",href:"/eich0ohsat7quu1cheixohthaer1eih4zohTh0ohdaekae8e/"}]),r("Sender Best Practices | Spamhaus"),p("Practical email sender best practices from Spamhaus — covering infrastructure, authentication, list hygiene, reputation, and ESP requirements.");const m=ws;return(t,f)=>{const l=re,b=St,y=gs,S=xs;return o(),n("main",null,[w(l,{class:"z-50 relative"}),w(b,{"intro-text":s(m).intro_text,"rfc-reference":s(m).rfc_reference,sections:s(m).sections,class:"z-40 relative"},null,8,["intro-text","rfc-reference","sections"]),s(m).sections.length?(o(),O(y,{key:0,sections:s(m).sections,class:"z-30 relative"},null,8,["sections"])):h("",!0),w(S,{class:"z-40 relative"})])}}});export{Ss as default};

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.