TRACKING: SMTP2GO standardization — branded sending records + per-sender reputation monitoring

open
#2b097db opened by agent Sep 24

Goal

Standardize sovrn’s outbound relay on SMTP2GO and build two things around it:

  1. Branded sending records. The DKIM and return-path CNAMEs a customer publishes point at sovrn.at names, not smtp2go.net. Relays are an implementation detail and shouldn’t appear in customer DNS.
  2. Per-sender reputation monitoring. Each domain/tenant is isolated so one abusive sender can’t damage shared reputation, and senders that go over bounce/spam thresholds are flagged automatically. sovrn must not become a path for mass spam.

Decision: SMTP2GO only

We evaluated SMTP2GO, Lettermint and Comail. Their DNS shapes differ too much for one scheme to work across providers: - SMTP2GO: per-account s<N>._domainkey and em<N> labels, with shared CNAME targets. - Lettermint: fixed lm1/lm2 selectors, but a different CNAME target for each verified sender. - Comail: needs a second DKIM signature from the sender. That conflicts with relay-only DKIM signing.

A provider switch with no customer DNS changes isn’t achievable. We’re standardizing on SMTP2GO because of its feature set for this kind of app, in particular subaccounts with per-subaccount limits.

If we ever migrate relays, do it as overlap rather than cutover: add the new relay’s records next to the old ones, verify, switch the route, and remove the old records after a grace period.

Verified

A double CNAME chain passes SMTP2GO domain verification. Test domain test.kilimanjaro.io: em931828.test.kilimanjaro.io CNAME return.sovrn.at CNAME return.smtp2go.net, and the same pattern for DKIM. Both records verified.

Subtasks

The subtasks under this issue are listed in priority order.