Skip to content

Transactional vs marketing mail under bulk sender rules

Which bulk sender rules apply to receipts and password resets, which apply only to marketing, and why mixing both streams on one domain is risky.

Koltrix Team4 min read
A stack of paper envelopes in muted colors
Photo by Joanna Kosinska on Unsplash
On this page(7 sections)
  1. How bulk status is assigned
  2. Which requirements apply to which mail
  3. What counts as transactional
  4. Clearly transactional
  5. Usually subscribed (treat like marketing)
  6. Gray zone
  7. Why mixing streams on one domain is risky
  8. Common mistakes
  9. A classification exercise
  10. Key takeaways

A common assumption about the Gmail and Yahoo sender requirements goes like this: "We only send receipts and password resets, so the bulk rules are for marketers, not us." That is half right. Some requirements apply only to marketing mail, but bulk sender status, and most of what comes with it, attaches to your domain, not to the type of message.

How bulk status is assigned

Gmail defines a bulk sender as one that sends close to 5,000 or more messages to personal Gmail accounts in 24 hours. The count covers all mail from the same primary domain, so example.com and notifications.example.com add up together. And once a domain is classified as bulk, Google says that status does not expire.

None of that depends on what the messages say. A SaaS product with a few thousand active users can cross the threshold on transactional mail alone: daily digests, alerts, receipts, login codes and comment notifications add up quickly.

Which requirements apply to which mail

Here is how the published requirements break down by message type, once a domain is a bulk sender:

Requirement Transactional mail Marketing and subscribed mail
SPF and DKIM both configured Yes Yes
DMARC published (at least p=none) Yes Yes
From domain aligned with SPF or DKIM Yes Yes
Valid forward and reverse DNS Yes Yes
TLS Yes Yes
Spam rate below 0.3% Yes, measured for the domain Yes, measured for the domain
One-click unsubscribe (RFC 8058) Not required Required
Visible unsubscribe link Not required Required
Unsubscribes honored within two days Not applicable Required

So the exemption for transactional mail is narrow: it covers the unsubscribe mechanics, because nobody should be able to unsubscribe from a password reset. Authentication, alignment, infrastructure and complaint rates apply to everything.

What counts as transactional

Gmail's requirements describe one-click unsubscribe as applying to marketing messages and subscribed messages. That leaves a gray zone that each team has to decide carefully:

Clearly transactional

  • Password resets and login codes.
  • Receipts, invoices and payment failures.
  • Security alerts about the user's account.
  • Direct responses to an action the user just took, such as "your export is ready."

Usually subscribed (treat like marketing)

  • Newsletters and product announcements.
  • Promotional offers, discounts and upsells.
  • "We miss you" and re-engagement campaigns.
  • Event invitations not tied to a specific user action.

Gray zone

  • Activity digests ("here is what happened in your workspace this week").
  • Notification emails for comments, mentions or assignments.
  • Onboarding sequences after signup.
  • Usage summaries and tips.

For the gray zone, ask: could a reasonable user want to stop receiving this while still using the product? If yes, give them a way to do so, and treat the stream as subscribed. Digests and notification emails almost always qualify. Many products give each notification category its own preference toggle and a one-click unsubscribe that turns off that category only. That reduces complaints, which protect the reputation your password resets also depend on.

Why mixing streams on one domain is risky

Because the spam rate and reputation are measured for the domain, marketing complaints affect transactional deliverability. A promotional campaign to an old segment that draws complaints can push password resets into spam the next day. That is the core argument for separating streams.

Practical separation options:

  • Different From subdomains, such as mail.example.com for transactional and news.example.com for marketing. Reputation is tracked at multiple levels, and subdomains give receivers a clearer signal about which stream is which. Note that Gmail still counts subdomains together toward the bulk threshold.
  • Different DKIM signing domains or selectors per stream, so complaints and authentication can be traced to a stream.
  • Different sending IPs or IP pools if you operate dedicated IPs.
  • Different providers for transactional and marketing mail, which some teams choose for operational reasons as well.

Separation does not make the organizational domain invisible; filters can see that both subdomains belong to example.com. But it limits how far damage from one stream spreads, and it makes diagnosis far easier.

Common mistakes

  • Adding marketing to receipts. A "while you are here, check out our new plan" block in a receipt changes the character of the message. Keep promotional content out of mail users cannot opt out of.
  • No unsubscribe on digests. Users who cannot turn off a weekly digest report it as spam instead.
  • One-click unsubscribe on transactional mail that suppresses everything. If you do add List-Unsubscribe to notification emails, scope it to that notification category, not to all mail including security alerts.
  • Assuming low volume means exemption. The threshold is about 5,000 messages a day to Gmail personal accounts, which many growing SaaS products reach without any marketing at all.
  • Ignoring vendors. Billing and support tools that send as your domain count toward the volume and must align.

A classification exercise

Make a table of every email your product and company send, with columns for trigger, audience, volume, opt-out available, stream and sending domain. Then for each row decide:

  1. Transactional or subscribed?
  2. If subscribed, is there a one-click unsubscribe and a visible link?
  3. Which From domain and DKIM identity does it use?
  4. Is it on the same domain as your most critical mail?

This exercise usually takes an hour and finds at least one notification stream with no opt-out and one vendor sending unaligned mail.

Key takeaways

  • Bulk sender status attaches to your primary domain, counts subdomains together, never expires, and can be reached with transactional mail alone.
  • Authentication, alignment, DNS, TLS and the 0.3% spam rate apply to all mail once you are a bulk sender.
  • Only the unsubscribe requirements are limited to marketing and subscribed messages.
  • Treat digests and optional notifications as subscribed: give them scoped one-click unsubscribe.
  • Separate transactional and marketing streams so complaints about one do not sink the other.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn