Deliverability•3 min read

Handling Spam Complaints to Protect Your Sender Reputation

Spam complaints can severely damage your email deliverability and sender reputation. Learn how Piisend automatically manages suppressions and how to leverage webhooks for real-time complaint handling to maintain a healthy email program.

Handling Spam Complaints to Protect Your Sender Reputation

Section 1

Understanding Spam Complaints and Their Impact

A spam complaint occurs when a recipient marks your email as spam or junk in their email client. Internet Service Providers (ISPs) use Feedback Loops (FBLs) to report these complaints back to email service providers like Piisend. Even a low complaint rate can significantly harm your sender reputation, leading to lower deliverability for all your emails, including critical transactional messages. It's crucial to address these complaints promptly to avoid being blacklisted or having your emails routed directly to spam folders.

Section 2

Piisend's Automatic Suppression for Complaints

Piisend automatically adds any email address that generates a spam complaint to a global suppression list. This critical feature prevents you from inadvertently sending future emails to users who have explicitly indicated they don't want them, thereby protecting your sender reputation. This automatic suppression differs from a hard bounce: a complaint is a user-initiated action, while a hard bounce is a permanent technical delivery failure (e.g., invalid email address). Both lead to suppression, but understanding the distinction helps in diagnosing deliverability issues. Piisend handles both to ensure your sending practices remain healthy.

bash
1curl -X POST https://api.piisend.com/api/v1/emails \
2 -H "Authorization: Bearer YOUR_API_KEY" \
3 -H "Content-Type: application/json" \
4 -d '{
5 "to": ["recipient@example.com"],
6 "subject": "Your Order Confirmation",
7 "html": "<p>Thank you for your order!</p>",
8 "text": "Thank you for your order!"
9 }'

Section 3

Real-time Complaint Handling with Piisend Webhooks

To take immediate action when a user complains, you can set up a webhook to receive real-time notifications for complaint events. This allows your application to update internal user statuses, remove the user from marketing lists, or trigger other custom workflows. Piisend sends a POST request to your configured webhook URL with a JSON payload detailing the event. This proactive approach helps you maintain a clean mailing list and respect user preferences instantly.

json
1{
2 "event_type": "complaint",
3 "timestamp": 1678886400,
4 "message_id": "msg_abcdef1234567890",
5 "email": "complaininguser@example.com",
6 "reason": "user_marked_as_spam",
7 "ip_address": "192.0.2.1"
8}

Section 4

Verifying Webhook Signatures for Security

It's crucial to verify the authenticity of incoming webhook requests to ensure they originate from Piisend and haven't been tampered with. Piisend includes an X-Webhook-Signature header, which is an HMAC-SHA256 hash of the raw request body, signed with your webhook secret. You should also check the X-Webhook-Timestamp to mitigate replay attacks. Implementing signature verification adds a vital layer of security to your complaint handling system, preventing malicious actors from injecting fake complaint data.

python
1import hmac
2import hashlib
3import time
4
5WEBHOOK_SECRET = "your_webhook_secret_from_piisend"
6
7def verify_piisend_webhook(request_body, headers):
8 signature = headers.get("X-Webhook-Signature")
9 timestamp = headers.get("X-Webhook-Timestamp")
10
11 if not signature or not timestamp:
12 return False
13
14 # Check for replay attacks (e.g., within 5 minutes)
15 if abs(time.time() - int(timestamp)) > 300:
16 return False
17
18 signed_payload = f"{timestamp}.{request_body.decode('utf-8')}"
19 expected_signature = hmac.new(
20 WEBHOOK_SECRET.encode('utf-8'),
21 signed_payload.encode('utf-8'),
22 hashlib.sha256
23 ).hexdigest()
24
25 return hmac.compare_digest(expected_signature, signature)
26
27# Example usage (assuming 'request' object from a web framework)
28# if verify_piisend_webhook(request.body, request.headers):
29# print("Webhook verified successfully!")
30# else:
31# print("Webhook verification failed.")

Section 5

Best Practices to Prevent Spam Complaints

Minimizing spam complaints is key to long-term deliverability. Here are some best practices:

  • Obtain Explicit Consent: Only send emails to users who have explicitly opted in to receive communications from you. Double opt-in is highly recommended.
  • Send Relevant Content: Ensure your emails provide value and meet the expectations set during the sign-up process. Irrelevant content is a major cause of complaints.
  • Provide Clear Unsubscribe Options: Make it easy for recipients to opt out. Include a prominent unsubscribe link in the email body and utilize the List-Unsubscribe header. Piisend automatically adds this header to your emails.
  • Maintain List Hygiene: Regularly clean your email lists by removing inactive subscribers or those who haven't engaged with your emails in a long time.
  • Segment Your Audience: Send targeted emails to specific user groups based on their interests and behavior. This increases relevance and reduces the likelihood of complaints.

Start sending

Ship transactional email in minutes

Create an API key, verify a domain, and send your first message with Piisend.