M3AAWG Documents for Senders and ESPs — Annotated Index
What else M3AAWG publishes for senders and ESPs, plus the feedback-loop ecosystem — FBL format types and the per-provider FBL signup list.
The Messaging, Malware and Mobile Anti-Abuse Working Group (M³AAWG) maintains a "Documents for Senders and ESPs" page and a Feedback Loop resources page. Two of the documents are digested in full in this KB:
- M3AAWG Sender Best Common Practices v3.0
- M3AAWG Email Authentication Recommended Best Practices (2020)
This index catalogs the rest, so the KB knows what exists and where.
Documents listed on the senders/ESPs page
| Document | Date | What it covers | URL |
|---|---|---|---|
| Trust in Email Begins with Authentication | Feb 2015 | White paper on why/how email authentication (SPF, DKIM, DMARC) establishes trust; background reading the 2020 Authentication BCP builds on. | https://www.m3aawg.org/sites/default/files/doc_files/M3AAWG_Email_Authentication_Update-2015.pdf |
| M3AAWG Sender Best Communications Practices v3.0 | Feb 2015 | The Senders BCP — digested at m3aawg-senders-bcp.md. | https://www.m3aawg.org/sites/default/files/doc_files/M3AAWG_Senders_BCP_Ver3-2015-02.pdf |
| M3AAWG Position on Email Appending | Sep 2019 | Position statement: email appending (matching customer records to email addresses the owner never provided/consented to) is a direct violation of core M³AAWG values — abusive, complaint-generating, and a privacy/anti-spam legal risk. | https://www.m3aawg.org/sites/default/files/legacy/m3aawg_apending_position_update-2019-01.pdf |
| M3AAWG Vetting Best Common Practices | Nov 2011 | In-depth guide to customer vetting for ESPs: pre-send vetting to identify malicious senders before they mail, and post-send monitoring afterward (the Senders BCP makes both mandatory). | https://www.m3aawg.org/sites/default/files/doc_files/MAAWG_Vetting_BCP_2011-11.pdf |
| M3AAWG Complaint Feedback Loop BCP | Aug 2010, replaced Nov 2011 | Superseded by RFC 6449, Complaint Feedback Loop Operational Recommendations — the operational standard for running/consuming FBLs. | https://tools.ietf.org/html/rfc6449 |
| Best Current Practices for Building and Operating a Spam Trap | Aug 2016 | How spam-trap networks are built and run — useful for senders to understand how trap operators source addresses (recycled vs. pristine traps) and why hitting traps damages reputation. | https://www.m3aawg.org/sites/default/files/legacy/m3aawg-spamtrap-operations-bcp-2016-08.pdf |
Additional M³AAWG documents referenced from within the two digested BCPs (same catalog, not on the hub page):
| Document | What it covers | URL |
|---|---|---|
| Best Practices for Managing SPF Records (2017-08) | Comprehensive SPF record management, incl. staying within RFC 7208 DNS lookup limits. | https://www.m3aawg.org/sites/default/files/m3aawg_managing_spf_records-2017-08.pdf |
| DKIM Key Rotation BCP (2019-03) | How and how often to rotate DKIM keys. | https://www.m3aawg.org/sites/default/files/m3aawg-dkim-key-rotation-bp-2019-03.pdf |
| Best Practices for Implementing DKIM To Avoid Key Length Vulnerability (2017-07) | Minimum key lengths and implementation guidance. | https://www.m3aawg.org/sites/default/files/m3aawg-key-implementation-bp-revised-2017-07.pdf |
| Protecting Parked Domains BCP (2015-12) | Publish v=spf1 -all (and related records) on domains that never send mail. |
https://www.m3aawg.org/sites/default/files/m3aawg_parked_domains_bp-2015-12.pdf |
| Email Forwarding Best Practices | Running a mail-forwarding service (e.g., an ESP forwarding replies to customers using ESP-domain addresses). | http://www.maawg.org/system/files/news/MAAWG_Email_Forwarding_BP.pdf |
| Feedback Reporting Recommendation (2014-02) | Recommendations on feedback/complaint reporting between receivers and senders. | https://www.m3aawg.org/sites/default/files/legacy/document/M3AAWG_Feedback_Reporting_Recommendation_BP-2014-02.pdf |
| DMARC Training Series (videos) | Extensive course on DMARC presented by DMARC.org experts. | http://www.maawg.org/activities/training/dmarc-training-series |
Feedback loop (FBL) resources
A Complaint Feedback Loop is a mechanism by which a mailbox provider reports its users' spam complaints back to the verified sender of the message, so the sender can clean its database and fix the causes of the complaints. Standards: RFC 6449 (operational recommendations) and the Abuse Reporting Format (ARF) (RFC 6650 lineage) as the report format.
Three FBL format types
| Type | How it works | Notes |
|---|---|---|
| Traditional (IP-based) | Per-RFC 6449; reports in ARF with the full message and complaining-user identification, keyed to the sending IP. | The classic model; requires the sender to control/register the sending IPs. |
| Aggregated | Rolls up complaint counts without PII or full messages. | Privacy-driven; still gives per-stream performance data. Examples: Gmail (Postmaster Tools spam-rate data), Microsoft SNDS, Signal Spam. |
| Domain-based | Requires DKIM signatures; reports in ARF keyed to the signing domain. | Lets senders on shared IPs get feedback about their specific program — pairs with the Senders BCP advice to DKIM-sign each entity in a shared pool with its own (sub)domain. |
FBL signup points by mailbox provider (as listed by M3AAWG)
Most traditional FBLs are operated through Validity's Universal Feedback Loop (https://fbl.validity.com): Bluetie/Excite, Comcast, Cox, Fastmail, Gandi, Italiaonline (Libero/Virgilio), La Poste, Locaweb, Mail.Ru, OpenSRS/Tucows, Rackspace, Seznam, SFR, SilverSky (USA.NET), Swisscom, Synacor, Telecom Italia, Telenet, Telenor, Terra, UOL, Virgin Media, Ziggo.
Exceptions and non-Validity programs:
| Provider | Type | Signup |
|---|---|---|
| Earthlink | Traditional | fblrequest@abuse.earthlink.net |
| Microsoft JMRP (Junk Mail Reporting Program) | Traditional | https://postmaster.live.com/snds/JMRP.aspx |
| QQ.com | Traditional | http://open.mail.qq.com (Chinese) |
| United Online/Juno/NetZero | Traditional | http://www.unitedonline.net/postmaster/whitelisted.html |
| Gmail | Aggregated | https://support.google.com/mail/answer/6254652 (Postmaster Tools) |
| Microsoft SNDS | Aggregated | https://sendersupport.olc.protection.outlook.com/snds/index.aspx |
| Signal Spam (France) | Aggregated | https://www.signal-spam.fr (paid membership) |
| Yahoo! | Domain-based (DKIM) | https://senders.yahooinc.com/contact#complaint-feedback-loop |
| Comcast, Gandi, La Poste, SFR | Domain-based (also offer traditional) | https://fbl.validity.com |
Notable: Gmail offers no traditional per-message FBL — its aggregated program (spam-rate by identifier via Postmaster Tools) is the only complaint signal available, which is why suppressing complainers individually is impossible at Gmail and complaint prevention matters more there. Yahoo's FBL is domain-based, keyed to the DKIM d= domain.
M³AAWG provides this list as an industry service and does not endorse specific providers; the material is third-party and offered "as is."
How FBLs fit a sender's workflow
Per the Senders BCP: ESPs must have a system to ingest both FBL reports and direct abuse-mailbox complaints, plus a process to act on them — immediate suppression of the complaining recipient (where the FBL identifies one) and complaint-rate monitoring per customer/stream to detect Terms-of-Service violations or list-hygiene problems.
Related
- M3AAWG Sender Best Common Practices
- M3AAWG Email Authentication BCP
- Foundations of Email Deliverability — complaints as a core reputation input