Sender Certification Programs: Validity Certification and the CSA
The two surviving commercial allowlist programs — Validity Sender Certification and the Certified Senders Alliance — with exact admission criteria, performance thresholds, costs structure, which receivers honor each, and an honest assessment of when certification pays off.
Formal third-party allowlisting is largely historical, but two commercial programs survive with real receiver backing: Validity Sender Certification (the former Return Path Certification, an IP allowlist honored mainly by Microsoft, Yahoo/AOL, Comcast, and Cloudmark-filtered networks) and the Certified Senders Alliance (CSA) (a German eco/DDV program whose allowlist is consumed by GMX/WEB.DE and most of the German-speaking mailbox market). They target different senders: Validity certifies brands on dedicated IPs and explicitly excludes ESPs; the CSA certifies sending platforms — including ESPs — at the infrastructure level.
Neither program influences Gmail. Gmail runs its own reputation systems and largely ignores third-party signals — there is no certification, paid or otherwise, that improves Gmail placement.
Validity Sender Certification
Source: "Sender Certification Requirements" (Validity, © 2024, published for 2025; fetched July 2026). Certified IPs are placed on Validity's allowlist; mailbox provider partners are notified, and Validity starts 24×7 monitoring of the IPs. Validity claims relationships with "75+ global mailbox and security providers"; the partners it names thresholds for are Microsoft, Yahoo/AOL, Comcast, and Cloudmark.
Application and pre-approval process
- Subscribe → Validity initiates a comprehensive audit of the email program.
- Complete the Sender Certification Questionnaire (typically within the first day); this unlocks the certification data feeds (complaint rates, spam trap hits, sending volume per IP from Validity's provider/filter partners) and starts the audit.
- If the program meets the Business Model, Measurability, and Infrastructure requirements, the account may get preliminary activation of Certified status before the audit completes — the "pre-approved" state marketed at validity.com/sender-certification/get-pre-approved. Preliminary benefits last up to 60 days while the audit runs.
- If audit remediation is incomplete after the 60-day preliminary period — or requirements are breached at any point during the subscription — the IPs are suspended from the allowlist (data-feed access continues); they are re-activated once corrections are made.
Ongoing obligations: respond to any program notice within 3 days and initiate required actions within 10 days; notify Validity in writing within 2 business days of an IP/domain compromise (re-enable only after Validity reviews the mitigation).
Eligibility (business model)
- Business verifiable via public third-party source (country registry, Dun & Bradstreet), physical address on record, legally registered and operational ≥1 year, no registered agent obscuring ownership.
- Valid HTTPS website/landing pages for every approved brand for ≥ the past 6 months.
- Dedicated IPs only — shared IPs are ineligible; the applicant must have been the only entity on the IPs for ≥60 days.
- Certified IPs may carry only transactional and commercial templated email — no corporate/1:1 mail, no free-form content (e.g., web-form input) in messages.
Excluded business categories (not certifiable): Email Service Providers (senders mailing on behalf of brands they don't own — ESPs, brand licensing, publishers, white-labels), agencies, third-party/affiliate mailers, lead generation, list rental providers, penny-bid auctions, illegal activities, human trafficking. Operational consequence for an ESP: you cannot certify your own platform or shared pools — only your dedicated-IP customers who fully own their brand can enroll, individually.
Volume minimums and IP limits
- Each IP must deliver ≥100 messages to each of Microsoft and Yahoo per rolling 30 days (as seen in Validity's data). IPs without measurable, consistent volume are not reviewed; once certified, such IPs are suspended after 30 days and deleted from the program after 90 days.
- An IP may not target a single mailbox provider (occasional exceptions only with Validity's prior written approval).
- Max certified IPs scale with contracted annual volume:
| Annual sending volume | Max IPs | Annual sending volume | Max IPs | |
|---|---|---|---|---|
| 1,200,000 | 2 | 120,000,000 | 8 | |
| 3,000,000 | 2 | 180,000,000 | 9 | |
| 7,500,000 | 3 | 240,000,000 | 10 | |
| 12,000,000 | 4 | 420,000,000 | 13 | |
| 36,000,000 | 5 | 600,000,000 | 16 | |
| 60,000,000 | 6 | 1,200,000,000 | 18 | |
| 90,000,000 | 7 | > 1,200,000,000 | 22 |
Technical and program requirements (summary)
- Infrastructure: no open relays; FCrDNS; SPF on all Return-Path domains with no
+all/?alland noptrmechanism; all mail DKIM-signed, keys ≥1024 bits (2048 recommended), nol=tag (usex=instead); DMARC at leastp=none, aligned, with a workingrua, on the From domain; ARC recommended if forwarding;abuse@andpostmaster@role accounts on all sending/Return-Path domains; domain-ownership proof via a Validity TXT token that must stay in DNS for the membership's duration; hard bounces removed from all future mailings; TLS recommended. - Content: clear branding; accurate subject lines with no "RE:"/"FWD:"; physical mailing address in commercial and transactional mail; no URL shorteners (Bitly, TinyURL, etc.); no attachments of any kind; no hidden content; valid Message-ID; RFC 5322-compliant headers.
- Unsubscribe: List-Unsubscribe (RFC 2369) covered by the DKIM signature, RFC 8058 one-click, plus a body link; requests processed within 2 days; links functional ≥60 days after send; non-standard requests (postal, phone, abuse@) also honored.
- Consent: double opt-in or single opt-in with notification (an alternative legal basis, e.g. documented legitimate interest, needs written evidence). Prohibited: pre-selected or plain single opt-in without notification, harvesting, list rental/purchase/append, email prospecting. Co-registration requires per-brand unchecked sign-ups and provable consent. Forward-to-a-friend: CAPTCHA on the form, one email + at most one follow-up, no external links, ≤140-char personalized comment, ≤100 messages per user per 24 h.
- FBLs: sign up for all available feedback loops; mandatory minimum — Microsoft JMRP, Comcast IP & Domain FBL, Yahoo FBL.
Performance thresholds (exceeding any → suspension in part or whole)
Microsoft SRD (Sender Reputation Data junk votes), 30-day cumulative:
| Individual IP SRD volume | 0–4 | 5–10 | 11+ |
|---|---|---|---|
| Allowed SRD rate | not enforced | 5 junk votes | 45% |
| Group SRD volume (all certified IPs) | 0–9 | 10–30 | 31–50 | 51+ |
|---|---|---|---|---|
| Allowed SRD rate | not enforced | 75% | 65% | 55% |
Group enforcement applies when ≥2 IPs are certified; if the group threshold is exceeded, every IP with ≥1 junk vote is suspended.
Complaint rates, 30-day average of all sending volume (enforced only above a minimum complaint count):
| Source | Threshold | Enforced above |
|---|---|---|
| Microsoft complaint rate | 0.2% | 200 complaints |
| Yahoo/AOL inbox complaint rate | 0.2% | 200 complaints |
| Comcast complaint rate | 0.3% | 100 complaints |
| Cloudmark complaint rate | 1.0% | 100 complaints |
Spam traps, 30-day cumulative:
| Trap class | Allowed hits |
|---|---|
| Critical spam traps | 3 |
| Significant spam traps | 5 |
| RP Trap Network | 100 |
| Cloudmark traps | 100 |
Blocklists (current listings): 1 listing on a critical blocklist or 2 on significant blocklists breaches the threshold; repetitive or excessive listings can mean suspension or termination.
Certified Senders Alliance (CSA)
The CSA is run by eco (Association of the Internet Industry) with the DDV (German Dialogue Marketing Association), founded 2004. It is an IP-platform certification (IPv4 only): the certified party is the company that operates and controls the sending platform — which is exactly an ESP, the opposite of Validity's model. The CSA maintains a certified-IP list distributed to participating mailbox and security providers for integration into their filters, and those partners return live compliance data that certified companies see in the Certification Monitor. Contract documents (Criteria, Conditions of Participation, Rules of Procedure, Price List) are published at certified-senders.org/resources. German law applies; jurisdiction is Cologne.
Provenance: the legacy 2017 PDF URLs cited above now serve the June 2026 editions of the Criteria and Conditions of Participation (the legacy documents expired 19 July 2026), so the figures below are current as of the June 2026 versions, fetched July 2026.
Who can participate
- The company operates the technical platform that controls bulk-email sending and bears responsibility for it; generally ≥3 months of sending history on the infrastructure.
- Certification covers all IPs used for commercial bulk email; every IPv4 + FQDN must be uploaded to the Certification Monitor, and declared IPs may be used only for commercial bulk email (not internal corporate mail).
- ESPs/platform providers: only IPs under the company's sole control are certifiable, and certified outbound servers must be clearly separable from non-certified ones.
- Brands running their own platform must fully control and monitor delivery on it — otherwise they cannot be certified.
- Hosting providers are excluded for servers rented for autonomous customer use.
- The business model must not conflict with eco/DDV ethical principles (independent rejection ground).
Certification process, fees, and contract
- Return the signed individual offer and pay the assessment fee (per the CSA Price List; not refunded if certification fails).
- Assessment: reputation check on the declared IPs using participating partners' data, plus document review (sample newsletters, IP list). Repeatedly uncorrected errors can trigger a deadline; missing it allows the CSA to charge a fresh assessment fee.
- Decision by the Complaints and Certification Committee (CCC) — four members, two each elected from eco and DDV; certification requires a majority. Rejection (compliance doubts or ethical conflict) → may reapply after 6 months.
- Monthly contributions (invoiced quarterly, pro-rated) start on approval. The price category is set by total annual revenue of the company or its parent (annual revenue survey; non-response → highest category). Contract term 1 year, auto-renewing, 3-month notice.
- >30 days payment arrears → temporary delisting of IPs (reinstatement ~5 working days after payment); >60 days → termination for good cause. After contract end, all CSA references must be removed within 4 weeks (6 months for print) — €500 contractual penalty per week thereafter.
IP statuses on the certified list: Active (full benefits + monitoring/reporting), Failed (technical requirements not met — no benefits), Delisted (sanction — no benefits, monitoring continues), Monitored (during certification), Parked (company-assigned for unused IPs; listed but sending prohibited, lets you pre-stage DNS). Proof of control over each IP, for the duration of certification: either a DNS TXT record on the server FQDN of the form CSA-certified-host=<token>, or a WHOIS registrant-organisation match with the contracted company name. Outgoing servers need full FCrDNS (PTR → FQDN → A → same IP), the FQDN announced in HELO/EHLO, and hostnames that don't look like coded dial-up identifiers (server-80-12-54125.example.org fails). Missing verification or broken lookups → status "failed".
Mandatory criteria (June 2026)
Trust & transparency: postal address and digital contact easy to find on the website; accessible privacy information; RFC-compliant messages and SMTP dialogue (currently RFC 6532, 2142, 2369, 5321, 5322, 7208, 6376, 8058).
Abuse prevention:
- Role-account abuse address (preferably
abuse@org-domain.tld) registered in the Certification Monitor; respond to the eco Complaints Office within 24 hours on business days. - Platform providers must be able to enforce compliance per customer (blocking, rate limiting, volume caps, sending-domain caps) and protect customer accounts (e.g., 2FA).
- Redirect/click-tracking links must be deactivatable within 24 hours of a phishing/misuse notification.
X-CSA-Complaints: csa-complaints@eco.deheader inserted and DKIM-signed on certified servers only, within 4 weeks of certification, confirmed by test mailing.- No open relay, no public proxy, no backscatter; continuous monitoring; delivery over current-state-of-the-art TLS.
Authentication:
- SPF for the MAIL FROM domain ending
-allor~all. - Valid DKIM signature on every email (RFC 6376). For ESPs,
d=must be assignable to the customer's sending domain (an additional ESP-domain double signature is allowed); the signature must cover at least From, X-CSA-Complaints, Date, To; thel=length parameter is prohibited. - Relaxed DKIM alignment required: the organizational domain of
d=must match the header-From domain (ESP exception only when the customer has no domain of their own).
List hygiene:
- Platform capability to insert List-Unsubscribe (RFC 2369 URL method with POST HTTPS, combinable with List-Unsubscribe-Post / RFC 8058 one-click) and List-Help (mailto: or HTTPS link — HTTP not permitted) in every email.
- Every advertising email must carry a working unsubscribe requiring no login; ESPs must give customers an easy body-link unsubscribe feature (preference/selection pages allowed).
- Bounce handling per RFC 5321, with an MX record (A record as fallback) on the envelope-from domain; further delivery to known non-existent mailboxes must be prevented.
Performance thresholds (7-day windows):
| Indicator | Threshold | Basis |
|---|---|---|
| Spam complaint rate | ≤ 0.3% per IP or per company | complaints ÷ emails reaching the inbox |
| DKIM missing rate | ≤ 3.0% company average | unsigned ÷ total sent (partner-validated data) |
| Hard bounce rate | ≤ 1.0% per IP or per company | |
| General reputation | no significant IP/DKIM reputation problems with participating providers (trap hits, content scanners, spam rates) |
Recommended (non-mandatory): register for public FBLs and implement the CFBL header (RFC 9477); multipart HTML+text; DMARC with processable rua, p=reject recommended; DANE (RFC 7671 + DNSSEC), with MTA-STS (RFC 8461) as the fallback where DNSSEC isn't feasible; DKIM 2048-bit SHA-256; double opt-in (confirmation email must contain no advertising); state mailing frequency at sign-up; functional reply-to; separate IPs for newsletters vs transactional; avoid URL shorteners; extended DKIM alignment to MAIL FROM plus consistent List-/Reply-To-/Sender-header domains.
The CSA publishes a self-assessment checklist (certified-senders.org/csa-checklist) mapping these criteria to yes/no readiness questions — useful to run before paying the assessment fee.
The CSA Email Directive: German legal baseline encoded as certification content
The CSA's certification criteria reference its "Email Marketing Directive," which digests German/EU law. This is what makes CSA certification legally meaningful in Germany, and it's decision-relevant even for uncertified senders mailing German users (cf. the DOI expectation noted in GMX/WEB.DE requirements).
Permission (directive ch. 2) — grounded in GDPR + ePrivacy Directive 2002/58/EC as implemented in the UWG, TMG/TTDSG, BDSG:
- "Advertising" is construed broadly (newsletters, birthday greetings, market research, brand promotion, donation requests). Transactional mail needs no consent — until any advertising element is added, at which point full consent rules apply.
- Consent must be transparent (which company, which products, which channels — no blank consent; BGH: consent naming ~8 companies can hold, OLG Frankfurt: 59 sponsors is too many), active (no pre-checked boxes or opt-out constructs), freely given, and documented (consent text, place, timestamp + IP of sign-up and of the DOI confirmation click).
- Double opt-in is the de-facto evidentiary standard (BGH-recognized proof the request came from the address). The DOI confirmation email must contain no advertising (courts have objected even to footer logos); unconfirmed sign-ups should be deleted within ~2 weeks.
- Consent has no statutory expiry, but LG München I has treated consent unused for ~1.5 years as lapsed.
- Revocation must be easier than granting; consent documentation is retained 3 years after revocation (§195 BGB limitation period) to defend claims.
- §7(3) UWG existing-customer exception (email advertising without consent) requires all four: address obtained in connection with a concluded sale; advertising only similar own goods/services; a clear objection notice at collection and in every email; no objection made.
- B2B is not exempt: German law requires opt-in for B2B email advertising too (the B2B presumed-consent easing exists only for telephone).
Legal notice / Impressum (directive ch. 3) — E-Commerce Directive 2000/31/EC + Telemedia Act: every commercial email needs a complete legal notice in full text in the email itself (not behind links): company name with legal form, full street address, authorized representatives, register court and number, an email address (phone recommended), VAT ID where applicable. Sender identity and commercial character must be evident; violations are finable up to €50,000.
Which receivers honor the CSA
Participating mailbox providers (per certified-senders.org/participants, fetched July 2026) include the entire German-speaking consumer market — GMX, WEB.DE, mail.com, 1&1, freenet, mail.de, T-Online, Arcor, Kabel Deutschland/Vodafone, unitymedia, Swisscom — plus international names: Microsoft (Outlook.com, Office 365), Yahoo, AOL, Comcast, Orange, Seznam.cz, Fastmail and various hosters. Security/filter participants include Cloudmark, Cisco Talos, abusix, Hornetsecurity, Open-Xchange, Halon, Excello/virusfree. Weighting varies: German providers (GMX/WEB.DE actively direct bulk senders to the CSA and route complaint feedback through it — they run no public in-house FBL) treat it as a first-class signal; for the large international participants it is one input among many, not an allowlist bypass.
Is certification worth it?
An honest cost/benefit for an ESP operator:
- Gmail: no. Gmail participates in neither program and ignores third-party certification and blocklists in favor of its own systems. If the pain is Gmail placement, certification buys nothing — fix engagement and spam-rate fundamentals instead.
- Certification is a floor, not a boost. Both programs' admission criteria are essentially the M3AAWG senders BCP plus monitoring: a sender who genuinely meets them usually already delivers well. The marginal value is (a) the data feeds (Validity's trap/complaint/SRD feeds; the CSA Certification Monitor with partner data — notable because GMX/WEB.DE complaint feedback is otherwise unavailable), (b) benefit-of-the-doubt during incidents and warm-up, and (c) a documented compliance posture.
- CSA — worth evaluating for any ESP with meaningful German/DACH volume. It is the only program designed for platform/ESP certification, it is the de-facto FBL and escalation channel for GMX/WEB.DE, and its criteria encode the German legal regime (DOI, Impressum) you must meet anyway to mail Germany safely. Costs scale with company revenue (assessment fee + monthly contributions); mind the compliance obligations (24 h abuse response, 24 h link deactivation, 7-day thresholds) — decertification after public participation is a reputational signal in itself.
- Validity — a per-brand decision, not an ESP decision. ESPs are an excluded category; only dedicated-IP customers who own their brand, have ≥1 year of corporate history, ≥60 days alone on their IPs, and sustained Microsoft+Yahoo volume qualify. It suits high-volume B2C brands whose problem set is Microsoft (SRD/JMRP), Yahoo/AOL, Comcast, or Cloudmark-filtered regional ISPs. Its thresholds (0.2% Microsoft/Yahoo complaints, 3 critical trap hits/30 days, 1 critical blocklisting) are stricter than typical operating targets — treat them as an SLA you must keep, or face suspension mid-contract.
- Neither substitutes for consent quality. Both programs prohibit purchased/rented/appended lists outright; certification cannot launder a bad acquisition practice, and both revoke faster than mailbox providers forgive.
Sources
- https://certification.validity.com/wp-content/uploads/IP-Sender-Cert-Requirements-2025.pdf
- https://www.validity.com/sender-certification/get-pre-approved/
- https://certified-senders.org/resources/
- https://certified-senders.org/csa-checklist/
- https://certified-senders.org/wp-content/uploads/2017/07/CSA_Admission_Criteria.pdf
- https://certified-senders.org/wp-content/uploads/2017/07/CSA_Conditions_of_Participation.pdf
- https://certified-senders.org/email-directive/2-permission/
- https://certified-senders.org/email-directive/3-legal-notice/
- https://certified-senders.org/participants/