Email blast platform: how to send a mass email without burning your domain
Published Updated 12 min readBy the Rasket team

What an email blast platform is
An email blast platform is software that sends one message to a large list of people at once: a sale, a product announcement, a monthly newsletter, a change to your opening hours. It holds the list, merges a name or two into each copy, sends the copies, and tells you afterwards who received, opened, clicked, bounced or unsubscribed. An email blast service is the same thing sold as a hosted product, and “mass email” is the plain-English name for what it sends.
The word “blast” is the problem. It suggests volume first and audience second: load every address you can find, press send, see what sticks. That is how mailbox providers see it too, and they have built their filters to stop exactly that. A message sent to many people who did not ask for it is spam, however good the offer, and the domain it came from is marked accordingly.
So this post treats a blast as what it has to be in order to work: a campaign. A campaign is one message to an audience that opted in, about something they opted in to, with an unsubscribe they can use in one click, from a domain that has been introduced to mailbox providers gradually. If you want to send bulk email and still have a working domain next month, every rule below follows from that definition. The glossary entry for a broadcast uses the same word for the same thing.
The one rule with no exception
Never send to bought or scraped lists. An address you bought, rented, copied from a website or pulled from a directory belongs to someone who never asked to hear from you. Google’s sender guidelines tell senders not to purchase email addresses, Yahoo’s tell them not to purchase mailing lists, and Rasket’s acceptable use forbids sending to purchased, rented, shared, scraped or harvested lists. Nothing in this post makes such a list safe to send to.
What breaks a domain when you blast
Mailbox providers decide where a message lands largely on the reputation of the domain it came from, and that reputation is built from how recipients treat its mail: whether they open it, delete it unread, or press “Report spam”. A blast is a large number of those judgements in a short time, so it moves a domain’s reputation faster than anything else you send. Four habits move it the wrong way.
| What goes wrong | Why it hurts | What fixes it |
|---|---|---|
| A cold list | Old addresses bounce, abandoned ones have become spam traps, and people who forgot they signed up report the mail as spam. | Send only to people who opted in, and sunset the ones who stopped reading. |
| No warm-up | A domain with no history that suddenly sends thousands of messages looks exactly like a spammer's new domain. | Start small, with the most engaged readers, and raise the volume over weeks. |
| No unsubscribe | A reader who cannot leave reports the message as spam instead, which costs far more than losing them. | One-click unsubscribe headers and a visible link in every message. |
| An unwatched complaint rate | Complaints accumulate across sends; by the time inbox placement drops, the damage is weeks old. | Read the complaint rate after every send and stop when it rises. |
Notice that none of the fixes is technical cleverness. Each one is about sending to fewer, more willing people, more slowly, and letting them leave. That is uncomfortable if the goal was reach, and it is the whole of deliverability for bulk mail. The same reputation also carries your receipts and password resets if they leave from the same domain, which is why a bad blast can cost more than the blast itself; the post on transactional and marketing email explains how to keep the two apart.
The rules mailbox providers set for bulk senders
The largest mailbox providers have written their expectations down, and they agree on the substance. Gmail calls anyone who sends more than 5,000 messages a day to Gmail accounts a bulk sender. Bulk senders are asked to:
- Authenticate the domain. Set up SPF and DKIM, and publish a DMARC record. Yahoo asks for a DMARC policy of at least
p=nonethat passes. - Support one-click unsubscribe. Marketing and subscribed messages carry the headers RFC 8058 defines, plus a clearly visible unsubscribe link in the body. Yahoo asks for unsubscribes to be honoured within two days.
- Keep the spam rate low. Google’s sender guidelines ask for a spam rate reported in Postmaster Tools below 0.3% and recommend staying below 0.1%. Yahoo’s best practices also name 0.3%.
- Mail only people who asked. Google says not to send messages to people who did not sign up to get messages from you, and both providers say not to buy lists.
The law asks for some of the same things. In the United States, the FTC’s CAN-SPAM compliance guide points out that the Act covers all commercial messages, not only bulk ones, and lists among its requirements a valid physical postal address in every message, a clear way to opt out, and opt-outs honoured within 10 business days. Other countries set their own rules, often stricter about consent; this is not legal advice. The bulk sender requirements guide walks through every item on the providers’ lists.
How to send an email blast safely
Seven steps, in the order they matter. The first three happen before the first send and stay done; the last four are part of every send.
- Clean the list — Start from people who opted in to hear from you, remove addresses that hard-bounced or complained, and sunset subscribers who have not opened or clicked in months. Never send to a bought or scraped list.
- Warm up the sending domain — If the domain or address is new to bulk mail, start with a small send to your most engaged readers and raise the volume over several weeks, slowing down whenever deferrals or complaints rise.
- Authenticate the domain — Publish SPF and DKIM for the sending domain and a DMARC record of at least p=none, so mailbox providers can tie the blast to a domain whose reputation they can score.
- Add one-click unsubscribe — Send the List-Unsubscribe and List-Unsubscribe-Post headers defined by RFC 8058, put a visible unsubscribe link in the body, and honour every opt-out straight away.
- Send in a topic — Scope the blast to a topic people subscribed to, so it reaches only the contacts opted in to that kind of mail and an opt-out from it leaves the rest of their choices alone.
- Watch the complaint rate — Read the complaint rate per send and per domain. Google asks bulk senders to stay below 0.3% and recommends staying below 0.1%; a send that crosses that line is the signal to stop and find out why.
- Handle bounces — Suppress hard bounces at once, retry soft bounces for a bounded window, and treat an address that soft-bounces on every send as dead, so the next blast goes only to mailboxes that exist.
1. Clean the list
The list is the decision that matters most, and the one no setting can repair. Start from people who opted in to hear from you, ideally with a confirmed opt-in, and take out every address that hard-bounced or complained before. Then remove the people who stopped reading: a subscriber who has not opened or clicked anything in months is a future complaint or a future spam trap. The sunsetting guide covers how to find them and how to ask once before letting them go.
And never send to bought or scraped lists. Buying a list does not buy consent, and no amount of warm-up or authentication makes the mail wanted.
2. Warm up the sending domain
A domain with no history of bulk mail has no reputation, and mailbox providers are wary of a newcomer that arrives with a large send. Start with a small blast to the readers most likely to open it, and raise the volume over several weeks as the results stay healthy. If deferrals or complaints rise, hold or step back. The warm-up guide lays out the schedule and the signals to watch.
3. Authenticate the domain
SPF says which servers may send for the domain, DKIM signs each message so a provider can tell it was not altered, and DMARC tells providers what to do when the other two fail. All three are DNS records you publish once. Without them, a provider has no reliable domain to attach your reputation to, good or bad. The DKIM, SPF and DMARC post explains each record and how they fit together.
4. Add one-click unsubscribe
One-click unsubscribe is a pair of headers that lets a mail app show its own “Unsubscribe” control and act on it with a single HTTPS request, without opening a page. RFC 8058 requires the message to carry a valid DKIM signature covering both headers, which is one more reason step 3 comes first:
List-Unsubscribe: <https://www.rasket.com/u/v1.1.eyJ0…>
List-Unsubscribe-Post: List-Unsubscribe=One-ClickPut a visible unsubscribe link in the body as well, and honour the click at once. A reader who can leave easily leaves; a reader who cannot reports the message as spam. The one-click unsubscribe guide covers the headers, the endpoint and the common mistakes.
5. Send in a topic
A topic is a kind of mail someone subscribed to: product news, the weekly digest, sale announcements. Sending the blast inside a topic means it reaches only the people opted in to that kind of mail, and someone who opts out of sales announcements keeps getting the product news they still want. Without topics, every unsubscribe is a total one, and people who wanted half of what you send report the other half as spam.
6. Watch the complaint rate
The complaint rate is the share of delivered messages that recipients reported as spam. It is the number mailbox providers weigh most heavily, and it is easy to ignore because nothing visibly breaks until it is too high. Read it after every send, per domain, and treat a rise as a reason to stop sending to that audience until you know why. The complaint rate guide covers where the number comes from and how to bring it down, and the glossary defines it in a sentence.
7. Handle bounces
A blast to a large list always finds some addresses that no longer work. A hard bounce means the mailbox does not exist and never will: suppress it at once. A soft bounce is temporary, such as a full mailbox or a busy server: retry it for a while, and treat an address that soft-bounces on every send as dead. The hard and soft bounce post covers the difference and what to do with each, and the next blast is better for every address removed.
Sending a blast with Rasket Campaigns
In Rasket a blast is a campaign, which is the broadcasts resource in the API. Most of the seven steps are built in, and the ones that cannot be skipped are enforced rather than recommended. There are two layers.
The send gate decides whether a campaign may be queued at all. It runs when you send, inside the same transaction that moves the campaign, and refuses with a 422 if any of these is missing:
- a from address on one of your domains that is verified for sending and enabled;
- a postal address on file for your team, which the footer prints;
- a segment that still exists, to send to;
- a body: non-empty HTML or text, written inline or copied from a published template.
A refused send creates nothing, and the answer names the first condition to fix. The unsubscribe link is not on the list because it cannot be missing: a body that contains neither {{{UNSUBSCRIBE_URL}}} nor {{{PREFERENCES_URL}}} gets a footer appended with an unsubscribe link and your postal address, and every campaign carries the one-click headers from step 4. A team whose sending has been restricted is refused with a 403 instead.
curl https://api.rasket.com/broadcasts \ -H "Authorization: Bearer $RASKET_API_KEY" \ -H "User-Agent: acme-news/1.0" \ -H "Content-Type: application/json" \ -d '{ "name": "Autumn sale", "segment_id": "'"$SEGMENT_ID"'", "topic_id": "'"$TOPIC_ID"'", "from": "Acme <news@news.acme.example>", "subject": "The autumn sale starts Monday", "html": "<p>Hi {{{FIRST_NAME|there}}},</p><p>Everything in the shop is cheaper for a week.</p><p><a href=\"{{{UNSUBSCRIBE_URL}}}\">Unsubscribe</a></p>" }'# Every condition of the send gate, passed or notcurl https://api.rasket.com/broadcasts/$BROADCAST_ID/checklist \ -H "Authorization: Bearer $RASKET_API_KEY" \ -H "User-Agent: acme-news/1.0"
# Then queue itcurl https://api.rasket.com/broadcasts/$BROADCAST_ID/send \ -H "Authorization: Bearer $RASKET_API_KEY" \ -H "User-Agent: acme-news/1.0" \ -H "Idempotency-Key: autumn-sale-send" \ -H "Content-Type: application/json" \ -d '{}'Eligibility decides who, of the segment, actually receives it. Each contact is checked when the campaign is planned and again just before their copy is sent, and skipped if they have unsubscribed from everything, opted out of the campaign’s topic (or never opted in to a topic whose default is out), are on your suppression list, or have been deleted. The report names the reason for each skipped contact. Every copy then goes through the same sending path as a single email, so hard bounces and complaints land on the suppression list automatically and the next blast skips them.
Consent is recorded where it is given. An opt-in written over the API, an opt-out from the one-click headers and a change on the hosted preference page all land in one ledger per contact and topic, with a source and a time. The Campaigns feature page shows the whole flow, and the newsletter API post walks through topics, contacts and segments call by call.
What to look for in an email blast service
Whatever you choose, judge an email blast service by what it refuses to do as much as by what it does. The questions worth asking:
- Does it insist on consent? A platform that will import any list and send to it is a platform whose shared reputation includes everyone else’s bought lists.
- Is unsubscribe automatic? One-click headers on every message and an unsubscribe link that cannot be removed by accident.
- Can people choose what they hear about? Topics or a preference page, so leaving one kind of mail does not mean leaving all of it.
- Does it show complaints and bounces per send? A report that shows only opens and clicks is hiding the two numbers that decide the next send.
- Does it keep blasts apart from your transactional mail? Separate sending domains, ideally a subdomain for marketing, so a bad campaign cannot push your password resets into spam.
A platform that answers yes to all five will occasionally stop you from sending something. That is the point: every refusal is a complaint, a bounce or a burned domain that did not happen. Rasket’s marketing email is built to answer yes, from the same account and API you already use for transactional mail.
Frequently asked questions
What is an email blast platform?
It is a service that sends one message to many recipients at once and handles what that involves: the contact list, the unsubscribe headers and links, bounces, complaints and a report on who received, opened and clicked. A good one also refuses the sends that would damage your domain, such as one with no postal address or no verified sending domain.
Can I send an email blast to a list I bought?
No. A bought or scraped list is made of people who never asked to hear from you, so it produces the complaints, the bounces and the spam-trap hits that ruin a sending domain. Google's sender guidelines tell senders not to purchase email addresses, and Yahoo's tell them not to purchase mailing lists. Rasket's acceptable use forbids it too.
Is sending a mass email legal?
In general terms, yes, when the recipients agreed to it and the message follows the law where you and they are; this is not legal advice. In the United States the FTC's CAN-SPAM guide covers all commercial messages, not only bulk ones, and asks for a valid postal address, a clear way to opt out and opt-outs honoured within 10 business days.
How many emails can I send in one blast?
There is no single safe number; what a mailbox provider accepts depends on the reputation your domain has built. Gmail treats anyone sending more than 5,000 messages a day to Gmail accounts as a bulk sender, with stricter rules. A new domain should start small with its most engaged readers and grow over weeks rather than send everything on day one.
What complaint rate is too high for a blast?
Google asks bulk senders to keep the spam rate reported in Postmaster Tools below 0.3% and recommends staying below 0.1%, and Yahoo also names 0.3%. Those are rates per day across your mail, so a single blast to a stale list can push the whole domain over the line in an afternoon. Stop, look at the audience, and fix it before the next send.
Why did Rasket refuse my campaign with a 422?
The send gate found something missing: a from address on a domain verified for sending, a postal address on file for the team, a segment that still exists, or a body. The answer names the first one to fix, and GET /broadcasts/{id}/checklist lists every condition at once so you can see them all before you try again.
Will a blast hurt my transactional email?
It can, if both leave from the same domain, because mailbox providers score a domain on how its recipients treat all of its mail. A blast draws more complaints than a receipt. Send blasts from their own subdomain, such as news.acme.example, and receipts and password resets from another, so a bad campaign cannot push the resets into spam.
Sources
- Email sender guidelines — Google, read 2026-10-01
- Sender Best Practices — Yahoo, read 2026-10-01
- RFC 8058: Signaling One-Click Functionality for List Email Headers — RFC Editor, read 2026-10-01
- CAN-SPAM Act: A Compliance Guide for Business — Federal Trade Commission, read 2026-10-01
Related
- Campaigns — An audience you own: contacts with typed properties, segments, topics people subscribe to, and campaigns sent through the same pipeline as your other mail.
- Marketing email — An email marketing platform on the API you already send with: campaigns to contacts and segments, automations from your product's events, a brand-aware editor.
- Campaign — A campaign, also called a broadcast, is one message sent to many people at once: a newsletter, a product announcement, a release note.
- Spam complaint rate — The complaint rate is the share of your delivered messages that readers marked as spam, measured per mailbox provider rather than across your whole audience.
- Newsletter API: send campaigns from your code — Send a newsletter over an API in six calls: create a topic, add contacts with consent, build a segment, create the campaign, pass the gate and read the report.
- Double opt in email: how it works and why — How a double opt in email flow works: sign a confirmation link, verify the click, record the consent on the contact, and never mail anyone who did not confirm.