Email list hygiene in 2026 is three jobs, not one delete: stop mailing addresses that cannot receive mail, stop mailing people who mark you as spam, and sunset people who no longer engage with marketing mail. Remove hard bounces, complainers, completed unsubscribes, and known traps the same day. Do not apply a 90-day click window to invoices or password resets. ArawaMail does not clean lists for you—recipient quality lives in your app or ESP.
Hygiene is not “delete everyone who did not click”
Lists still decay on the order of 2–3% per month as jobs change and mailboxes die. That is industry context, not an ArawaMail metric. The instinct when bounces rise or inbox placement slips is to “clean the list.” Over-cleaning is how you drop recent buyers, people who read without a tracking pixel, and paying customers who never open the newsletter.
Treat three buckets separately:
- Cannot receive. Hard bounces, role accounts that reject, and known spam traps.
- Does not want the mail. Spam complaints and completed unsubscribes.
- Stopped engaging with marketing. A sunset decision after a re-engagement attempt—not a transactional suppression.
Mixing those buckets is how password-reset domains inherit newsletter complaint rates. Keep streams apart; the architecture is already covered in why marketing and transactional email should use separate subdomains.
Remove immediately versus watch for a week
Delete or suppress the same day:
- Hard bounces (unknown user, inactive mailbox, domain does not accept mail).
- Spam complainers. Honor the complaint; do not wait for a second one.
- Completed unsubscribes. CAN-SPAM, GDPR, and CASL all require you to honor them. Marketing mail also needs one-click unsubscribe (RFC 8058) for Gmail and Yahoo bulk senders—headers are a separate implementation job.
- Known spam traps and purchased or scraped names. Bought lists remain a reputation landmine. Do not rehabilitate them.
Watch, then act on a pattern:
- Repeated soft bounces—commonly 3–5 consecutive failures (mailbox full, greylist, temporary deferral). One “mailbox full” is not a permanent death.
- Sustained campaign bounce rates above about 2% as a warning and about 5% as an emergency. That is operator consensus in 2026, not a published Gmail SLA.
Address verification at import catches many invalids. It does not measure engagement or complaints. A verifier is necessary hygiene infrastructure, not a complete policy.
Sunset marketing names; do not sunset invoices
For marketing subscribers, re-engage first, then suppress the silent remainder. Common windows are 90–180 days without opens or clicks; tighten the window if you send daily. A two-step re-permission (“still want this?”) beats a silent mass delete on a young list.
Do not apply that window to transactional mail. A customer who never opens the newsletter still needs the invoice, the shipping notice, and the password reset. Suppress hard failures for that message type. Keep sending operational mail to a living address. What counts as transactional is defined in What is transactional email?; the operational habit is in Stop treating transactional mail as a side project.
Over-cleaning hurts revenue when you drop:
- Recent buyers who have not had time to engage with a monthly newsletter.
- People who read in clients that block tracking pixels.
- Transactional recipients whose only “unengagement” is ignoring marketing.
Prefer suppression plus re-permission over mass deletion.
What mailbox providers actually punish
Cleaning invalid addresses lowers bounces. It does not replace authentication, stream separation, or one-click unsubscribe. Gmail and Yahoo bulk-sender baselines still in force in 2026 (see Gmail Email sender guidelines) expect:
- SPF and DKIM pass, with From-domain alignment.
- A published DMARC policy of at least
p=none. - Marketing one-click unsubscribe (RFC 8058).
- Spam rate in Google Postmaster Tools below 0.30%, with operators aiming under 0.10%.
Gmail has ramped rejection of non-compliant bulk since November 2025. Microsoft has required the authentication trifecta for high-volume Outlook consumer mail (about 5,000/day) since May 2025. Complaint rate remains the kill switch. Hygiene that only deletes quiet subscribers while leaving a leaky unsubscribe path will still fold the domain.
Placement failures have more causes than a dirty list—see Why emails go to spam. Domain reputation is the asset you are protecting, especially into Q4; that framing lives in Your domain is the product. Black Friday 2026 falls on 27 November. A dirty list plus a seasonal blast is how domains get folded before November, not during it.
Transactional suppression is not list cleaning
Product teams often copy an ESP sunset policy onto receipts. That is the wrong model.
- Transactional: suppress hard-bounced recipients for that message type. Retry or hold soft failures. Never sunset a paying customer because they ignored a newsletter.
- Marketing: verify imports, drop hard failures the same day, re-engage, then suppress the remainder before a blast.
If you still send through Amazon SES, SES already maintains account, configuration-set, and tenant suppression layers. Use them; do not reinvent a third copy in your app without reading Amazon SES suppression lists. ArawaMail does not implement that three-layer SES model.
Keeping inboxes and product email coherent on the company domain is covered in Keep inboxes and product email on one domain. Two sending vendors on one From address create a different hygiene failure—events land in two logs—and is covered in Two vendors, one From address.
What ArawaMail does and does not do
ArawaMail is an operational platform for company-managed domains: receiving, mailboxes, and an HTTP send API on an exact Cloudflare zone. Docs for overview, domain onboarding, and enable sending cover identity and from checks. They do not clean recipient lists.
Outgoing webhooks push inbound mailbox mail to your systems as JSON. They are not bounce webhooks for campaign hygiene. Do not treat them as SES event notifications.
There is no ArawaMail list-cleaner, segment builder, sunset policy, or suppression-list UI. You own recipient quality in your application or in the ESP that sends marketing. The send API will not verify that an address can receive mail before you hand it a recipient.
Product sending itself is on the transactional email page.
How we analyzed this
Provider thresholds above summarize Gmail sender guidelines, Yahoo bulk-sender expectations, Microsoft high-volume Outlook authentication rules, and 2026 operator practice on bounce rates. They are not a single official RFC and not an ArawaMail SLA. Product claims are limited to what ArawaMail documents: no list product, no recipient verification at send, outgoing webhooks for inbound mailbox mail only. The Gmail Verified Sender Program that starts 8 September 2026 for eligible US political committees is out of scope.
A practical week-one pass
- Today: export hard bounces, complaints, and unsubscribes. Suppress them on every marketing send. Confirm transactional sends use a separate suppression rule that only covers hard failures.
- This week: inspect soft-bounce repeats (3–5 consecutive). Verify new imports before the next campaign. Do not blast last year’s scraped event list.
- Before the next seasonal send: run a two-step re-engagement on marketing names silent for 90–180 days, then suppress the remainder. Leave transactional recipients alone.
Good marketing: verify imports, drop hard bounces the same day, re-engage, suppress the silent remainder. Good transactional: suppress hard-bounced recipients for that message type; keep sending invoices. Bad: blasting a scraped list the week before Black Friday. Bad: deleting every address that did not click in 30 days on a monthly newsletter. Bad: mixing newsletter complaints onto the same From domain as password resets.
FAQ
What should I delete today versus watch for a week?
Today: hard bounces, complainers, completed unsubscribes, known traps. Watch: repeated soft bounces and unengaged marketing names that have not had a re-engagement attempt.
Will removing unengaged subscribers hurt revenue?
It can, if you sunset recent buyers or transactional recipients. Sunset marketing names after a re-permission pass. Keep invoices and resets on living customer addresses.
Is a verifier enough?
No. Verification catches many invalids. It does not measure engagement or complaints.
Should transactional mail use the same hygiene rules as newsletters?
No. Transactional streams suppress hard failures. They do not sunset a customer who ignored a newsletter.
Does ArawaMail clean my list?
No. ArawaMail hosts mailboxes and a send API. Recipient quality lives in your app or ESP.
When is a re-engagement campaign better than deletion?
When the list is young, the send cadence is monthly or slower, or pixel-off readers are likely. Re-permission first; suppress the remainder before a blast.
Does cleaning the list replace one-click unsubscribe?
No. Gmail and Yahoo still expect RFC 8058 on marketing mail. Hygiene lowers bounces; it does not replace the header.