This article explains the requirements that newsletters must meet in order to continue being sent via Hornetsecurity relays.
The article is intended for administrators and partners who want to send mass emails, such as newsletters or marketing campaigns, through the Hornetsecurity infrastructure.
Compliance with these requirements protects all Hornetsecurity customers. If the standards are not met, Hornetsecurity relays may be placed on blacklists. This can lead to service restrictions for all users.
Mandatory Requirements
The following mandatory requirements apply to sending newsletters via Hornetsecurity relays:
| Area | Requirement |
|---|---|
| Opt-In | Verifiable consent of the recipient |
| Opt-Out | Clearly visible unsubscribe link |
| Opt-Out | Automated unsubscription without manual data entry |
| Opt-Out | Permanent removal of unsubscribed recipients |
| Technology | Compliance with relay connection limits |
Opt-In
An opt-in must have taken place before a recipient is added to the newsletter distribution list.
The recipient must have actively and verifiably signed up for the newsletter, for example, via a double opt-in process.
A mere business relationship is not sufficient as opt-in.
Hornetsecurity follows the guidelines of the eco – Association of the Internet Industry e. V. as well as the German legal framework as a minimum standard. If stricter regulations apply in the sender’s country of origin, these must also be met.
Opt-Out
Every newsletter must provide the recipient with an easy way to unsubscribe.
The unsubscription must meet the following requirements:
- The unsubscribe link, for example “Unsubscribe” or “Opt-out”, is clearly visible and easily accessible.
- The unsubscription is fully or semi-automated.
- The recipient does not have to write a manual email or contact customer service.
- The unsubscription works independently of the device used.
- The unsubscription is performed via a unique key in the URL.
- The recipient does not have to enter an email address or other personal data.
- Unsubscribed recipients are permanently removed from the distribution list.
Technical Relay Limits
The following technical limits apply when sending via Hornetsecurity relays:
| Parameter | Limit |
| Relay Address | [YOUR-DOMAIN].relay.cloud-security.net |
| Ports |
25 or 587
|
| Maximum Connections | 20 per 1 minute per relay server |
| Maximum Emails per Connection | 10 per 1 minute per relay server |
| Available Relay Servers | 6 via DNS load balancing |
| Theoretical Maximum Throughput | 3600 emails per minute |
Configure your mail server so that there is a pause of 2 to 3 seconds between new connections. This gives the load balancer enough time to release the next relay node.
Due to varying load balancing, a maximum throughput of 3,600 emails per minute should not be exceeded.
For temporary error messages, for example 4xx codes, a retry interval of a maximum of 1 minute should be configured.
In Case of Non-Compliance
If the requirements are not met, Hornetsecurity may restrict or block sending via the relays.
| Step | Action | Timeframe |
| 1 | Notification of the customer about the violation | Immediately |
| 2 | Deadline to resolve the issue | 4 weeks after notification |
| 3 | Blocking of relay access | After deadline expires |
| ⚠️ | Immediate blocking in case of severe service restrictions or risks to other Hornetsecurity customers | Possible without notice |
Recommendations
If possible, use professional newsletter software or a specialized newsletter service provider. Such solutions typically support opt-in, opt-out, bounce management, and unsubscribe mechanisms.
Also check the following points:
- The SPF record includes the Hornetsecurity relay IPs.
- Invalid recipient addresses are automatically removed from the distribution list.
- A List-Unsubscribe header is set in the newsletter emails.
- The sending rate is configured to comply with relay limits.
More Information
Further information can be found in the following articles and documents: