Blog

How the CSA IP Platform Certification Is Evolving to Meet the Requirements of the Modern Email Ecosystem

For over two decades, the Certified Senders Alliance (CSA) has had one clear objective: to strengthen trust and quality across the entire email ecosystem. What started as a joint project with mailbox providers and a few basic requirements has grown into an internationally recognised certification programme for professional email delivery platforms.

The underlying principle has remained unchanged. Trust is built on shared standards, transparent processes, and clearly defined quality requirements. However, the email ecosystem continues to evolve. Modern sending architectures, growing security requirements and increasing expectations among mailbox providers for secure message delivery mean the certification programme must constantly adapt and evolve.

The revised CSA IP Platform Certification is therefore not a complete redesign. Instead, we’ve carefully adapted it to meet the current requirements of professional email delivery platforms. Existing criteria have been refined, responsibilities have been defined more clearly, and the framework has been restructured to make it easier to navigate.

The sending platform as the anchor of trust

Professional email delivery platforms provide the technical foundation for secure, high-quality email delivery for many organisations. Companies rely on their infrastructure and technical expertise, while mailbox providers expect these platforms to protect their systems effectively against abuse and to provide their customers with the necessary tools to adhere to email best practices.

This principle is at the heart of the updated IP Platform Certification. Going forward, the certification will focus more closely on areas that a sending platform can directly influence and be reasonably held responsible for, including infrastructure security, authentication, abuse prevention, and providing essential platform functionality.

Responsibility for email content, proof of consent and compliance with country-specific legal requirements, however, remains with the sender (brand). This clear allocation of responsibilities creates greater transparency while also laying the foundation for the future CSA Domain Certification, which will specifically address the responsibilities of senders (brands) and sending domains.

Proven requirements remain – the structure becomes clearer

The good news for organisations that are already certified is that the vast majority of the existing requirements remain unchanged.

Established technical criteria such as RFC compliance, authentication, TLS, bounce handling and established reputation metrics have not been altered. Instead, they have been reorganised into a new, practice-oriented structure:

  • Trust & Transparency
  • Abuse Prevention
  • Authentication
  • List Hygiene
  • Reputation & Performance Indicators
  • Recommended Criteria

This new structure makes the certification easier to navigate and more accurately reflects the practical responsibilities of modern email delivery platforms.

The Core Requirements remain the foundation

The existing Core Requirements also remain fully intact. They have been incorporated unchanged into the participation conditions, where they continue to form the fundamental technical and commercial prerequisites for IP Platform Certification.

The technical foundation continues to include:

  • Declaration of all sending IP addresses
  • Correctly configured reverse DNS, including a fully qualified domain name (FQDN)
  • Proof of responsibility for the sending IP address by means of either a DNS token or a WHOIS entry

These technical requirements are complemented by the following commercial requirements:

  • Sending exclusively commercial bulk email
  • Responsibility for compliance with the CSA certification criteria
  • A commitment to complying with all applicable legal requirements

In short, the foundation remains unchanged. Only its position within the overall certification framework has been revised.

More security, greater transparency

Many of the requirements remain unchanged. However, where expectations of professional email delivery platforms have evolved over time, the criteria have been specifically expanded.

Corporate transparency

Certified companies will now be required to provide clearly identifiable corporate information on their website:

  • Postal address
  • Digital contact option (email or contact form)
  • Easily accessible privacy policy

For most companies, these are already standard practice. As part of the certification, however, these requirements reinforce the importance of transparency and accountability in building trust.

Protecting the sending platform against abuse

Sending platforms are a central component of the email ecosystem and, as a result, an attractive target for abuse. The certification has therefore been expanded to include requirements relating to active platform governance and the protection of customer accounts.

The CSA deliberately does not prescribe specific technical solutions. What matters is that effective measures are in place to prevent abuse and make unauthorised access to customer accounts more difficult. How these measures are implemented remains at the discretion of the certified company.

Possible measures include:

  • Customer verification
  • Sending limits
  • Login monitoring
  • Two-factor authentication
  • Automated detection of unusual sending patterns

Measurable quality instead of isolated assessments

A consistent and correctly configured DKIM signature is now a key trust factor for mailbox providers and a fundamental prerequisite for secure email delivery. The CSA has therefore introduced an additional performance indicator to its certification: the DKIM Missing Rate.

Over a rolling seven-day period, no more than three per cent of emails may lack a valid DKIM signature.

This assessment is therefore based not on individual incidents but on real-world data collected over an extended period. This enables an objective assessment of a sending platform’s authentication quality and provides a fair and measurable way of evaluating quality.

From implementation to the provision of core platform functions

One of the most significant conceptual changes in the revised certification concerns the responsibility of the sending platform.

Whereas individual criteria previously assessed the implementation of specific best practices in the emails being sent, the focus will now shift more strongly towards the provision of core functions within the sending platform itself. In doing so, the certification reflects the platform’s actual area of responsibility: providing the technical prerequisites for high-quality email delivery and equipping customers with the tools they need.

This principle is reflected, among other things, in the following requirements:

Opt-out functionality

Sending platforms must provide their customers with the ability to include a functioning unsubscribe link in emails. The certification assesses the provision of this functionality – in other words, the technical capability required to implement a simple and reliable opt-out.

List-Unsubscribe and List-Help

The focus has also shifted with regard to the List-Unsubscribe and List-Help headers. In future, the certification will no longer assess whether either of these headers is actually included in every email sent. Instead, it will assess whether the sending platform provides its customers with the corresponding functionality, including the required technical characteristics.

Opt-out: A key enhancement of platform responsibility

One of the most significant changes to the revised IP Platform Certification concerns the sending platform’s responsibility for consent management.

Previously, the certification assessed the platform’s responsibility for legally compliant opt-in procedures. Following the revision, this focus has been aligned with the platform’s actual sphere of influence. In future, the certified company must ensure that every commercial, non-transactional email sent via the certified infrastructure includes a functioning unsubscribe option – either by means of an unsubscribe link or, alternatively, an unsubscribe email address. Both options meet the certification requirements.

Unlike the platform functions described above, simply providing the functionality is not sufficient in this case. The sending platform also bears responsibility for ensuring that this functionality is actually present in every relevant email.

Greater transparency and traceability in the complaints procedure

The complaints procedure has also been revised. While the underlying principles remain unchanged, the structure and presentation have been fundamentally redesigned to make the entire process more transparent and easier to follow.

The new structure is based on two complementary documents:

  • The Rules of Procedure describe the overall complaints process – from the parties involved and their responsibilities through to the possible measures.
  • The Annex supplements the Rules of Procedure with specific violations, thresholds, measures, deadlines and standard timeframes. This enables certified companies to understand at any time what consequences a particular violation will entail.

Clear Stages – Transparent Decisions

The escalation model has also been further developed.

The term “notice” takes on a new meaning in this context. Whilst it previously referred to what will in future be termed a “warning”, a notice now serves exclusively as an information measure. It alerts companies at an early stage to anomalies or best practices – without any immediate formal consequences. These include, for example, criteria without an individual escalation procedure or matters outside the scope of the CSA criteria, such as individual complaints regarding consent.

If there is an actual breach of the certification criteria, the formal escalation procedure is triggered. It begins with a documented warning and initially gives the company the opportunity to rectify the identified breach within a defined timeframe.

In the event of repeated or serious breaches, this may result in the temporary suspension of individual IP addresses or – in severe cases – the revocation of the entire certification. The aim remains to ensure a transparent, traceable and proportionate procedure that provides clear guidance to both certified companies and mailbox providers.

Promoting quality – supporting responsibility through partnership

CSA certification is intended as a quality standard for professional email sending platforms. Companies that seek certification consciously invest time and resources in continuously developing their processes and meeting the high requirements of the certification.

The CSA will continue to deal with breaches of the certification criteria rigorously – through notices, warnings, suspensions and, in exceptional cases, exclusion from the certification programme.

What’s new, however, is the approach to communicating these measures. In future, warnings and temporary suspensions will no longer be published publicly.

In doing so, the CSA emphasises the collaborative nature of its certification programme. The aim is to support certified companies on their journey towards consistently high quality and to promote continuous improvement. Consistent quality assurance remains just as much a given as a trusting and constructive dialogue.

Conclusion

The further development of the CSA IP Platform Certification is far more than a mere update of individual criteria. It takes account of changes in the email ecosystem and is consistently aligned with the actual responsibilities of modern email platforms.

Proven requirements are retained, new criteria address current developments, and the set of rules provides greater clarity – both in terms of the certification criteria and the complaints procedure.

In this way, the CSA remains true to its original mission: to sustainably strengthen trust, security and quality in the email ecosystem for all stakeholders. Particularly in a market that is constantly evolving, effective self-regulation remains a crucial building block for trust-based cooperation between sending platforms, email providers and brands.

The full regulations governing the revised CSA IP Platform Certification are available to view on the CSA website. If you have any questions about the changes or the certification process, the CSA team will be happy to assist you at any time.


Related Articles

    Get in touch with us