Recognize the incident
Use timestamps, queue IDs, remote responses, source IP, VMTA, sender domain and message class to establish the failure boundary. Avoid reacting to one isolated delivery attempt.
Correlate the response with source IP, complaint activity, new-domain changes, authentication, traffic spikes and recent list acquisition.
Immediate controls
- Reduce or pause affected bulk traffic
- Protect high-engagement and transactional streams
- Remove obvious low-quality segments
- Verify SNDS/JMRP and authentication telemetry
Recovery
Resume with the cleanest engaged recipients and gradual volume. A sudden return to previous volume can reset recovery progress.
Operational rule: collect evidence before changing policy, make one controlled change, verify the result, and retain a rollback path.