Your email provider asked for your tenants' consent records
If you run a platform that sends email for your own customers, your email provider can ask you to show how your tenants' recipients opted in. This page sets out what Bird, Mailchimp, Mailgun, Mailjet, SendGrid and Amazon SES each say, in their own published terms, they can ask you for, and what a consent record can and cannot show.
This is not legal advice, and it is not a statement of any provider's internal review process. Every quote below is from that provider's own published terms, linked where it appears. Read the current version before you reply.
What each provider says it can ask for
Twilio SendGrid. The Twilio Email Policy requires affirmative consent before sending, apart from transactional emails. It requires you to keep proof, and says what to produce when asked:
“Upon written request from Twilio, you must promptly provide proof of a recipient’s affirmative consent and the date and the method through which that recipient’s email address was obtained.” Twilio Email Policy, last updated 9 April 2026
The same policy says you are required to “retain proof of all affirmative consents” obtained from recipients, at least until the recipient withdraws, and that consent is “not transferable to your affiliates or any other party”. For a platform that matters: your own customers' consent to hear from you does not cover the lists your tenants send to.
Bird. Bird's Acceptable Use Policy reserves the right to ask for opt-in proof, and is the one policy read for this page that puts a time on the answer:
“If you fail to provide evidence of confirmation that your recipients have opted-in for receiving these messages within twenty-four (24) hours from the time of our request, we reserve the right to suspend or deactivate your account.” Bird Acceptable Use Policy, last updated 19 June 2025
Mailgun and Mailjet. Both publish the same Acceptable Use Policy wording. They ask that you can provide, for the addresses you have sent to, “when and how the email address or telephone number was collected”, and the policy says what you show “must be provided in the event of an escalated abuse complaint”. It also allows sending only to recipients who have given “clear, explicit and provable consent”.
Mailgun Acceptable Use Policy and Mailjet sending policy, both last revised 16 January 2023
Mailchimp. Its Acceptable Use Policy puts the requirement on the sender:
“You must be able to point to an opt-in form or show other evidence of consent for any commercial or marketing email you send.” Mailchimp Acceptable Use Policy, updated 26 September 2025
Amazon SES. When SES reviews an account over mail that looks unsolicited, its own FAQ lists the questions it asks — including this one:
“You should explain how you acquired your mailing list.” Amazon SES sending review FAQ
The same FAQ asks how your subscribe and unsubscribe processes work, with the links. It asks you to explain how addresses were acquired; it does not say it requires a record per recipient.
Deadlines
Bird's policy gives twenty-four (24) hours, quoted above. Twilio's email policy says “promptly”, with no number. None of the other policies read here states a deadline. How long a reply is allowed is something to ask your provider, not to assume.
Why your provider asks
Your provider isn't the villain here. It answers to the people who receive the mail, and it carries every sender on its service, including you. The asking exists because of marketers who will mail anyone, at any cost. Because of them, everyone else has to be able to show their work. Being asked is part of sending at scale; what matters is how long your answer takes.
What an answer for one recipient contains
Between them, the policies above ask for these things about one recipient:
- The date, and the method: SendGrid asks for “the date and the method through which that recipient’s email address was obtained”.
- How the address was collected, and when: Mailgun and Mailjet ask for “when and how the email address or telephone number was collected”.
- The form: Mailchimp asks you to “point to an opt-in form or show other evidence of consent”.
- Whether they confirmed: Bird asks for “evidence of confirmation that your recipients have opted-in for receiving these messages”.
- Whose permission it was: consent is “not transferable to your affiliates or any other party”, so the answer names the tenant that asked, not your platform in general.
We also keep the exact opt-in wording each recipient was shown. None of the policies read here asks for the wording itself; we keep it because a date and a method alone don't show what the person was asked to agree to.
What none of them asks for
None of the email policies read for this page asks for the signup IP address. That is a finding from reading them on 6 October 2026, not a feature or a promise. The closest is “when and how”, which a timestamp and the wording answer. Redoubt Vault does not record an IP address.
What a consent record can show, and what it cannot
Redoubt Vault is an API that records these facts as your tenants' signups happen, and hands you a packet per recipient when you are asked. Each packet says how every event reached us: reported as it happened, reported late, or imported from your own records with the name of the person who vouches for it. It holds the opt-in wording by its SHA-256 hash, so anyone can check it has not changed.
What this can and can't do. It shows what your platform told us, and when, for signups recorded from the day you start. It doesn't see your sign-up form, it never sends messages, and it can't prove consent it never recorded. It can't rebuild what was never recorded. It doesn't record an IP address. It doesn't show that a person clicked. It is not legal advice, and nobody can promise a provider will accept an answer.
You can read a sample evidence packet, including its “what this record does not show” section, before signing up for anything. Redoubt Vault never sits between you and your provider.
Make a key and record your first consent event
Or read the API reference first. Pricing is on one page.
What this is based on
- Twilio Email Policy (SendGrid), last updated 9 April 2026: on written request, “you must promptly provide proof of a recipient's affirmative consent and the date and the method through which that recipient's email address was obtained”; sender must “retain proof of all affirmative consents”.
- Bird Acceptable Use Policy, last updated 19 June 2025: “you agree to our right to request opt-in proof”; “evidence of confirmation that your recipients have opted-in for receiving these messages”, and “within twenty-four (24) hours from the time of our request, we reserve the right to suspend or deactivate your account.”
- Mailgun Acceptable Use Policy, last revised 16 January 2023: “clear, explicit and provable consent”, “when and how the email address or telephone number was collected”, which “must be provided in the event of an escalated abuse complaint”.
- Mailjet sending policy, last revised 16 January 2023: the same wording, “when and how the email address or telephone number was collected” and “must be provided in the event of an escalated abuse complaint”.
- Mailchimp Acceptable Use Policy, updated 26 September 2025: “point to an opt-in form or show other evidence of consent”.
- Amazon SES sending review FAQ: “You should explain how you acquired your mailing list”.
Related
- A story: a recipient escalated a complaint, and your email provider wants to know how you got their address
- When you're asked to prove someone opted in: all the stories
- ESP tenant vetting requirements: SendGrid, Mailgun, Amazon SES
- CAN-SPAM when your tenants send the email
Last checked against the sources below: 6 October 2026. Redoubt Vault is not affiliated with Twilio, SendGrid, Bird, Sinch, Mailgun, Mailjet, Mailchimp or Amazon Web Services.