ESP tenant vetting requirements: SendGrid, Mailgun, Amazon SES
If your platform sends email for its own customers, each of these three providers' terms makes you answerable for what those customers send. Here is what each says, in its own words, and the one thing none of them publish.
This is not legal advice. Redoubt Vault is not affiliated with Twilio, SendGrid, Sinch, Mailgun or Amazon Web Services, and nothing here speaks for them. Every quote is from the provider's own published terms, linked where it appears; terms change, so read the current version.
The short version
- All three make the account holder answerable for its customers' sending.
- None of the three publishes a checklist for vetting the businesses you send for. We looked; if one exists, it is not on the pages linked below.
- What they do publish is what they will act on: consent they can ask you to prove, and complaint and bounce rates that trigger a review.
Twilio SendGrid
SendGrid's list of prohibited uses addresses software vendors who send for their own customers directly:
“…your responsibility to adhere to our policies extends to the activity of your customers.” SendGrid: Email Prohibited Content Types and Uses
The Twilio Email Policy (last updated 9 April 2026) applies to “your End Users, and your customers”, requires affirmative consent before sending (with a carve-out for transactional notifications), requires you to keep proof of it, and asks you to use reasonable efforts to detect and remove customers who break it. The Twilio Terms of Service make you “solely responsible for all acts, omissions, and activities of your End Users”.
Mailgun
The Mailgun Terms of Service (last revised 15 February 2025) ask you to “ensure that your own users comply” with its policies. The Acceptable Use Policy (last revised 16 January 2023) goes further:
“You are responsible for violations of this AUP by anyone using your Services with or without your permission.” Mailgun Acceptable Use Policy
It also requires “clear, explicit and provable consent” from every recipient and forbids sending to third-party lists.
Amazon SES
SES has a tenant feature built for exactly this setup, for those “sending emails on behalf of multiple downstream entities”, to “prevent issues with one tenant from affecting others”. It does not move the responsibility:
“As the account owner, it's your responsibility to monitor the reputation metrics of all your tenants…” Amazon SES: tenant management
The SES sending review FAQ publishes its thresholds: a bounce rate of 5% or a complaint rate of 0.1% puts an account under review, and at 10% or 0.5% SES says it “might pause” sending until the cause is fixed. When mail looks unsolicited, it asks how you acquired your list and how your subscribe and unsubscribe processes work.
Why your provider asks
Your provider isn't the villain here. It answers to the people who receive the mail, and it carries every sender on its service, including you. The asking exists because of marketers who will mail anyone, at any cost. Because of them, everyone else has to be able to show their work. Being asked is part of sending at scale; what matters is how long your answer takes.
What that leaves a platform to do
With no published checklist, the practical question is what you could show if asked about one tenant: how its recipients signed up, what they agreed to, and when. The three providers ask it in different words; the answer is the same record.
Redoubt Vault is an API for keeping that record as your tenants' signups happen, and producing it per recipient when asked. It is an account of what your platform told us and when: not a verdict on a tenant, and not a substitute for your provider's own review. It never sits between you and your provider. You can read a sample evidence packet first.
What this can and can't do. It shows what your platform told us, and when, for signups recorded from the day you start. It can't rebuild what was never recorded, it doesn't see your sign-up form, it never sends messages, and it doesn't record an IP address. It doesn't show that a person clicked. And nobody can promise your provider will accept an answer.
Make a key and record your first consent event
Or read the API reference first. Pricing is on one page.
What this is based on
- SendGrid: Email Prohibited Content Types and Uses: for software vendors, “your responsibility to adhere to our policies extends to the activity of your customers”.
- Twilio Email Policy, last updated 9 April 2026: it applies to “your End Users, and your customers”.
- Twilio Terms of Service: “solely responsible for all acts, omissions, and activities of your End Users”.
- Mailgun Terms of Service, last revised 15 February 2025: “ensure that your own users comply”.
- Mailgun Acceptable Use Policy, last revised 16 January 2023: “You are responsible for violations of this AUP by anyone using your Services with or without your permission”, and “clear, explicit and provable consent”.
- Amazon SES: tenant management: “As the account owner, it's your responsibility to monitor the reputation metrics of all your tenants”.
- Amazon SES sending review FAQ: “If your complaint rate is 0.1% or greater, we'll place your account under review”, and at higher rates SES “might pause” sending.
Related
- A story: a recipient escalated a complaint, and your email provider wants to know how you got their address
- When you're asked to prove someone opted in: all the stories
- Your email provider asked for your tenants' consent records
- CAN-SPAM when your tenants send the email
Last checked against the sources below: 6 October 2026.