Your preparation
0 of 0 safeguards readyMake the next decision with evidence
Preserve lawful subscriber data and sending evidence, restore customer communication, and resolve the provider concern without evading enforcement.
Capture before evidence disappears
- Save closure notices, policy reason, account and list IDs, support cases, campaigns, templates, automations, domains, integrations, and billing.
- Export subscribers with consent source and time, suppression, unsubscribe, bounce, complaint, segment, custom fields, and engagement where permitted.
- Preserve SPF, DKIM, DMARC, sending-domain reputation, complaint rates, acquisition sources, and recent content.
Decisions that change the response
| Question | Act when | Action |
|---|---|---|
| Appeal or migrate? | The provider allegation can be answered with consent and campaign evidence versus a valid policy breach. | Appeal factually; migrate only lawful contacts and honor every suppression. |
| Send from another system? | The new provider approves the use case, domains authenticate, and suppression and consent data are intact. | Warm gradually; never blast the full list to escape a closure. |
Proof that recovery worked
- Subscriber counts, consent, suppression, segments, and automation state reconcile with the verified export.
- Authentication passes and complaints, bounces, and unsubscribes process correctly on the approved route.
- No unsubscribed, suppressed, purchased, or undocumented contact is reintroduced.
Controls to put in place
- Export subscribers, consent, suppressions, templates, and automation definitions regularly.
- Use confirmed acquisition records, visible unsubscribe, list hygiene, and separate transactional sending.
- Keep domains, DNS, brand assets, and customer communication channels independent of one vendor.
Import a synthetic list with consent and suppressions into a blank provider account. Rebuild one automation, authenticate a subdomain, send to seed inboxes, and prove suppressions hold.
Use provider compliance support and privacy counsel when consent, complaints, regulated marketing, data return, or account termination is disputed.
What this means
The provider may have detected abuse, a compromised account, billing trouble, an unusual list import, policy violations, or deliverability risk. Do not create a new account and upload the same list before you understand the cause.
Your subscriber list is not enough by itself. A safe migration also needs consent status, unsubscribes, suppression records, templates, sending-domain configuration, and recent campaign history.
Warning signs
- You cannot sign in or send.
- The provider asks for a compliance, identity, billing, or security review.
- A campaign is stopped after unusual complaints or bounces.
- Subscribers report spam you did not send.
- API keys, integrations, owners, or sending domains changed unexpectedly.
Recover now
First 15 minutes
- Read the provider notice carefully. Record the case number, stated reason, deadline, affected audience, and requested evidence.
- Secure the primary email and provider account. Reset access from a trusted device, enable 2FA, remove unknown users, and revoke old API keys.
- Pause connected automations. Stop forms, webhooks, scheduled sends, imports, and integrations that may keep creating the problem.
- Open one factual appeal. Explain how contacts joined, what changed recently, and what you have already contained.
- Do not email the list elsewhere yet. An incomplete export can omit unsubscribes or consent evidence.
Today
- Export every available audience, consent field, subscription status, suppression list, template, campaign, automation, and report.
- Compare recent imports and sends with signup records. Remove contacts without a clear permission trail.
- Inspect the account for unauthorized campaigns, API use, users, integrations, and domain changes.
- Prepare a plain status update on your website or social account if a promised send is delayed.
- If the provider restores access, send a small monitored campaign before resuming normal volume.
- If migration is required, import subscribed contacts and suppression data separately. Configure SPF, DKIM, DMARC, unsubscribe handling, and a gradual warm-up before a large send.
Verify recovery
- The provider confirms the account and sending function are active.
- Unknown users, API keys, campaigns, and integrations are gone.
- Subscribed, unsubscribed, cleaned, and suppressed contacts remain correctly separated.
- A small test reaches major mailbox providers without unusual complaints or bounces.
- Signup forms, consent records, unsubscribe links, and sending-domain authentication work.
Prepare now
Portability
- Audience data is exported regularly with consent and subscription status.
- Templates and essential campaign copy are stored outside the provider.
- Suppression and unsubscribe records can be migrated safely.
- Signup source, time, and permission evidence are retained.
Access and reputation
- Owners use named accounts, strong 2FA, and reviewed API keys.
- SPF, DKIM, and DMARC are documented and monitored.
- Imports require a clear source and permission check.
- Complaint, bounce, and abuse alerts go to a monitored address.
Practice
- A recent export can be opened and explains which contacts may legally receive email.
Common mistakes
- Uploading only active email addresses to a new provider. Missing suppressions can cause illegal or unwanted mail.
- Sending the full list immediately. A cold domain and sudden volume can damage deliverability.
- Blaming the provider before checking compromise. An attacker may have sent the abusive campaign.
- Keeping templates only inside the tool. You lose both audience and production assets together.
- Importing an old list without consent evidence. Age is not permission.
Sources
- Mailchimp: Export and back up account data
- Mailchimp: View or export contacts
- Mailchimp: Compromised accounts