Written by
Tim Collins
Published on
7 July 2026
There is a design decision buried inside every bulk email platform that almost nobody asks about, and it quietly decides whether your mail reaches the inbox.
It is this: when the platform signs your email, whose key does it sign with?
If the honest answer is "the same one we use for everybody", then your sending reputation is not really yours. You are sharing it with every other customer on the platform, including the ones you would never choose to stand next to.
Here is what that means in practice, and why we built FlipSend differently.
A one-minute refresher on DKIM
DKIM stands for DomainKeys Identified Mail. When an email leaves a properly configured platform, it gets a cryptographic signature attached to the header. That signature is created with a private key held by the sending platform, and it can be checked against a matching public key published in DNS.
The signature does two jobs. It proves the message genuinely came from where it claims to, and it proves nobody tampered with it in transit. Think of it as a wax seal that also carries a return address.
Crucially, inbox providers do not just check that the seal is valid. They remember the seal. Every signing key builds up a reputation over time based on how the mail signed with it behaves: whether people open it, ignore it, delete it, or mark it as spam. Gmail, Outlook and the Australian providers all keep a running score against the signing identity.
That last point is the whole story. If reputation attaches to the signing key, then everyone who signs with the same key shares one reputation.
What "shared DKIM" actually means
A lot of platforms, especially the cheaper self-serve ones, take a shortcut. They set up a single signing domain, something like mail.theplatform.com, generate one DKIM key for it, and sign every customer's email with that same key.
It is easy for them. There is nothing for you to configure, you paste in your list and hit send, and the mail goes out signed and authenticated. On the surface it looks fine.
Underneath, you have just been dropped into a shared pool. Your carefully written, permission-based newsletter is being signed with the exact same key as:
- the customer who uploaded a purchased list of 200,000 scraped addresses
- the one running aggressive cold outreach with no unsubscribe link
- the one whose account got compromised last week and blasted phishing mail before anyone noticed
- and a few thousand senders you will never see and cannot vet
To an inbox provider, all of that mail carries the same seal. It is, as far as the reputation system is concerned, coming from the same sender. You.
What goes wrong, step by step
The failure is not dramatic. Nothing breaks. That is what makes it so hard to diagnose.
Say a handful of senders on the shared key have a bad week. Complaint rates climb, a couple of spam traps get hit, a compromised account fires off a phishing run. The signing key's reputation drops.
Now you send your monthly update. It is clean, wanted, and beautifully behaved. But it is signed with the key that just took the hit. So it lands in Promotions instead of Primary, or in Junk instead of the inbox, or it gets throttled and arrives six hours late.
Your delivery report says 99 per cent delivered. Your open rate is on the floor and you have no idea why, because from where you are standing you did everything right. You did do everything right. You just signed with a key that somebody else damaged.
This is called reputation contagion, and it runs entirely in the background. You never see the sender who caused it, you get no warning, and there is nothing in your own account you can fix, because the problem is not in your account. It is in the shared key you were never told you were using.
The reverse trap is just as real. If you are a careful, high-engagement sender, your good behaviour is being spent propping up the reputation of the worst accounts on the platform. You are subsidising them, and getting a diluted inbox rate in return.
Alignment makes it worse before it makes it better
There is a second layer to this. Inbox providers increasingly care about alignment, which means the domain in your visible "from" address should match the domain that actually signed the message.
On a shared platform, your customers see your name in the from field, but the DKIM signature belongs to the platform's domain, not yours. The two do not line up. Even setting the shared-reputation problem aside, misaligned mail is treated with more suspicion, and a strict DMARC policy on your own domain can reject it outright.
Fixing alignment properly means signing with a key tied to a domain that belongs to your sending stream, not a generic platform domain shared by thousands. Which brings us to how we do it.
Why FlipSend uses three separate signing lanes
We took the view that not all mail is the same, so it should not all share one reputation. FlipSend runs three isolated DKIM signing lanes, each with its own domain and its own key, and mail is routed into the right one based on what it is.
Lane one is for regulated and transactional mail. Healthcare reminders, government notices, education communications, order confirmations, the mail that people expect and want. This lane is kept deliberately clean and its reputation is protected accordingly.
Lane two is for cold B2B outreach. This is legitimate, but it is a fundamentally different risk profile. Cold sending naturally attracts more complaints and more unknowns, so it gets its own key and its own reputation. If a cold campaign has a rough week, it stays contained in this lane. It cannot reach across and drag down someone's appointment reminders.
Lane three is for internal and platform mail. System notifications, password resets, the platform talking to itself. Isolated again, so operational mail never mixes its reputation with customer campaigns.
The point of three keys is not complexity for its own sake. It is a firebreak. When reputations are separated by risk class, a problem in one lane physically cannot spread to another, because they do not share the seal. A cold-outreach stumble cannot touch a hospital's reminders. A compromised account in one lane does not poison the well for everyone else.
That is the exact contagion that a single shared key allows, and separating the keys is what prevents it.
And when you need your reputation entirely your own
Three lanes solve the risk-class problem, but some senders want to go further and stand on nothing but their own name. For those, FlipSend supports fully authenticated sending on your own domain, with DKIM signing aligned to a subdomain you control.
That gives you a reputation that is yours alone. It is not pooled with anyone, not even other customers in the same lane. Your good sending builds your own score, your from address and your signature align cleanly, and a strict DMARC policy on your domain passes instead of fighting you. Setup is guided, and it takes about ten minutes.
The question worth asking any platform
Before you trust a platform with your sender reputation, ask one question: when you sign my mail, is the key shared with your other customers, or is it mine?
If the answer is vague, or if it is "everyone uses the same signing domain", you now know what that costs. Your inbox placement is only ever as good as the worst sender you have been quietly grouped with, and you will never be told who that is.
We built FlipSend so that question has a clean answer. Your mail is signed in a lane matched to what it is, kept apart from unrelated risk, and if you want it, signed on a domain that belongs to you and no one else. All of it runs and stays in Australia.
If you are not sure how your current platform signs your mail, we will check it with you and tell you plainly. It takes about ten minutes and there is nothing to sign.
FlipSend by Flipside Digital. Email, SMS and fax from one platform, built and hosted in Australia.

