All skills
resend avatar

/email-best-practices

@376d1c3 official
by resendresend/resend-skills193 stars
28

Use when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM, GDPR, CASL), handling webhooks, retry logic, making emails accessible (alt text, headings, contrast, screen readers), or deciding transactional vs marketing.

Use this Skill: https://skilld.dev/gh/resend/resend-skills/email-best-practices

This session only. Nothing lands on disk.

referencescompliance.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Email Compliance

Legal requirements for email by jurisdiction. Not legal advice—consult an attorney for your specific situation.

Quick Reference

Law Region Key Requirement Penalty
CAN-SPAM US Opt-out mechanism, physical address $53k/email
GDPR EU Explicit opt-in consent €20M or 4% revenue
CASL Canada Express consent, opt-out mechanism $1M (individual) to $10M (organization) CAD

CAN-SPAM (United States)

Requirements:

  • Accurate header info (From, To, Reply-To)
  • Non-deceptive subject lines
  • Physical mailing address in every email
  • Clear opt-out mechanism
  • Honor opt-out within 10 business days

Transactional emails: Can send without opt-in if related to a transaction and not promotional.

GDPR (European Union)

Requirements:

  • Explicit opt-in consent (not pre-checked boxes)
  • Consent must be freely given, specific, informed
  • Easy to withdraw consent (as easy as giving it)
  • Right to access data and deletion ("right to be forgotten")
  • Process unsubscribe immediately

Consent records: Document who, when, how, and what they consented to.

Transactional emails: Can send based on contract fulfillment or legitimate interest.

CASL (Canada)

Consent types:

  • Express consent: Explicit opt-in (ideal)
  • Implied consent: Existing business relationship (2 years) or inquiry (6 months)

Requirements:

  • Clear sender identification that will be valid for 60 days after send
  • Unsubscribe functional for 60 days after send
  • Process unsubscribe no later than 10 business days
  • Keep consent records 3 years after expiration

Other Regions

Region Law Key Points
Australia Spam Act 2003 Consent required, honor unsubscribe within 5 days
UK PECR + GDPR Same as GDPR
Brazil LGPD Similar to GDPR, explicit consent for marketing

Unsubscribe Requirements Summary

Law Timing Notes
CAN-SPAM 10 business days Must work 30 days after send
GDPR Immediately Must be as easy as opting in
CASL 10 business days Must work 60 days after send

Universal best practices: Prominent link, one-click when possible, no login required, free, confirm action.

List-Unsubscribe Header (Required for Bulk Senders)

Gmail, Yahoo, and Microsoft require List-Unsubscribe headers. Without them, bulk emails may be rejected or spam-filtered.

Required headers:

headers: {
  'List-Unsubscribe': '<https://example.com/unsubscribe>',
  'List-Unsubscribe-Post': 'List-Unsubscribe=One-Click',
}

Your unsubscribe endpoint must:

  • Accept POST requests — return 200 or 202 with a blank page
  • Display standard unsubscribe page for GET requests
  • Stop sending within 48 hours of the request

Managing preferences vs Unsubscribe from all

Most legistlations require a one-click unsubscribe. Managing preferences is a nice-to-have and can lead to lower unsubscribe rate but doesn't replace Unsubscribe. If possible, offer both.

Consent Management

Record:

  • Email address
  • Date/time of consent
  • Method (form, checkbox)
  • What they consented to
  • Source (which page/form)

Storage: Database with timestamps, audit trail of changes, link to user account.

Data Retention

Law Requirement
GDPR Keep only as long as necessary, delete when no longer needed
CASL Keep consent records 3 years after expiration

Best practice: Have clear retention policy, honor deletion requests promptly, review and clean regularly.

Privacy Policy Must Include

  • What data you collect
  • How you use data
  • Who you share data with
  • User rights (access, deletion)
  • How to contact about privacy

International Sending

Best practice: Follow the most restrictive requirements (usually GDPR) to ensure compliance across all regions.

Related

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is a comprehensive knowledge base for email best practices, including deliverability, accessibility, compliance, and reliability. It contains educational content and code examples for developers. No malicious patterns or security risks were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 376d1c3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 months ago
Other metadata
metadata
{
  "author": "Resend",
  "version": "1.0.2",
  "homepage": "https://resend.com/agent-skills",
  "source": "https://github.com/resend/email-best-practices",
  "openclaw": {
    "links": {
      "repository": "https://github.com/resend/email-best-practices",
      "documentation": "https://resend.com/docs/email-best-practices-skill"
    }
  }
}
  • email
  • transactional
  • marketing
  • deliverability
  • spf-dkim-dmarc
  • compliance
  • webhooks
  • accessibility
  • list-management
  • resend

README badge

README badge for resend/resend-skills/email-best-practices

Provides decision trees and reference guides for deliverability (SPF/DKIM/DMARC), compliance (CAN-SPAM/GDPR/CASL), transactional vs marketing email classification, webhook handling, list management, and accessibility (alt text, headings, contrast). Targets teams building email features with Resend or similar transactional email APIs.

Generated from the current SKILL.md.

Does this skill cover setting up SPF, DKIM, and DMARC?
Yes. The Deliverability section covers authentication setup and is the first step recommended for fixing spam issues, as unauthenticated emails are commonly rejected by Gmail and Yahoo.
What compliance standards does this skill address?
It covers CAN-SPAM, GDPR, and CASL requirements, with a dedicated Compliance section for legal obligations around email capture and marketing sends.
Does this skill include guidance on making emails accessible?
Yes. The Accessibility section covers screen reader support, alt text, headings, contrast requirements, and proper HTML structure for inclusive email design.
How does this skill handle bounces and list hygiene?
The List Management section covers bounce handling, suppression list updates, and list hygiene jobs. Webhooks & Events section covers processing delivery events to track bounces and complaints.
Does this skill cover retry logic and idempotent sending?
Yes. The Sending Reliability section covers retry strategy, idempotency, and error handling for production-ready email sending.

Generated from the current SKILL.md. These answers refresh after source changes.