Enforcement
Sending
Releasing an approved notice: the send path in order, the sender identity it leaves from, the delivery states, and what sent, delivered and delivery unknown each mean.
Last revised
An approved notice is released by a Brand Admin, with a fresh second factor, and leaves from a sender identity your workspace configured and verified. It never comes from a MapProtector address.
The sender identity
Under Settings › Enforcement › Sender identity, a Brand Admin sets the display name, the From address and the reply-to, and takes the address through the mail provider’s verification. The screen shows the From header as a seller sees it. A notice can leave only from a verified sender; the absence of one is a blocker, not an omission. Addresses on MapProtector’s own domain are refused.
- Attribution. The seller reads a notice from your brand about your policy.
- Replies. The seller’s answer arrives at your reply-to, where your compliance team sees it.
- Deliverability. Complaints about enforcement mail land on your sender’s reputation, not on the one that carries your password resets.
Releasing
- Open the approved notice and choose Queue or Send. Both require a fresh second factor and an explicit confirmation, like approval.
- On the send path the product, in order: claims the notice so no second worker can take it; re-runs the full eligibility gate; re-validates the approval against the current state; re-checks the seller contact against the suppression list; opens a delivery record whose key refuses a duplicate; and only then calls the mail provider.
- A notice blocked at any of these steps returns to ready for review with the reason. Nothing is sent.
Delivery states
| State | Meaning |
|---|---|
| Sent | The mail provider accepted the message. Nothing more. |
| Delivered | The provider reported that the recipient’s mail server accepted it. Only a provider callback moves a notice here. |
| Failed | The provider refused it, or the address bounced. The contact is marked accordingly. |
| Delivery unknown | The provider did not answer in time. The message may or may not have gone. Nothing retries it automatically — a person resolves it against the provider’s own records. |
One approved notice sends once
The delivery record’s key is unique to the notice and its approval. A worker that believes it should send again, a redelivered queue message or a double click all converge on the one record. A re-approval after an invalidation produces a new key — correct, because that is a different authorized send.
Attachments
Notices do not carry attachments in this release. A notice cites the case and the sealed package by reference; the package itself is presented separately, see Downloads.
Outside production
Anything sent from an environment other than production carries a test marker in its subject, so a rehearsal can never be mistaken for a notice.