Limiting the Blast Radius with a Dedicated Sending Subdomain

Megargy sends newsletters from an address such as update@newsletter.acme.com rather than newsletter@acme.com. The dedicated newsletter subdomain limits the permission you give us to send email on your behalf, while update@newsletter.acme.com provides a simple, consistent sender identity for the newsletter.

In examples like this, acme.com is a convenient shorthand for any company’s domain name. In this context, it means your custom domain. If your organisation uses example.com, for instance, the corresponding newsletter address would be update@newsletter.example.com.

Why not newsletter@acme.com?

At first sight, newsletter@acme.com seems like the natural address for a company newsletter.

The problem is that authorising a newsletter provider to send from your core acme.com domain can give that provider the technical ability to send using other addresses on the same domain — not just newsletter@acme.com, but potentially addresses such as accounts@acme.com, support@acme.com or ceo@acme.com.

That is a much broader permission than a newsletter service needs.

Instead, Megargy only asks for permission to send from a specific subdomain:

newsletter.acme.com

The DNS records you add authorise our email sending service for newsletter.acme.com, rather than for your core company domain. Megargy can therefore send as update@newsletter.acme.com, but it cannot use that permission to send as accounts@acme.com or ceo@acme.com.

This deliberately limits the blast radius. If Megargy’s systems were ever compromised, the sending authority you had granted us would remain confined to your newsletter subdomain rather than extending across your organisation’s primary email domain.

A sender identity does not need to be a mailbox

A separate point, unrelated to the use of a subdomain, is that the address shown as the sender of an email does not necessarily need to be an actual mailbox.

update@newsletter.acme.com does not need an inbox, a password or a person behind it. You do not need to create a new Microsoft 365 or Google Workspace user for it, choose the address of a particular employee, or reuse an existing company group or alias.

It is simply the sender identity used for the newsletter.

That distinction is useful because the address can describe what the email is — an update from your newsletter — without having to correspond to a real person or an existing mailbox in your organisation.