What companies sending emails to customers must take into account during a pandemic.
Shops closed, restaurants shut, hotels empty — in recent weeks the coronavirus pandemic has brought Germany and other countries to a standstill, and many small and medium-sized businesses have found themselves in a very uncertain financial situation. As the old saying goes, however, necessity is the mother of invention, so many companies have moved their operations to where there are no viruses — at least none that harm the human body — to the internet. Customers, too, faced with closed shop doors, are moving their purchases to the World Wide Web. This turn of events has concrete consequences: according to email providers WEB.DE and GMX, part of the 1&1 group, since the start of the corona crisis email usage has risen by a full 40 percent, and the number of transactional emails by more than 30 percent.
In principle, this trend is not a problem, but resourceful fraudsters are exploiting the current situation by abusing recipients' trust. A Google search for the terms "email" and "corona" returns almost exclusively phishing-related results. For example, the German Consumer Advice Centre recently warned about a phishing email purportedly from "Sparkasse", a well-known German bank. Its customers were to provide their personal data via an attached link, which then immediately ended up with the fraudsters. The phishers exploited the fact that, due to the coronavirus pandemic, customer relationships are maintained more intensively via email and that recipients accepting this state of affairs may not exercise due caution when reading correspondence. This fact, which is troublesome for the recipients of such emails, can in the worst case cost them dearly. On the other hand, the frequent appearance of such messages can also have consequences for highly reputable email senders if messages sent on their behalf, as in the case mentioned above, are phishing messages.
Fraudsters exploit the crisis
The second problem at present is spam. Emails with dubious offers, e.g. protective masks or disinfectants, exploit recipients' fears for their own purposes. Spam messages sent in the name of the World Health Organization (WHO) have already appeared. It is therefore no wonder that email providers, too, have recognised the new threats and have begun to enforce their spam detection rules even more rigorously. And here is very important information for senders: anyone who lands in a recipient's spam folder even once will also not reach that same recipient's "inbox" in the future. In this context, it is therefore particularly important that senders strictly follow certain rules in order to ensure delivery of their emails.
Five rules of safe email marketing
Especially small and medium-sized businesses that have moved their operations online in the face of the current crisis and are now also sending a lot of emails often have no idea how to protect themselves from being used for phishing attacks or from losing their good reputation as alleged spammers. The Certified Senders Alliance (CSA), a project created by eco - Verband der Internetwirtschaft e.V. in cooperation with Deutscher Dialogmarketing Verband (DDV) and dedicated to creating a whitelist, has set itself the goal of improving the quality of commercial emails, and thereby increasing their deliverability and protecting senders' reputations. CSA email experts recommend that companies follow the five basic rules listed below to protect their identity online and ensure their emails reach recipients' inboxes today and in the future.
Use only high-quality addresses
Look after the quality of your list
Include on your recipient list only addresses of people you obtained legally, whom you know want to receive information from you, and whose consent to data processing you can always prove. This not only gives you legal security, but also protects your reputation and builds your customers' trust. A small list with high-quality addresses is better than a large one with addresses obtained from at least questionable sources. In every case, use the "double opt-in" procedure, i.e. a feedback loop. In case of any doubt, you should at any time be able to clearly prove that you have consent to receive emails from every person to whom an email was sent in your name. Double-Opt-In (DOI) gives you this security.
Make sure you create a professional impression
Pay attention to your choice of words and the quality of images in your emails. Pixelated photos or buttons or a subject line that says nothing leave a negative overall impression. Be sure to make sure all links in your email work correctly and follow the "rules of the game": every link should reflect the advertised information. Make sure the overall picture of your presentation inspires trust rather than merely covering what is legally required.
Speak clearly
Be honest, even when your aim is to gain new subscribers to your newsletter. Say what you want to achieve in clear and understandable words. Do not "hide" your request for consent to send advertising, because the recipient will notice it at the latest upon receiving your newsletter, which they did not order. As a result, annoyed, they will unsubscribe again — or worse — mark it as spam in their mailbox.
Create a point of reference for the recipient so they know why and on what basis you are communicating with them. Set a clear expectation for the recipient by choosing a subject line that will also be reflected in the content of the email. And if possible, establish personal contact with the recipient.
Don't be a phisher
Protect your brand from phishing
Protect yourself and your brand through authentication against misuse for phishing. When sending emails, use the Sender Policy Framework (SPF), Domain Keys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC) standards. With DMARC, (SPF) and (DKIM), you have the ability to make your emails clearly recognisable to mailbox providers and at the same time specify how they should handle emails that purportedly come from you. Thanks to this, phishing messages can be reliably detected and filtered before they reach the recipient and cause potential harm to your customer.
Look for partners
Never heard of terms like SPF, DKIM and DMARC? Until now you have only sent individual emails, but in the current situation you would like to expand your email communication? Large-scale sending requires compliance with extensive standards for transactional emails (e.g. invoices, order confirmations, etc.) and newsletters. The CSA has summarised the required technical and legal standards in its criteria. Or perhaps you are thinking of sending emails via companies specialising in email sending (ESPs)? Senders certified by the CSA have committed to complying with CSA criteria and thus to meeting very high standards. CSA-certified senders can be found here.
If your email service provider (ESP) offers this option, use a feedback loop. Your provider will then give you feedback about recipients who classify your mail as spam or junk email. This will also help you maintain list hygiene if you immediately remove the relevant addresses from your list. In the CSA library you will also find other informative articles on current challenges.
Summary
The pandemic has forced commerce to move online, which has translated into a rise in the number of emails sent — WEB.DE and GMX recorded a 40 percent increase in email usage. Unfortunately, fraudsters are also exploiting the crisis by impersonating well-known brands such as Sparkasse or institutions like the WHO, which increases the risk of phishing and spam. For senders, deliverability is crucial, because once marked as spam, an email goes to the recipient's folder forever.
CSA experts recommend five basic rules: building a recipient list exclusively on the basis of double opt-in, taking care of a professional look of messages, clear communication, authenticating your domain with the SPF, DKIM and DMARC standards, and working with certified email service providers. This will protect the sender's reputation and build customer trust.