Free website migrationGet started
TopSyde
Diagram showing order confirmation emails and marketing campaigns leaving a store from two separate sending subdomains

Keep Transactional Email Off Your Marketing Subdomain

Transactional vs marketing email for ecommerce: why order confirmations and campaigns need separate subdomains, senders, and SPF, DKIM and DMARC records.

Elena Marchetti

Elena Marchetti

Content & SEO Strategist

··12 min read

Last updated: October 11, 2026

Transactional email (order confirmations, password resets, shipping notices) and marketing email (campaigns, newsletters, win-back flows) should leave your store from separate subdomains with their own SPF, DKIM and DMARC records. Share one sending identity and a single bad campaign drags receipts into spam, where they trigger refund requests instead of repeat orders.

What is the difference between transactional and marketing email in ecommerce?

Transactional email is triggered by something the customer did: they ordered, they reset a password, they asked for a return label. Marketing email is sent on your schedule to a list. The distinction matters because mailbox providers, spam filters and US law all treat the two categories differently, and because customers expect them at different reliability levels.

Nobody files a support ticket when a newsletter lands in Promotions. They file one within 20 minutes when the order confirmation does not show up. CAN-SPAM reflects that split too: transactional messages are exempt from the unsubscribe and physical-address requirements that apply to commercial content. Put a 20% off banner at the bottom of a receipt and you have arguably turned it into a commercial message, which is one more reason to keep the two streams on separate infrastructure and separate templates.

The practical version for a WooCommerce or Shopify store:

AttributeTransactionalMarketing
TriggerCustomer actionYour campaign calendar
Volume patternSteady, matches order countSpiky, thousands at once
Target inbox placement98%+85% is a decent day
Complaint rate toleranceNear zeroUnder 0.3% required by Gmail
Consent modelImplied by the purchaseExplicit opt-in
Typical senderPostmark, SES, SendGrid, MailgunKlaviyo, Mailchimp, Omnisend

Why one marketing campaign can sink your order confirmations

Mailbox providers score reputation at the domain and subdomain level as well as the IP. If your Klaviyo campaign and your WooCommerce receipts both authenticate as yourstore.com, the complaints from that campaign attach to the same reputation record your receipts depend on. Gmail does not separate them for you.

According to Validity's 2024 Email Deliverability Benchmark Report, about one in six commercial emails worldwide never reaches the inbox. That is the baseline for marketing. Dragging receipts down to that number is where it gets expensive.

The scenario plays out the same way every time. A store buys or imports a list, or re-engages 18,000 addresses that have not opened anything in two years. Complaint rate hits 0.5%. Gmail starts throttling, then bulk-foldering. Three days later the merchant notices nothing wrong with the campaign stats (they never expected much) but the support inbox is full of "I was charged and never got a confirmation." Google and Yahoo's bulk sender rules, in force since February 2024, require senders of more than 5,000 messages a day to a given provider to keep complaints under 0.3% and to publish a DMARC record. Cross that line on a shared domain and everything you send is in the penalty box.

Separating the streams means a bad campaign costs you campaign performance only. The receipts keep flowing from a subdomain with a clean, boring, high-engagement sending history.

How to split sending across subdomains

Use three sending identities, each with its own DNS records and its own provider. The root domain stays reserved for people writing to people.

PurposeSender addressSubdomain authenticatedProvider
Order, shipping, account emailorders@notify.yourstore.comnotify.yourstore.comPostmark, Amazon SES, Mailgun
Campaigns, flows, newslettershello@mail.yourstore.commail.yourstore.comKlaviyo, Mailchimp, Omnisend
Support and sales repliessupport@yourstore.comyourstore.comGoogle Workspace, Microsoft 365

Three rules make this work in practice.

Never send bulk from the root domain. Your root is what your invoices, your vendor emails and your legal correspondence authenticate against. Burn it with a cold campaign and you will spend a quarter rebuilding it.

Set the reply-to separately from the from-address. Receipts can come from orders@notify.yourstore.com with a reply-to of support@yourstore.com. Customers who hit reply reach a human. The sending reputation stays isolated.

Warm new subdomains before you need them. A brand new sending subdomain with no history gets treated with suspicion. Start transactional volume on the new subdomain two to four weeks before you launch the marketing one, so your receipts are already trusted when the campaign traffic begins.

If your store's email is currently going out through the free mailboxes bundled with your hosting plan, start there. We wrote about why shared host mail servers hurt deliverability in your host's free mailboxes are not a business email plan: on a shared host you are sharing an IP with whoever else bought the $4 plan that month.

How to set up SPF, DKIM and DMARC per sender

Each subdomain gets its own SPF record, its own DKIM key from its own provider, and inherits or overrides the DMARC policy you publish at _dmarc.yourstore.com. Doing it per-subdomain is what keeps a failure in one stream from authenticating as a failure in another.

SPF has a limit most people discover the hard way: a maximum of 10 DNS lookups per record. Google Workspace costs one. Klaviyo costs one or two. SES, Mailgun, a helpdesk, an invoicing tool, a webinar platform, all stacked into one root-domain SPF record, and you quietly exceed the limit. Once you do, SPF returns permerror and every sender in the record can fail, including the ones that were fine yesterday. Splitting senders onto subdomains gives each one its own 10-lookup budget.

A workable DNS layout:

yourstore.com           TXT  "v=spf1 include:_spf.google.com -all"
notify.yourstore.com    TXT  "v=spf1 include:spf.mtasv.net -all"
mail.yourstore.com      TXT  "v=spf1 include:_spf.klaviyo.com -all"
_dmarc.yourstore.com    TXT  "v=DMARC1; p=quarantine; rua=mailto:dmarc@yourstore.com; pct=100"

Start DMARC at p=none with reporting on, read the aggregate reports for two to three weeks to catch any sender you forgot about (there is always one: the invoicing tool, the review request plugin, the shipping app), then move to p=quarantine and eventually p=reject. Rushing to reject before you have read a single report is how stores block their own receipts.

Alignment is the part that trips people up. DMARC passes when the visible From domain aligns with either the SPF or DKIM domain. If your plugin sends as orders@yourstore.com but relays through a subdomain-authenticated provider, you get a mismatch. Set the From address to match the subdomain you authenticated, or configure relaxed alignment so the organizational domain matches. For the WordPress-side mechanics of SMTP plugins, authentication and testing, see our guide on fixing WordPress email deliverability.

What does split sending cost per month?

Less than one lost day of receipts for most stores. Here is a realistic stack for a store doing 600 orders a month with a 12,000-person marketing list.

ComponentTypical monthly cost
Transactional relay (Postmark 10k emails, or Amazon SES at $0.10/1,000)$0.50-$15
Marketing platform (Klaviyo at 10k-15k contacts)$150-$200
Google Workspace, 3 mailboxes$21-$26
DMARC report monitoring (Postmark DMARC Digests, dmarcian free tier)$0-$25
Total$172-$266

You are almost certainly already paying for the marketing platform and the mailboxes. The incremental spend to isolate transactional sending is the relay, and Amazon SES will run a 600-order store about 25 cents a month. The work is DNS configuration and testing, not budget.

Now run the other side. Say 10% of your order confirmations land in spam for a week. At 600 orders a month that is roughly 15 customers who did not get a receipt. Industry support teams usually budget 5-8 minutes per "where is my order" ticket including the lookup and the reply, so call it 90-120 minutes of staff time. Add two customers who assume the charge was fraudulent and open a dispute. A single card chargeback typically carries a $15-$25 fee on top of the lost order value, per the fee schedules published by Stripe and most acquirers. Add the one-star review that mentions "never received confirmation." The week costs more than a year of SES.

Stores that treat order email as part of the checkout experience see it differently from stores that treat it as a side effect of the plugin. The same thinking applies to the rest of the stack, which is the argument we made in why your WooCommerce store needs managed hosting, not shared: the infrastructure under a transaction is revenue infrastructure.

Who should own this at your store

Someone has to notice when the bounce rate on the transactional subdomain moves from 0.4% to 3%. On most stores, nobody does, because there is no dashboard anyone looks at and the merchant only hears about it through support tickets days later.

This is the part we take on. Every site on TopSyde managed WordPress hosting gets its transactional sending configured against a dedicated subdomain with SPF, DKIM and DMARC published and verified, the WordPress SMTP layer pointed at the relay rather than PHP mail, and bounce, complaint and delivery rates monitored 24/7. If the deliverability rate on your receipts drops, you hear from us before your customers do. Our support team answers in under 2 hours during business hours when you need a sender added or a record changed.

Plans start at $89/mo per site. You can see exactly what is included on the TopSyde pricing page, and the full technical breakdown of the platform, including mail handling, lives on the spec sheet. Migrations are handled by our team and come with a 30-day money-back guarantee, so if the split sending setup does not hold up, you are not stuck with it.

One more thing worth checking while you are in DNS: whether your current host can even be reached if something goes wrong with it. Email records, nameservers and site hosting often live in the same account, which is how merchants end up locked out of everything at once. We covered that failure mode in when your web host shuts down, the site goes with it.

A 45-minute audit you can run today

Open your store's email settings and list every system that sends on your behalf. Checkout receipts, shipping notifications, review requests, abandoned cart flows, the contact form, the helpdesk, the invoicing tool. Most merchants find seven or eight. Then check which From address each one uses.

If more than one category sends from the root domain, you have the problem this post describes. Pick a transactional relay, create the notify subdomain, publish SPF and DKIM for it, point your WooCommerce SMTP plugin at it, and send a test order to a Gmail address, a Yahoo address and an Outlook address. Check the raw headers for dkim=pass and dmarc=pass on all three.

Then publish DMARC at p=none and read the reports for a fortnight before tightening. If your abandoned cart flow is the thing driving most of your marketing volume, our take on recovering WooCommerce carts without more popups covers how to keep those sends engagement-positive rather than complaint-generating, which protects the marketing subdomain too.

Frequently asked questions

Can I use the same email service provider for both transactional and marketing email?

You can, and some providers support it with separate sending domains and separate IP pools inside one account. The configuration matters more than the vendor. If both streams authenticate as the same domain and share a reputation, you have gained nothing by splitting the templates.

Does a subdomain inherit the root domain's sending reputation?

Partly. Mailbox providers factor in organizational domain reputation, so a badly damaged root domain will drag on a new subdomain. The separation works best when you set it up before there is a problem, rather than as a recovery move after Gmail has already started bulk-foldering everything you send.

Should order confirmations include promotional content?

Keep it minimal. A small related-products block is normal practice, but a receipt dominated by discount codes starts to look like a commercial message under CAN-SPAM and reads like one to spam filters. The receipt's job is to confirm the order and reduce support tickets.

What DMARC policy should an ecommerce store run?

Start at p=none with aggregate reporting enabled, spend two to three weeks identifying every legitimate sender in the reports, then move to p=quarantine. Reach p=reject only once all your senders authenticate cleanly, since reject will block anything misconfigured, including your own checkout emails.

How do I tell if my receipts are landing in spam right now?

Place a real test order using a Gmail, Yahoo and Outlook address you control, then check the Spam and Promotions folders as well as the inbox. Open the raw message headers and confirm SPF, DKIM and DMARC all show pass. Repeat after any change to your sending setup.

Elena Marchetti
Elena Marchetti

Content & SEO Strategist

7+ years SEO & content strategy, Google Analytics certified

Elena drives content strategy and SEO at TopSyde, helping clients maximize organic visibility and AI search presence. She combines technical WordPress knowledge with data-driven content optimization.

Related Articles

View all →

Managed WooCommerce

Your store, off your plate.

Hosting tuned for checkout speed, updates tested before they ship, daily security scans, and a senior developer on call when an order breaks. Flat $89/mo — everything included.

Flat $89/mo per site · Free migration · 30-day money-back guarantee