Mailgun disables accounts for one of three reasons: a new account that failed verification, a metric that crossed a line in the acceptable use policy (5% bounces, 0.08% spam complaints, 1.4% unsubscribes), or a use case the policy bans outright. The email you got tells you which, but only if you know the phrasings. Work out which of the three you hit before you reply, because a verification hold and a policy termination need completely different responses.
I've had accounts held, disabled and reinstated at most of the shared relays, and Mailgun is more readable than most because it publishes its numbers. That helps. It also means there is no arguing with them.
Which kind of disable you got
Mailgun uses three distinct notice types. They look similar in the inbox and lead to very different places.
| Notice type | Typical wording | Who gets it | Realistic outcome |
|---|---|---|---|
| Verification hold | "Your account is pending review", "additional verification required" | New accounts, first 1-14 days | Cleared in 1-3 business days with the right reply |
| Compliance disable | "disabled due to a high bounce rate", "complaint rate exceeded" | Established accounts after a bad send | Reinstated in 3-10 days if the cause is shown and fixed |
| Policy termination | "violation of our Acceptable Use Policy", "terminated" | Any account, any age | Permanent for that account |
The verification hold is by far the most common on new accounts. Mailgun's free tier allows 100 emails a day and sandbox domains only send to authorised recipients, so a fresh signup that adds a custom domain and immediately pushes 5,000 messages looks like trial abuse whether it is or not. That hold has nothing to do with your list. It is a question about who you are.
The compliance disable is about numbers. The policy termination is about what you send. Most people treat all three as the same event and write the same angry ticket. Don't.
The thresholds Mailgun actually publishes
Unlike SendGrid, Mailgun writes its limits into the acceptable use policy. That is useful, because you can measure exactly how far over you were.
| Metric | Mailgun AUP limit | Gmail's line | Where the gap comes from |
|---|---|---|---|
| Hard bounces | 5% | not published, but 2% draws throttling | list provenance |
| Spam complaints | 0.08% | 0.3% hard, 0.1% target | shared IP protection |
| Unsubscribes | 1.4% (1% if unsubscribes exceed clicks) | none | Mailgun-specific signal |
| Blocks | 20% | none | receivers already rejecting you |
Two things stand out. First, the complaint limit is 0.08%, tighter than the 0.1% most people quote, and less than a third of Google's 0.3% hard line in the bulk sender guidelines. Mailgun has to act earlier than Gmail because your complaints land on IPs shared with thousands of other customers.
Second, the unsubscribe threshold is unusual. A 1.4% unsubscribe rate does not hurt anyone's reputation directly. Mailgun uses it as a proxy for consent: people who did not ask for your mail unsubscribe at that rate before they start complaining at 0.08%. If you tripped this one, your problem is targeting, not hygiene.
What to pull from the logs before you reply
You still have API and dashboard access on a disabled account in most cases. Use it before you lose it.
Pull the 7 days before the disable, per sending domain:
- Delivered, bounced, complained counts from the Analytics tab or the
/eventsAPI. Work the rates out yourself. Do not trust the headline percentage, which averages across domains. - Failed events with reason "esp block". These are receivers rejecting the mail at the door and they count toward Mailgun's 20% block limit. Sort by recipient domain. If 80% of blocks are at one receiver, that is your cause.
- Bounce events sorted by recipient domain. Bought and scraped lists show up here as a wall of unknown-user bounces at Gmail, Yahoo and Outlook simultaneously.
- Complaints by campaign tag. If one tag carries most of the complaints, you have your segment.
curl -s --user "api:$MAILGUN_API_KEY" \
"https://api.mailgun.net/v3/yourdomain.com/events?event=failed&limit=300&begin=$(date -v-7d +%s)" \
| jq -r '.items[] | [."delivery-status".code, ."delivery-status".message[:60], .recipient] | @tsv'
Export all of it. Suppression lists too. Once the appeal fails or the account is terminated, that data is gone, and it is the only evidence you have for the post-mortem.
What to send support
One message. Three specifics. No argument.
- Which segment caused it. "A 38,000-address re-engagement list from 2023" beats "an older segment". Name the campaign tag.
- What you removed, with a count. "Deleted 38,000 addresses, suppressed 2,140 hard bounces, list is now 61,000."
- What prevents a repeat. A concrete process: bounce suppression on, 12-month non-opener pruning monthly, verification on every import.
For a verification hold, the three specifics are different: your company website, a plain description of what mail you send and to whom, and how the recipients opted in. Attach a screenshot of the signup form if you have one.
Mailgun's compliance team responds to evidence. Second tickets, replies to the automated notice, and messages about how unfair it is all slow the queue for your own case. If it is a policy termination for a banned category, do not appeal at all. The answer is already in the AUP and the ticket costs you a week you could spend moving.
What the disable did to your domain
Nothing new. That is the uncomfortable part.
A disable is a Mailgun action. Gmail and Microsoft never see it. What they saw was the sending that caused it: the bounce wall, the complaint spike, the block events. Those were recorded against your domain at the time, and they travel with you to whatever you send from next.
So before you plan a clean start:
- Open Google Postmaster Tools for the sending domain.
- Check Domain Reputation for the week of the disable. A drop from High to Medium is normal and recovers in 2 to 4 weeks of clean sending. A drop to Low or Bad means the domain needs the same warm-up a new one would.
- Check IP Reputation separately. If only the IP dropped, that was Mailgun's shared IP, and it is no longer your problem.
If Postmaster Tools was never set up, do it today. The Google Postmaster Tools guide covers the DNS record and how to read the graphs.
Route decision: list problem or policy problem
The disable cause decides where you go next, and getting this wrong is how people end up disabled twice in a month.
| Cause | What actually failed | Does moving provider fix it? | What does |
|---|---|---|---|
| Bounce rate over 5% | list provenance | No, SendGrid and SES use the same 5% line | list cleaning before anything else |
| Complaints over 0.08% | consent or frequency | No, you carry the domain reputation | smaller engaged sends, clear opt-in, lower cadence |
| Unsubscribes over 1.4% | targeting | Partly, other relays don't measure it | fix segmentation, not infrastructure |
| Affiliate, cold, restricted category | shared-pool policy | Yes, if the sending is otherwise lawful and consented | dedicated IPs, your own reputation |
| Verification hold | identity signals | Usually resolves at Mailgun | reply properly, don't move yet |
The honest version: if your numbers were bad, every shared relay will treat you the same way, because they all protect the same kind of shared pool. Fix the list, then decide. Mailgun alternatives covers the like-for-like relays if you want to stay on shared infrastructure after cleaning up.
If your numbers were fine and the disable was about category, the policy conflict is structural. Affiliate marketing is named in Mailgun's AUP. Cold outreach trips the unsubscribe and complaint lines by design. On your own dedicated IPs there is no other customer to protect, so the objection disappears. The law and Gmail's 0.3% line do not disappear, and a dedicated server makes a bad list more expensive rather than less. See Mailgun vs a dedicated SMTP server for where that line falls.
Realistic outcomes and timelines
| Scenario | Chance of reinstatement | Time to resolve | Time to full volume again |
|---|---|---|---|
| Verification hold, real business, replies with website and opt-in proof | High | 1-3 business days | immediate, you never ramped down |
| Compliance disable, first offence, segment identified and removed | Moderate | 3-10 days | 2-3 weeks on Mailgun's shared IPs |
| Compliance disable, second offence in 90 days | Low | 5-14 days | unlikely on Mailgun |
| Policy termination, banned category | None | permanent | 4-8 weeks on new dedicated IPs |
| Purchased or scraped list, any notice type | None | permanent | do not resend that list anywhere |
Plan on the pessimistic row. If the appeal succeeds you are ahead. If you wait for it and it fails, you have lost the week and still have to move.
What the outage costs
| Line item | Typical figure |
|---|---|
| Sending down | 3 days to 6 weeks |
| Mailgun plan still billing | $35 to $90 a month on Foundation or Scale, not credited under the AUP |
| Lost campaign revenue | whatever your email normally drives per week, multiplied |
| Engineering and admin time | 15 to 30 hours for logs, appeal, migration, DNS |
| Re-warm on new infrastructure | 4 to 8 weeks at 30% growth every 2 days per IP |
| Domain reputation recovery | 2 to 4 weeks if Medium, months if Low |
The clocks run in sequence. A 7-day appeal that fails, then a 6-week warm-up, is 7 weeks before you are back at your previous daily volume.
The 30-day recovery plan
Work this from day one regardless of the appeal.
Days 1-3: export and diagnose. Pull events, suppressions and domain stats via API while access lasts. Identify the segment from bounces by recipient domain and complaints by tag. Set up Postmaster Tools. Send the one support message.
Days 4-7: clean. Every hard bounce out permanently. Every address with no open or click in 12 months out. Run the rest through verification. On a typical list this removes 20 to 30% of addresses, and that 20 to 30% was producing most of your bounces and complaints.
Days 8-14: rebuild the sending path. New infrastructure on a subdomain, not the root domain, so the next problem stays contained. SPF, DKIM at 2048 bits, DMARC starting at p=none, PTR matching the HELO name. If you are staying on Mailgun after reinstatement, still move to a fresh subdomain.
Days 15-45: warm up. A few hundred a day per IP to the most engaged 10% of the list. Grow roughly 30% every 2 days. Watch 4xx deferrals, not opens. A rising deferral rate means slow down.
Weekly, forever: complaint rate per campaign, bounce rate per campaign, Postmaster domain reputation. Fifteen minutes.
What not to do
- Do not open a second Mailgun account. Card, domain, IP and company details are matched. It gets disabled and it kills the first appeal.
- Do not point the same list at SendGrid or SES. Same 5% bounce line, same outcome, about two weeks later.
- Do not resume full volume on reinstatement. Mailgun's rolling averages are still fragile and a second disable within 90 days is nearly always final.
- Do not skip the post-mortem. If you cannot name the segment that caused it, you will mail it again.
How BulkEmailSetup helps
We build dedicated SMTP infrastructure you own: your own server, your own IPs, SPF, DKIM, DMARC and PTR configured, bounce and complaint handling wired in, and a warm-up schedule that matches your list. Because the IPs are yours alone, there is no shared pool to protect and no acceptable use team deciding whether your legitimate category is too risky for the customers next to you.
If your disable was caused by list quality, clean the list first, because dedicated IPs make a poor list more costly rather than less. When the list is clean, Basic starts at $549 one-time, covering 1 SMTP server, 3 dedicated IPs, 25,000 emails/day and unlimited contacts. Higher tiers scale to 15 IPs and 200,000 emails/day. See pricing, or read SendGrid suspended my account if you have been through this at more than one relay.
Frequently asked questions
Why did Mailgun disable my account?
Mailgun disables accounts for three kinds of reason. New accounts get held when the domain is unverified or the signup looks like trial abuse. Established accounts get disabled when a metric crosses the acceptable use policy line, which is 5% bounces, 0.08% spam complaints or 1.4% unsubscribes. Any account gets terminated for a banned category such as affiliate marketing, payday loans or purchased lists.
How long does a Mailgun account stay disabled?
A verification hold on a new account usually clears within 1 to 3 business days once you reply with a real domain, a company website and a description of your mail. A compliance disable on an established account takes 3 to 10 days if the appeal is accepted. A policy termination is permanent for that account, and there is no timeline because there is no review.
What are Mailgun's bounce and complaint limits?
Mailgun's acceptable use policy sets them out: bounces at or below 5%, spam complaints at or below 0.08%, unsubscribes at or below 1.4%, and blocks below 20%. The complaint line is tighter than Gmail's own 0.3% hard limit because your complaints land on IPs shared with other Mailgun customers.
Can I open a new Mailgun account after being disabled?
No. Mailgun matches new signups against payment card, sending domain, IP address and company details, and a replacement account normally gets disabled within days. It also converts a fixable compliance case into an evasion case, which ends any chance of the original appeal succeeding.
Does a Mailgun disable hurt my domain reputation?
The disable itself records nothing at Gmail or Microsoft. But whatever caused it already has. Receivers score your sending domain regardless of which provider carried the mail, so a complaint spike that tripped Mailgun's 0.08% line is already in Google Postmaster Tools as a reputation drop. Check there before assuming a fresh start elsewhere.
What should I move to after Mailgun disables me?
It depends on the cause. If it was list quality, clean the list first, because SendGrid, Amazon SES and every other shared relay will disable you for the same numbers. If it was a policy category that your business legitimately operates in, a dedicated SMTP server with your own IPs removes the shared-pool policy conflict, though it does not remove the law or receiver rules.



