Forex brokers, CFD platforms, signal services and trading-education sellers are prohibited or restricted on Mailchimp, Klaviyo, SendGrid and Brevo, and the ban is written into the acceptable-use policy rather than decided per sender. Amazon SES and Mailgun will usually carry lawful trading mail after review. A dedicated SMTP server removes the provider policy entirely, because there is no shared pool to protect. What it does not remove is the FCA, ESMA and CFTC advertising rules, CAN-SPAM, or GDPR consent.
I've moved several brokers off shared relays after a termination notice. The pattern is the same every time, so here is the whole picture.
Who permits what
Get it in writing before you pay. These policies change without notice, and "restricted" often means a quiet review that ends in a paused account.
| Provider | Forex, CFD and trading mail | Notes |
|---|---|---|
| Mailchimp | Prohibited | Forex and binary options named in the acceptable-use policy |
| Klaviyo | Prohibited | Financial trading listed as a restricted business |
| SendGrid | Restricted | Case by case, promotional mail usually declined |
| Brevo | Restricted | Review required, marketing streams often refused |
| Amazon SES | Allowed if lawful | Production access review, will pause on complaint spikes |
| Mailgun | Case by case | Transactional treated more favourably than promotional |
| Dedicated SMTP | Your own policy | IPs are yours, the law still applies |
The split is the same one you see in crypto and iGaming: account mail is tolerated, promotional mail is where the bans bite. A margin-call notice is expected. A "97% win rate signals" pitch is not.
Why trading is treated as high risk
Providers are protecting their other customers, and three things make this sector expensive to host on a shared IP.
Phishing lookalikes. Broker brands are impersonated more than almost any category outside banking. Receivers see thousands of fake "verify your trading account" messages a day, so anything from a trading domain starts with a lower trust score.
Complaint rates from signal spam. Signal sellers and trading-course marketers have spent a decade mailing bought lists. Complaint rates on that traffic run 0.5% to 2%, against a Gmail hard limit of 0.3% and a target of 0.1%. Legitimate brokers pay for that history because filters score by category.
Regulator scrutiny. The FCA, ESMA and CFTC all publish warning lists and pursue unlicensed promotion. A provider does not want to check whether each customer holds a licence in each market, so it restricts the sector and moves on.
None of this is about legality. Licensed brokers get refused for the same reason unlicensed ones do: the category is a risk to the pool.
The three mail streams and how to split them
A trading platform sends three very different kinds of mail, and they belong on separate subdomains and separate IPs.
| Stream | Subdomain | Contains | Volume shape |
|---|---|---|---|
| Account | account.yourdomain.com | logins, KYC, deposits, withdrawals, margin calls, statements | steady, must never pause |
| Alerts | alerts.yourdomain.com | price alerts, order fills, market-open notices | bursty, time-critical |
| Marketing | news.yourdomain.com | webinars, promotions, education | scheduled, complaint risk lives here |
The reason is containment. If a promotional campaign draws complaints, the damage stops at the marketing subdomain and a client still receives the margin call that prevents their account being closed out. Mixing the streams means one bad campaign can stop regulatory notices reaching clients, which is a compliance failure as well as a deliverability one.
Give each subdomain its own DKIM selector, its own DMARC record and its own IP or IP group. A 3-IP starter setup maps cleanly: one IP for account, one for alerts, one for marketing. See subdomain vs root domain for email sending for the DNS layout.
Throughput numbers for market alerts
Alerts are the stream that breaks shared relays, and the maths is simple.
| Alert batch | Window | Required rate | Per IP across 3 IPs |
|---|---|---|---|
| 10,000 | 5 min | 34 msg/s | 12 msg/s |
| 50,000 | 10 min | 85 msg/s | 28 msg/s |
| 200,000 | 15 min | 222 msg/s | 74 msg/s |
A price alert that arrives 20 minutes after the move is worthless, so the window is fixed by the market, not by your sender. 85 messages per second is comfortable for a single tuned Postfix or PowerMTA instance on 3 dedicated IPs. The constraint is on the receiving side: Gmail and Microsoft throttle per IP, so spreading the burst across IPs is what keeps the 4xx deferral rate down. Shared relays on mid-tier plans often cap at a few hundred messages a minute, which turns a 10-minute alert run into an hour.
Two more rules for the alert stream. Keep it transactional only, so engagement stays high and complaints near zero. And run a hard time-to-live: if an alert has not been delivered within its window, drop it rather than deliver a stale price at 3am.
Compliance that does not go away with your own server
Dedicated infrastructure removes the shared-pool policy conflict. It does not touch the law, and in this sector the law is specific.
Financial promotion rules. Any mail that invites a retail client to trade is a financial promotion in the UK and EU. Under the ESMA product-intervention measures on CFDs, carried into the FCA rules for the UK, a promotion to retail clients has to carry the standardised risk warning: a statement that CFDs are complex instruments with a high risk of rapid loss, plus the percentage of your own retail accounts that lose money. That percentage has to be your real figure, updated quarterly, and it goes in the promotional email itself, not behind a link. In the US, the CFTC and NFA advertising rules apply to forex dealers and commodity trading advisors, including restrictions on performance claims and a requirement that hypothetical results carry a disclaimer. This is not legal advice. Get it checked per market.
CAN-SPAM. Accurate headers, a physical address, a working unsubscribe honoured within 10 business days. Applies to every promotional message, including the ones your signal partners send in your name.
GDPR and PECR. Consent for marketing to EU and UK individuals, and proof of it. A trading account does not imply consent to trading-course promotions. Keep the consent record next to the address.
No signal spam to bought lists. Unsolicited "free signals" mail to purchased addresses breaks consent law, breaks the financial promotion regime, and generates the complaint rate that got the category restricted in the first place. It also gets dedicated IPs blacklisted inside a week. Own infrastructure removes the provider, not the receiver.
Suppression. Closed accounts, unsubscribes and regulator-driven restrictions (for example, clients in a market where you are not licensed) must feed every stream, including alerts.
What it costs at 100K and 1M a month
Trading platforms tend to move from 100K to 1M a month quickly, because alerts scale with client count and volatility. Price both tiers before you choose.
| Provider | 100K per month | 1M per month | Dedicated IP | Policy risk |
|---|---|---|---|---|
| Amazon SES | ~$10 + $24.95 per IP | ~$100 + $24.95 per IP | add-on | review, pauses on spikes |
| Mailgun | ~$75 to $90 | ~$600 to $900 | higher tiers | case by case |
| SendGrid | ~$35 to $90 | ~$700 to $1,500 | high tier | restricted |
| Dedicated server | $549 one-time plus ~$30 to $80 hosting | same server, same price | 3 included | none from a provider |
SES is the cheapest bill on paper, and it is a workable choice for a broker with in-house deliverability staff. The cost is that you own warm-up, monitoring and the risk that an automated review pauses account mail on a volatile day. At 1M a month the dedicated server is the cheapest option by a wide margin and the only one where nobody else's policy can stop your margin calls. Full breakdown in cost to send 1 million emails per month.
Deliverability specifics for finance
DMARC at p=reject is close to mandatory. A broker domain at p=none lets a criminal send a perfect fake margin call from your exact From address, and Gmail will deliver it. RFC 7489 defines the three policies, and only reject asks receivers to drop the forgery. Start at none, read the aggregate reports for two to four weeks, move to quarantine, then reject. The path is in DMARC none vs quarantine vs reject.
Keep complaints under 0.1%. Google's bulk sender guidelines set 0.3% as the hard limit and 0.1% as the target, and require SPF, DKIM and DMARC for anyone over 5,000 messages a day. In a category filters already distrust, treat 0.1% as the ceiling for the marketing stream and 0.02% for account and alerts.
BIMI is optional but useful. Once DMARC is at enforcement, a BIMI record puts your logo next to the sender name in Gmail and Yahoo, which helps clients tell your real mail from the phishing copies. It needs a Verified Mark Certificate, which costs around $1,500 a year, so it is a brand decision rather than a deliverability requirement.
Content patterns. Urgency language, guaranteed-return claims and shortened links all score badly in this sector. Use your own tracking domain and write the risk warning in plain text, not an image.
What to do after a termination
- Export while you still can. Suppression lists, bounce logs, complaint reports, DKIM keys. Access usually closes within 48 hours.
- Find the cause. Complaint rate over 0.1%, bounces over 5%, or the category itself. The notice names one, the stats confirm it.
- Check domain reputation. Google Postmaster Tools, domain and IP separately. A Low or Bad domain follows you to the next provider.
- Clean before moving. Drop hard bounces and anyone with no engagement in 12 months. Typically removes 20 to 30% of a list.
- Rebuild on dedicated IPs. Fresh subdomains for the three streams, SPF, DKIM, DMARC at
p=none, matching PTR. - Warm up over 4 to 8 weeks. Account mail first, because engagement is highest, then alerts, then marketing. Ramp roughly 30% every two days per IP.
- Do not open a replacement account. The provider links by domain, payment method and pattern, and the second closure damages every later appeal.
The mistake I see most is skipping step 4. A signal list that got a SendGrid account closed will get dedicated IPs blacklisted just as fast.
How BulkEmailSetup helps
We build dedicated SMTP infrastructure for senders in restricted categories: your own server, your own IPs, full SPF/DKIM/DMARC/PTR configuration, MTA tuning for burst throughput, bounce handling and a warm-up plan, with account, alert and marketing streams separated onto their own subdomains and IPs from day one.
No shared pool means no category policy weighing your sending against other customers. Meeting the financial promotion rules, CAN-SPAM and GDPR in your markets remains yours. Basic starts at $549 one-time, covering 1 SMTP server, 3 dedicated IPs, 25,000 emails/day and unlimited contacts. Higher tiers scale to 15 IPs and 200,000 emails/day. See pricing.
Frequently asked questions
Which SMTP providers allow forex and trading companies?
Confirm in writing before paying, because policies change. Mailchimp prohibits forex and binary options outright, SendGrid and Brevo restrict the category and review case by case, Amazon SES permits lawful trading mail subject to review, and Mailgun decides per account. A dedicated SMTP server has no shared pool to protect, so the only policy that applies is the law in your markets.
Why do email providers treat forex senders as high risk?
Three reasons. Trading brands are heavily impersonated by phishing, so receivers scrutinise the category. Signal services and trading-education sellers have a long record of mailing bought lists, which pushes complaint rates well above the 0.1% target. And regulators in the UK, EU and US actively pursue unlicensed promotion, so providers avoid the exposure by restricting the whole sector.
How fast does a market alert system need to send?
Fast enough that the alert arrives while the price still matters. 50,000 alerts inside 10 minutes is roughly 85 messages per second, which a single well-tuned MTA on 3 dedicated IPs handles at about 28 messages per second per IP. Shared relays often cap throughput on lower tiers, so check the ceiling before you commit.
What compliance rules apply to forex email marketing?
The general email laws apply, meaning CAN-SPAM in the US, GDPR and PECR in the EU and UK, and CASL in Canada. On top of that, financial promotion rules apply to anything that invites retail clients to trade. In the EU and UK that includes the standardised CFD risk warning with your firm's percentage of losing retail accounts, and in the US the CFTC and NFA have their own advertising rules. Unsolicited signal mail to bought lists breaks both sets of rules.
Does a forex broker need DMARC at p=reject?
In practice, yes. Brokers are phished constantly, and a domain at p=none lets a criminal send a fake margin call from your exact address. Reject is the only policy that tells Gmail and Microsoft to drop those forgeries. Start at p=none, read the reports for two to four weeks, then move through quarantine to reject.
What should a trading platform do after an ESP termination?
Export suppression lists, bounce logs and stats while you still have access, then check Google Postmaster Tools for your domain reputation. If the cause was list quality, clean before moving anywhere. If the cause was category policy, move to dedicated IPs on a fresh subdomain, warm up over 4 to 8 weeks, and put account mail on its own stream so it is never paused again.



