I do apologise for the length of what follows.
I operated a small hosting reseller operation for seven years. In the beginning, email was simply included; it was expected. However, the burden of reputation management has become unsustainable. Let me describe three incidents from this year alone.
- A client's WordPress contact form was exploited to send pharmaceutical spam. Their domain was listed on Spamhaus CSS within four hours. I received forty-seven support tickets from other customers whose legitimate mail was now deferred.
- A business customer using "strong" passwords had credentials harvested via phishing. The attacker sent twelve thousand messages through our server before I detected the queue anomaly. The IP reputation required three weeks to recover.
- A newsletter sender insisted their double-opt-in list was clean. It was not. Microsoft blacklisted our entire /26 for sixty days; no amount of SNDS appeals would accelerate removal.
I am not a large operation. I cannot afford dedicated IP pools, deliverability consultants, or twenty-four-hour abuse response. The margins on shared hosting do not support this complexity.
As of last month, I refer all customers to specialised email providers. My support load has decreased by approximately seventy percent. My sleep has improved.
I do apologise if this sounds as though I am abandoning responsibility. It is my hope that this explanation may assist others facing similar pressures.