The Context Box
The recipient scrolls to the footer to find out why this email arrived, and finds a list of guesses: maybe you signed up, maybe you bought something, maybe you attended an event. Inspired by Al Iverson's Spam Resource post The Context Box: Do It, But Right, this blues-rock and retro-soul slow burn argues that a sender who cannot name how an address was acquired is admitting there was never any permission, and should not be sending at all.
Deliverability Case Study: "The Context Box"
This song exists because of Al Iverson. In July 2026 he published The Context Box: Do It, But Right on Spam Resource — the term itself was coined by newsletter strategist Dylan Redekop, and Al adopted it because it names something useful: the short footer line that tells the recipient why this email arrived. "You're receiving this because you signed up for the XYZ newsletter." The intent, as Al puts it, is a noble one — stave off spam complaints by reminding recipients how they ended up on the list, before confusion or amnesia sends them to the "This is Spam" button. Complaints damage sending reputation directly, and the context box is one of the very few footer elements that can move that number. Al is pro-context box, as is Redekop. His post is a rant anyway, because too many senders write it badly — and he quotes the real specimen that provoked him: "You're receiving this email because you signed up online, made a donation, attended an event, or received care from us."
If that sentence sounds familiar, it is because this song is built out of it. The verses restage Al's specimen nearly phrase for phrase — signing up online, the donation, the event, the "received care" — and hand the microphone to the recipient on the other end of it: the person given a menu of guesses and expected, in Al's words, to do the detective work. (Musically: slow blues-rock with retro-soul horns, anger saved for the bridge. That is all the style commentary this track needs.)
Here is the technical breakdown of the deliverability concepts detailed in the song:
Verse 1: The Shotgun Disclosure
"You claim I signed up online, or I bought a pair of shoes / Or maybe I attended an event I didn't choose / You threw a dozen reasons in a single sloppy phrase"The Deliverability Context: This is Al's specimen set to music — the "blanket, cover-your-ass context box," in his words, which is where the chorus's "cover-your-ass parade" comes from. It lists every acquisition channel the program has ever used and lets the recipient pick one, and it happens for a mundane reason: the acquisition source was never stored per record. The sender knows the address came from somewhere* — web forms, purchases, imports, event badge scans — but no field on the record says which, so the footer hedges across all of them. The recipient reads the hedge correctly: this sender does not know how it got my address. That admission does more damage than saying nothing, because it confirms the exact suspicion the context box was supposed to dispel.
- The Fix: Put the source on the subscriber record, not in the template. Store the specific form, page, purchase, or event, plus the signup date, and merge those two fields into the footer at send time so each recipient sees the one reason that applies to them. A record where the merge field comes up empty is not a formatting problem — it is a permission problem, and the outro says what to do about it.
Chorus: The Complaint Math
"You're begging for the Spam button, baby, can't you see? / (No permission here) / Don't blame the algorithm when it's just bad memory"The Deliverability Context: A recipient who cannot place a sender has two buttons: unsubscribe or report spam. The context box exists to push that choice toward the first. It may well increase* unsubscribes — that is the point, not a side effect. An unsubscribe removes one address; a complaint counts against delivery to everyone on the list. Trading complaints for unsubscribes is always a good trade, and the context box is one of the cheapest instruments for making it. The Numbers: Google's sender guidelines tell bulk senders to keep the user-reported spam rate below 0.10% and never to reach 0.30%; Yahoo asks bulk senders to stay under 0.30%. The denominator matters: Google Postmaster Tools computes the rate against mail delivered to the inbox*, not everything attempted — mail already routed to spam cannot be reported and does not dilute the ratio. A program landing 200,000 messages in inboxes crosses the 0.10% line at roughly 200 complaints. A footer line that prevents a fraction of those is not cosmetic.
- The Correction: "Don't blame the algorithm when it's just bad memory" is the sharpest technical line in the song, and it holds up with one qualifier. Complaint and engagement history for a domain and IP is among the heaviest inputs into filtering at the major mailbox providers — alongside authentication results, content and URL reputation, blocklist status, and per-recipient history. A sender whose inbox placement collapses after mailing addresses nobody remembers giving them is not fighting an arbitrary algorithm; they are reading their own recipients' verdict, aggregated.
Verse 2: A Relationship Is Not Permission
"Don't say I 'received care' or I 'made a donation too' / When I never checked a box to get a word from you / You won't even look inside your own database"The Deliverability Context: "Received care" and "made a donation" are quoted straight from the context box Al received, and his verdict on it — "I never checked a box to opt-in to this" — became the next line of the verse. Both phrases are relationships, and neither is a permission. Having been a patient, a donor, or a customer explains how an organisation came to hold an address; it does not establish that the person agreed to receive marketing at it. A context box that cites the relationship instead of the opt-in is quietly conceding that no opt-in exists — and the recipient, who was there, can tell. "You won't even look inside your own database" is the accusation underneath: the answer to how this address was acquired usually does* exist somewhere in the sender's systems, and writing a multiple-choice footer is choosing not to go find it.
- The Fix: Say what actually happened, in plain language, even when it is unflattering. "You gave us this address when you completed a purchase on 2 May 2026" is a weaker permission story than a double opt-in — but it is true, verifiable, and matches the recipient's memory. A recipient told the truth who doesn't want the mail unsubscribes. A recipient told a story they know is false complains.
Bridge: The Footer Is Not Insurance
"You thought that little footer was deliverability insurance / ... / If your explicit data ain't clean and bright / Don't write a context box unless you do it right!"The Deliverability Context: "Deliverability insurance" is Al's phrase — his post observes that showing proof of permission feels like good deliverability insurance, and the bridge takes that feeling apart. A context box is not a filtering input — there is no header, standard, or field through which a permission statement earns credit from a mailbox provider — and no anti-spam law mandates the sentence. CAN-SPAM requires truthful headers and subject lines, a physical postal address, and an opt-out honoured within ten business days; it does not require consent, or any explanation of how the address was obtained. GDPR and CASL govern the consent itself and require a record you can produce on demand — a sentence in a template is not that record. The one genuine legal hook is GDPR Article 14: a controller who obtained personal data from somewhere other than the data subject must tell them the source, at the latest at the moment of first communication. The disclosure can technically live in a linked privacy notice, but the first email is* that first communication — which makes the footer the natural place to carry it. For EU-facing senders working from third-party data, naming the source is a legal obligation, not just good sense.
- The Mechanism: Strip the legal framing away and the box works through exactly one channel — the recipient's memory. It reduces complaints when it restores recall. It does nothing when it doesn't. That is why the bridge conditions the whole practice on data quality: "if your explicit data ain't clean and bright," the sentence you'd write is a guess, and a guessed context box is worse than none.
Outro: The Only Correct Response to "I Don't Know"
"Next time you don't know how I got on your list... just don't hit send."
- The Deliverability Context: The spoken outro is the operational rule the whole song argues toward, and it is where Al's "do it right" gets teeth. An address with no recorded acquisition source is not a marketing asset — it is unquantified risk sharing a send with the addresses that do have consent, dragging the sending domain's reputation down with it. Unknown-provenance segments are also where spam traps concentrate: pristine traps enter lists through scraping, purchased data, careless imports, or bots stuffing unprotected signup forms; recycled traps arrive through age. Suppress those records before the send, not after the complaints — reputation falls faster than it recovers, and one bad campaign can cost weeks of clean sending to work off.
The Most Neglected Line in Your Template
A context box is one short, plain-language sentence near the footer telling the recipient why they are receiving this email. It has one purpose: to close the gap between "I don't recognise this sender" and the spam button.
- It is a memory aid, not a legal instrument. No mailbox provider gives you credit for having one — there is no header or standard that carries it. It works entirely through the human reading it, so the only thing that matters is whether that person finds it credible.
- Its leverage is on complaints, the metric with the least forgiveness. Google wants your user-reported spam rate under 0.10% and never at 0.30%; Yahoo holds bulk senders under 0.30%. Complaints are the recipient's answer to a question — "why am I getting this?" — and the context box is your best chance to answer it first, at the exact moment the recipient is deciding.
- It earns the most where recall is weakest: long gaps between signup and first send, sub-brands that don't match the signup domain, re-engagement of dormant segments, and lists that changed hands in an acquisition. These are precisely the sends where most programs skip it.
- It is not the unsubscribe link. Keep them adjacent but distinct: the box explains the relationship, the link ends it. A recipient who wants out and finds only an explanation will complain.
Store the Source, Then Merge It
The multi-guess footer is a symptom. The disease is that acquisition data was never captured per record — Al's "do it right" is, underneath, a data-model requirement.
- Capture at signup: the specific source (form, page, purchase flow, event), the timestamp, the exact consent language shown at that moment, and the submitting IP for web forms. The consent language stays in your records as proof; the source and date are what the footer will use.
- Merge source and date into the footer at send time, so every recipient sees the one reason that applies to them. A dynamic context box is the only kind that stays accurate as the program adds channels.
- Never write a fallback that lists possibilities. If a record has no source, the honest fallback is not a menu — it is routing that record out of the send.
- Audit inherited lists hardest. Data that arrived through an acquisition, an agency handover, or a platform migration is the most likely to have lost its provenance in transit. Treat missing source data on an inherited segment as a suppression trigger.
Write One True Reason: Al's Five Checks
Al's post ends with five checks a context box must pass — specific, accurate, permission-based, verified, useful. In practice:
- Be specific — name the event, the place, and the date. "You're receiving this because you signed up for our newsletter at example.com on 14 March 2026" gives the recipient three separate hooks for recognition; any one may land. Don't hand them the phone book of every opt-in route you operate.
- Be accurate — let it be unflattering. A purchase, a donation, a badge scan — say exactly that, and accept the unsubscribes it produces. If the box doesn't match reality, recipients assume you lied or bought their data, and the complaint rate goes up, not down.
- Be permission-based — a confession is not a permission. "We obtained your address legally" is accurate and still fatal: legally compliant spam is still spam to the person reading it, and the report button is available to them no matter how lawful your send was. If the true sentence describes a purchase rather than a signup, the fix is not better copy — it is not sending (next section).
- Be verified — or don't assert. Without double opt-in, signup forms get forged, pranked, and mail-bombed. Telling an angry recipient "you signed up on our site" when a bot or an enemy submitted their address only fuels the fire. Confirmed opt-in is what makes the sentence in your footer safe to write.
- Be useful — plain language, legible type. The job is to jog a memory at a glance. The moment it reads like a lawyer wrote it, the recipient treats it as a defence — the song's "fine-print alibi" — and grey 8-point type at the bottom of a long footer is functionally absent, especially on a phone.
If You Cannot Name the Source, Do Not Send
The song's outro is the rule, stated without decoration.
- Suppress unknown-provenance records before the campaign, not after the complaints arrive. One send to a segment you cannot account for can undo months of reputation building on a domain and IP.
- Segment by acquisition source and monitor each source separately. Bounce and click rates are available per segment directly. Complaint attribution is split by provider: Yahoo's Complaint Feedback Loop and Microsoft's Junk Mail Reporting Program return a per-message ARF report for each complaint, which your ESP maps back to the campaign; Gmail sends no per-message reports — its FBL is aggregate, keyed on the
Feedback-IDheader you set per source, and surfaced in Postmaster Tools. Tag your mail for both, and remember the per-campaign complaint rate in an ESP dashboard undercounts reality, because Gmail — usually the largest share of any list — is missing from it. - Read the right dashboards. Google Postmaster Tools reports spam rate per authenticated domain; Microsoft SNDS reports per IP — on a shared IP it describes the pool, not you. Keep hard bounces under the ~2% industry warning line.
- Expect traps in the unexplained records. Pristine spam traps never opted in to anything — they enter lists through scraping, purchased data, careless imports, or bots stuffing unprotected signup forms. Recycled traps arrive through age. Both concentrate exactly where nobody can name the source.
The Compliance Boundary
A context box is good practice, not compliance — conflating the two is how senders come to believe a footer protects them.
- CAN-SPAM requires truthful headers and subject lines, ad identification where applicable, a physical postal address, and an opt-out honoured within ten business days. It requires neither consent nor any explanation of how you got the address.
- GDPR — where consent is your lawful basis, it must be freely given, specific, informed, and unambiguous, and demonstrated by a stored record, not a template sentence. Article 14 is the provision worth knowing: when data came from somewhere other than the data subject, you must tell them the source at the latest at first communication. That is a legally required context box for EU-facing senders using third-party data.
- CASL requires express or defined implied consent, sender identification with valid contact information, and an unsubscribe honoured within ten business days — with the burden of proving consent on the sender.
- One-click unsubscribe (RFC 8058) — the
List-Unsubscribe/List-Unsubscribe-Postheader pair — has been required since February 2024 by Google for senders above 5,000 messages a day to Gmail and by Yahoo for bulk senders, with opt-outs processed within two days. It sits alongside the context box, not in place of it: the box explains, the header exits.
Conclusion
Al Iverson's framing survives every technical test applied above: the context box is powerful, widely botched, and only as good as the data behind it. Generated from real per-record acquisition sources, it is a free, immediate reduction in the complaint rate — the metric with the narrowest margins in modern deliverability. Written from a template, it is a list of guesses announcing that the sender never knew who you were. His closing advice is the standard: if you can't make it specific and accurate, skip the disclaimer entirely and focus on sending content people actually remember signing up for. And if the honest version of the sentence cannot be written at all, that is not a copywriting problem — it is a permission problem telling you not to send.
Your Context Box Checklist:- Store source, timestamp, consent language, and signup IP on every subscriber record.
- Merge source and date dynamically into the footer — one true reason per recipient, never a menu.
- Write it plainly, name a date and place, keep it readable on a phone.
- Run double opt-in, so the signup you cite is one the recipient actually performed — forms get forged and mail-bombed.
- Suppress every record whose source you cannot name — before the send, not after the complaints.
- Attribute complaints per source through the feedback loops; keep Gmail's spam rate under 0.10%.
- Remember what it is: complaint prevention, not legal cover — except under GDPR Article 14, where naming the source is the law.
Deliverability is a moving target. This content reflects our best understanding at time of writing — but RFCs get updated, ISP policies shift, and best practices evolve. Spot an error or outdated info? Let us know and we'll fix it.