STAMPWING / MULTI-PROJECT TRANSACTIONAL EMAIL CHECKLIST Last reviewed: October 4, 2026 Inventory (one row per app and environment) [ ] Application owner and operational contact [ ] Visible From domain; signing domain; envelope/return-path domain [ ] Provider account/project and region [ ] Separate Test and Live credentials; secret storage and rotation owner [ ] Domain verification and preserved mailbox MX records [ ] Password reset, verification, receipt, and notification event owners [ ] Template IDs and immutable version references [ ] Stable business-event ID and idempotency key policy [ ] Durable outbox and recovery process for uncertain submissions [ ] Signed webhook endpoint; durable inbox; duplicate/reordering tests [ ] Bounce and complaint handling; project and provider suppression scope [ ] Daily/monthly limits, alerts, retention, and spend cap [ ] Evidence for queued, provider-submitted, and receiving-server-accepted states [ ] Test fixtures are visibly simulated; no customer addresses in CI [ ] Controlled delivery check before Live; authentication alone is not inbox proof [ ] Runbook for rotating credentials, pausing sends, and recovering incidents Example inventory headings (no credentials): App | Environment | From domain | Key reference | Webhook endpoint | Limit | Owner Project separation organizes access and diagnosis. Shared infrastructure can still share reputation and provider limits; do not assume complete isolation.