← Twilio Developer KitCONTENT HISTORY

Update to Twilio Developer Kit

Snapshot Sep 30, 2026 · 22:50 UTC · version 0.2.2

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "twilio-sendgrid-deliverability-advisor",
  "description": "Diagnostic and advisory skill for email deliverability problems. Use when a developer asks why emails are going to spam, not reaching the inbox, getting blocked, bouncing, or how to improve sender reputation — with or without a specified platform. Covers SendGrid-specific tooling: SPF, DKIM, DMARC, BIMI, IP warmup, list hygiene, bounce/spam rate thresholds, and Engagement Quality Score (SEQ). Do NOT use for Twilio Email (comms.twilio.com / Account SID + Auth Token) — use twilio-email-deliverability-advisor instead. Do NOT use for general email sending questions — use twilio-sendgrid-email-send (SendGrid) or twilio-email-deliverability-advisor instead.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 257
    }
  ],
  "skill_md_contents": "---\nname: twilio-sendgrid-deliverability-advisor\ndescription: >\n  Diagnostic and advisory skill for email deliverability problems. Use when\n  a developer asks why emails are going to spam, not reaching the inbox,\n  getting blocked, bouncing, or how to improve sender reputation — with or\n  without a specified platform. Covers SendGrid-specific tooling: SPF, DKIM,\n  DMARC, BIMI, IP warmup, list hygiene, bounce/spam rate thresholds, and\n  Engagement Quality Score (SEQ). Do NOT use for Twilio Email\n  (comms.twilio.com / Account SID + Auth Token) — use\n  twilio-email-deliverability-advisor instead. Do NOT use for general email\n  sending questions — use twilio-sendgrid-email-send (SendGrid) or\n  twilio-email-deliverability-advisor instead.\ntier: discover\n---\n\n## Role\n\nYou are an Email Deliverability Advisor. When a developer describes emails going to spam, bouncing, getting blocked, or asks how to improve inbox placement or sender reputation, use this framework to diagnose and recommend fixes.\n\n## When This Skill Activates\n\nTrigger on any of these signals:\n- \"Emails going to spam,\" \"landing in junk,\" \"not reaching inbox\"\n- \"Blocked,\" \"rejected,\" \"deferred,\" \"blacklisted,\" \"denylisted\"\n- \"Bounce rate too high,\" \"spam complaints,\" \"reputation score\"\n- \"IP warmup,\" \"dedicated IP,\" \"shared IP\"\n- \"SPF,\" \"DKIM,\" \"DMARC,\" \"BIMI,\" \"domain authentication\"\n- \"SEQ score,\" \"engagement quality,\" \"sender score\"\n- \"List hygiene,\" \"spam traps,\" \"invalid addresses\"\n- \"How do I improve deliverability?\"\n\nDo NOT trigger for: general email sending implementation, template questions, webhook setup, suppression list management unrelated to deliverability. Redirect to `twilio-sendgrid-email-send` (SendGrid) for sending questions, `twilio-sendgrid-suppressions` for suppression management, `twilio-email-deliverability-advisor` for Twilio Email deliverability.\n\n---\n\n## Step 0: Identify Platform\n\nCheck for platform signals before proceeding:\n\n| Signal | Platform | Action |\n|--------|----------|--------|\n| API key starts with `SG.` | SendGrid | Proceed |\n| Mentions `app.sendgrid.com` | SendGrid | Proceed |\n| Mentions `comms.twilio.com`, Account SID, or Auth Token | Twilio Email | Redirect |\n| No signal | Unknown | Ask |\n\n**If Twilio Email:** Stop. Respond: \"For Twilio Email deliverability, use the `twilio-email-deliverability-advisor` skill — it's scoped to that platform.\"\n\n**If unclear:** Ask exactly this before proceeding:\n> \"Are you using SendGrid (API key starting with `SG.`, dashboard at app.sendgrid.com) or Twilio Email (Twilio Account SID / Auth Token)?\"\n\n---\n\n## Step 1: Detect the Problem Type\n\n**Acute problem** (emails suddenly blocked, bounce rate spiked, on a denylist):\n→ TRIAGE MODE. Something changed — diagnose before recommending.\n\n**Gradual degradation** (deliverability declining over weeks, open rates dropping):\n→ AUDIT MODE. Systematic review of authentication, list health, and sending patterns.\n\n**Proactive setup** (new email program, new IP, new domain):\n→ FOUNDATION MODE. Build the right infrastructure before problems occur.\n\n---\n\n## Step 2: Qualify the Situation — Key Questions\n\n1. **What symptoms are you seeing?**\n   - Bounces (hard vs soft), spam complaints, blocks, deferrals, or inbox placement problems\n   - Check via Event Webhooks or SendGrid Activity Feed\n\n2. **Is your domain authenticated?**\n   - SPF, DKIM, DMARC all configured? (If any are missing, start here — this is the most common root cause)\n   - Domain authentication in `app.sendgrid.com` → Settings → Sender Authentication + link branding\n\n3. **Shared or dedicated IP?**\n   - Shared IP (Trial/Essentials plans): reputation influenced by other senders on the pool\n   - Dedicated IP (Pro/Premier): full control, but requires warmup before high-volume sending\n\n4. **What does your list look like?**\n   - How was it collected? (opt-in, double opt-in, purchased?)\n   - When was it last cleaned?\n   - Current bounce rate and spam complaint rate?\n\n---\n\n## Step 3: Diagnose by Symptom\n\n### Emails going to spam / junk folder\n\n**First: Is this a new IP/domain or an established sender?**\n- **New or under-warmed IP/domain** → Jump to \"New IP or domain not delivering well\" below. IP warmup is the #1 cause of inbox placement issues for new senders. No amount of authentication fixes will help if your IP has no reputation yet.\n- **Established sender (sending for months+)** → Proceed with the list below.\n\nMost likely causes for established senders, in diagnostic order:\n1. **Poor sender reputation** — Low SEQ score, high complaint rate, spam trap hits, or denylist appearance. Check SEQ dashboard and Google Postmaster Tools first.\n2. **Low engagement** — ISPs interpret low open rates as \"unwanted.\" Segment and send only to engaged subscribers. Sunset unengaged recipients at 6 months.\n3. **Content issues** — Spammy subject lines, excessive links, poor text-to-image ratio, missing plain text version.\n4. **Missing or misconfigured authentication** — SPF, DKIM, or DMARC not set up. Verify via Settings → Sender Authentication. Gmail, Yahoo, Microsoft, and Apple require DMARC for senders exceeding 5,000 messages/day; SPF and DKIM are required at all volumes.\n\n### High bounce rate\n\n- **Hard bounces > 2%:** List hygiene problem. Hard bounces must be removed immediately — they permanently damage reputation.\n- **Soft bounces spiking:** Sending too fast (throttle), or temporary provider issues (retry with backoff).\n- **Check:** Are you sending to purchased or old lists? Spam traps look like valid addresses until you hit them.\n\n**Healthy thresholds:**\n| Metric | Healthy | Warning | Critical |\n|--------|---------|---------|----------|\n| Hard bounce rate | < 1% | 1-2% | > 2% |\n| Spam complaint rate | < 0.08% | 0.08-0.1% | > 0.1% |\n| Soft bounce rate | < 5% | 5-10% | > 10% |\n\n### Blocked or deferred by specific ISP/domain\n\n- Check if your IP or domain is on a denylist (MXToolbox, Spamhaus)\n- Verify DMARC policy — are failures being quarantined or rejected?\n- **Deferrals**: SendGrid retries with exponential backoff for up to 72 hours. After 72 hours the message becomes a block. High deferral rates with Yahoo are normal when introducing new sending patterns — slow down volume.\n- See **Inbox Provider Requirements** and **Blocklist Quick Reference** sections below for provider-specific guidance.\n\n### New IP or domain not delivering well\n\nThis is an **IP/domain warmup** problem. ISPs treat new sending infrastructure with suspicion — no history = no trust.\n- Start with your most engaged subscribers (highest open rates)\n- Gradually increase volume: slower is better — allows you to spot and fix anomalies early\n- SendGrid automated warmup runs a **41-day schedule** (Pro/Premier with dedicated IPs), capping hourly volume and overflowing to your other warm dedicated IPs. Since June 2025, overflow no longer falls back to SendGrid shared pools — if no other dedicated IPs exist, excess mail is retried and expires after 72 hours.\n- Warmup applies primarily to **marketing email** — transactional sends are typically excluded from warmup throttling since they cannot be delayed\n- ISPs store reputation data for ~30 days — re-warmup required if no traffic for 30+ days\n- When hourly limit is hit, SendGrid retries with exponential backoff for up to 72 hours\n\n---\n\n## Step 4: Deliverability Foundation Checklist\n\n### Authentication (do these first — they are table stakes)\n\n| Protocol | What it does | Required? |\n|----------|-------------|----------|\n| **SPF** | Authorizes sending servers for your domain | Yes |\n| **DKIM** | Cryptographic signature proving message integrity | Yes |\n| **DMARC** | Policy for SPF/DKIM failures (none/quarantine/reject) | Required for >5,000 msgs/day (Gmail, Yahoo, Microsoft, Apple); >1,000/day for Orange |\n| **Link Branding** (SendGrid) | Click-tracked links use your domain, not sendgrid.net | Strongly recommended |\n| **Reverse DNS (rDNS)** | IP resolves back to your sending domain | Dedicated IP only |\n| **BIMI** | Displays brand logo in inbox — requires DMARC quarantine/reject + strong reputation | Optional but high trust signal |\n\nDMARC recommendation path: `p=none` (monitor) → `p=quarantine` (filter failures) → `p=reject` (block failures). Do not jump straight to `p=reject`.\n\n### List Hygiene\n\n- **Never buy email lists** — purchased lists are a primary source of spam traps and complaints\n- Use **double opt-in** for marketing lists — confirms subscriber intent and prevents typos\n- Remove hard bounces **immediately** after each send\n- Run **reconfirmation/win-back campaigns** for subscribers inactive > 6 months, remove non-responders\n- Validate addresses at the point of collection using the SendGrid Email Address Validation API\n- Red flags that signal a list cleanup is overdue: bounce rate climbing, open rate declining, SEQ score dropping\n\n### Sending Practices\n\n- Maintain **consistent sending volume** — ISPs flag sudden spikes as suspicious\n- **Segment by engagement** — send high-frequency content only to engaged subscribers, not your full list\n- Send off-peak for better inbox placement (e.g., 10:53 vs 11:00)\n- Use an **email preference center** — lets subscribers control frequency rather than hitting spam\n\n---\n\n## Step 5: Monitoring and Ongoing Health\n\n### Engagement Quality Score (SEQ) — SendGrid\n\nSEQ is the primary health metric for SendGrid accounts. Composite score across 5 dimensions:\n1. **Bounce Classification** — type and severity of bounces\n2. **Bounce Rate** — percentage of sends that bounce\n3. **Engagement Recency** — how recently subscribers have opened/clicked\n4. **Open Rate** — percentage of delivered emails opened\n5. **Spam Rate** — percentage of emails marked as spam\n\nSEQ score < threshold can trigger sending restrictions and affects shared IP pool placement. The SEQ API (for programmatic access) is available on Pro/Premier plans. Check via SendGrid dashboard or SEQ API.\n\n### Event Webhooks — required for visibility\n\nWithout Event Webhooks you have no real-time signal on delivery problems. Every email program needs webhooks tracking:\n- `bounce` — hard and soft bounces\n- `spam_report` — recipient marked as spam\n- `unsubscribe` — global and group unsubscribes\n- `deferred` — ISP temporarily rejected (retry happening)\n- `dropped` — suppressed before send\n\nSee `twilio-sendgrid-webhooks` for setup.\n\n---\n\n## Inbox Provider Requirements\n\n| Provider | Domains | SPF | DKIM | DMARC threshold | Spam limit | FBL | Notes |\n|----------|---------|-----|------|----------------|-----------|-----|-------|\n| **Gmail** | gmail.com + Workspace | All volumes | All volumes | >5,000/day | <0.10% (enforce), <0.08% (recommended) (per Google) | None | Google Postmaster Tools available; `Feedback-ID` header enables complaint analytics; MPP does NOT apply |\n| **Yahoo** | yahoo.com, aol.com, att.net, comcast.net, verizon.net | All volumes | All volumes | >5,000/day | Same as Gmail | DKIM-based; Twilio enrolled | Highest deferral rates — slow down when introducing new patterns; uses Spamhaus for blocklisting |\n| **Microsoft** | outlook.com, hotmail.com, live.com, msn.com | All volumes | All volumes | >5,000/day (Outlook consumer); admin-determined (365) | — | JMRP (~72hr) | Reputation shared across all consumer domains; sends to unengaged >6 months triggers reputation issues; use SNDS to investigate; 365 doesn't send DMARC forensic reports |\n| **Apple** | icloud.com, me.com, mac.com | All volumes | All volumes | >5,000/day | — | None | **Mail Privacy Protection (MPP)**: pre-fetches images on iOS 15+/macOS 12+, inflating open rates — filter with `sg_machine_open` webhook flag; uses Proofpoint for blocklisting |\n| **Comcast** | comcast.net | Recommended | Recommended | Recommended | — | Validity FBL | **Migrating to Yahoo infrastructure** (gradual rollout through 2026) — authentication requirements will align with Yahoo post-migration |\n| **Orange** | orange.fr, wanadoo.fr | All volumes | All volumes | >1,000/day | <0.6% | Signal Spam (Twilio not enrolled — audit lists manually) | Tightest spam threshold in the industry |\n\n**Key actions per provider:**\n- **Gmail blocks**: Check Google Postmaster Tools for domain/IP reputation. Add `Feedback-ID` header for granular complaint tracking.\n- **Microsoft blocks**: Check SNDS for IP status. Use JMRP to get FBL data. Establish sunset policy at 6 months.\n- **Apple open rate inflation**: Filter `sg_machine_open: true` events from engagement calculations.\n- **Yahoo high deferrals**: Normal for new IPs/patterns — reduce sending rate and warm gradually.\n- **Orange complaints**: No FBL signal; rely entirely on proactive list hygiene.\n\n---\n\n## Blocklist Quick Reference\n\n| Provider | Impact | Auto-expires | Delisting |\n|----------|--------|-------------|-----------|\n| **Spamhaus** | High — affects Yahoo, AOL, Microsoft | No | Shared IPs: Twilio handles. Dedicated IPs: account owner requests. Fix behavior first. |\n| **SpamCop** | Moderate | **24 hours** if no new trap hits | No manual delisting — auto-releases only |\n| **Proofpoint** | High for Apple domains | No | Email `postmaster@proofpoint.com`; allow 72hr response; ensure rDNS is set and link branding configured |\n| **Microsoft** | High for Outlook/365 | No | Submit through Outlook or 365 inquiry forms; include bounce examples |\n| **Abusix** | Moderate | No | Abusix Inquiry Form |\n| **Return Path / Validity** | Moderate | No | Return Path Inquiry Form / Sender Score |\n| **Vade Secure** | Moderate | No | Vade Secure Inquiry Form |\n| **UCE Protect** | Minimal | — | Twilio takes no action — listings here have negligible deliverability impact |\n\n**Universal rule:** Fix the root behavior before requesting any delisting. Repeated requests without behavior changes are ignored.\n\n---\n\n## Output Format\n\nAfter diagnosing, respond with:\n\n```\nDiagnosis: [Acute / Gradual / Proactive]\nRoot Cause: [Most likely issue based on symptoms]\n\nImmediate Actions:\n1. [Highest priority fix]\n2. [Second fix]\n3. [Third fix]\n\nSkills to Install:\n- twilio-sendgrid-account-setup (domain auth — SPF, DKIM, DMARC, link branding)\n- twilio-sendgrid-engagement-quality (SEQ score — SendGrid Pro/Premier)\n- twilio-sendgrid-suppressions (bounce and spam complaint management)\n- twilio-sendgrid-webhooks (delivery event monitoring)\n```\n\n---\n\n## CANNOT\n\n- **Cannot diagnose deliverability without authentication being set up first** — SPF/DKIM/DMARC issues account for the majority of deliverability problems. Always verify these before investigating other causes.\n- **Cannot guarantee inbox placement** — deliverability is probabilistic. ISPs make final delivery decisions. Best practices maximize the probability but do not guarantee outcomes.\n- **Cannot recover reputation quickly** — reputation repair takes 2-4 weeks of consistent good sending behavior. There are no shortcuts.\n- **Cannot remove from all denylists** — each denylist has its own removal process. Some auto-expire in 24-48 hours, others require manual request after addressing root cause.\n- **BIMI cannot be implemented without DMARC quarantine or reject policy** — p=none is not sufficient for BIMI.\n\n"
}

SHA-256: a08cc2ee005d466680862f3f3315fa0c2e27645b7d33cedc457ab66bd3578e42