Every policy step should be a decision taken against numbers from your own reports. The numbers are not complicated; the discipline is deciding what they have to say before you look at them.
Criteria worth stating in advance
| Before moving to | Require |
|---|---|
p=quarantine |
|
p=reject |
|
The percentages are defensible defaults rather than laws. What matters is that they exist before the meeting where someone asks whether it is safe to proceed, because the answer to that question should not be reached by consensus in the room.
“Explained” is the load-bearing word
A residual 2% of failures is safe to enforce against if you know what it is and unsafe if you do not, and the percentage is identical in both cases.
2% failing, all from forwarding IPs at universities -> known shape, no owner to fix it, accept and proceed 2% failing, source unidentified -> could be an unknown business system -> could be spoofing -> the number does not distinguish them. Do not proceed.
Reading volume honestly
- A low-volume source can be your most important one. Two hundred messages a month might be the system that sends password resets.
- Report volumes are lower bounds. A source absent from reports may simply send to receivers that do not report.
- Seasonality is real. A quarterly billing run appears in one month of reports and not the two before it. Four weeks of evidence can miss it entirely, which is an argument for looking at a quarter before the final step.
The deadline is not a criterion
A date imposed by a compliance requirement or a customer questionnaire tells you when somebody wants enforcement. It tells you nothing about whether your senders are ready, and enforcing on an unmet criterion because the date arrived is how a domain rejects its own invoices.