Do regulated companies run email better? We measured 117 companies that were hiring for it.
The cohort under HIPAA, GLBA and the FDCPA has already solved the part of email everyone writes about. What it is hiring for is the part nobody can audit.
TL;DR Across a 117-company hiring scan, the 22 in regulated verticals had zero outbound authentication gaps 91% of the time (20 of 22) against 55% for everyone else (52 of 95), and the gap holds after controlling for company size. They have already solved authentication. What their job postings ask for is consent work nobody can audit from outside.
HireAmino · Statutory text quoted from uscode.house.gov, current through 27 August 2026
Free deliverability audit
powered by Amino
SPF, DKIM, DMARC and alignment in one pass →
Do regulated companies run cleaner email authentication?
Yes, by a wide margin. In our August 2026 hiring scan of 117 companies that posted an email or lifecycle marketing role between 26 May and 15 August 2026, the 22 operating in regulated verticals had zero outbound authentication gaps in 20 cases — 91%. The other 95 companies in the sample managed 55% (52 of 95).
Each company’s sending domain was audited over DNS on the date it entered the sample, using the same engine behind our free deliverability audit. In this measurement, “zero outbound gaps” means all four of:
- a valid SPF record that resolves within the lookup limit
- a DKIM key retrievable at a common or provider selector
- a published DMARC record at an enforcing policy, not
p=none
- a
rua address configured to receive aggregate reports
| Cohort | Zero outbound gaps | DMARC enforced | Weak 1024-bit DKIM |
| Regulated verticals (n=22) | 20 / 22 — 91% | 20 / 22 — 91% | 0 |
| Everyone else (n=95) | 52 / 95 — 55% | 66 / 95 — 69% | 11 |
| Full sample (n=117) | 72 / 117 — 62% | 86 / 117 — 74% | 11 |
The weak-key column is the one we did not expect. Eleven companies in this sample publish a 1024-bit RSA DKIM key, below the 2048-bit floor that RFC 8301 set for DKIM signing in January 2018, and none of the eleven is in the regulated group. Our earlier scan found the same defect in more than half the Fortune 50, so its total absence across 22 regulated companies is a genuine contrast rather than a small-sample quirk. The same cohort also cleared the SPF lookup limit without exception.
What counts as “regulated” here
A company was classified as regulated if it operates under a sector regulator governing either the data it emails about or the act of messaging itself:
- HIPAA — health plans, telehealth providers, a clinical screening lab
- GLBA and NCUA — credit unions and consumer financial services
- The FDCPA — a receivables and collections operation
- State insurance regulation — pet and travel insurers
- SEC and FINRA rules — a retirement and annuities provider
That boundary is ours, drawn over a free-text industry column in the dataset, and it is the most contestable choice in this post — which is why we tested it two ways below.
Is this just because regulated companies are bigger?
Partly, but not mostly. Size is the strongest signal in this dataset, and regulated companies do skew large: 9 of the 22 employ more than 1,000 people, against 19 of the other 95. Company size alone moves the clean-rate across this sample from 38% (13 of 34) to 79% (22 of 28).
So the honest test is whether regulated companies beat their own size peers. In this sample they do, in every band:
| Size band | Companies | Regulated | Everyone else |
| Under 200 | 34 | 4 / 6 — 67% | 9 / 28 — 32% |
| 200 to 1,000 | 55 | 7 / 7 — 100% | 30 / 48 — 62% |
| Over 1,000 | 28 | 9 / 9 — 100% | 13 / 19 — 68% |
Pooling those three strata with a Cochran-Mantel-Haenszel test gives p=0.0045. A stratified permutation test that reshuffles the regulated label 200,000 times within each size band gives p=0.0029, and puts the effect at roughly six more clean companies than composition alone would predict. Size does not account for it. This is the same size gradient we reported when email ownership moved to marketing across the wider dataset, and it remains the single best predictor of posture we have found.
What would make this finding wrong?
Three things could, and we ran the checks available to us. The full aggregate dataset carries every figure below, the classification rules, and both cohort definitions.
- The boundary could be doing the work. All 22 companies were re-classified by hand against a named regime, dropping four that matched only on a keyword — a legal-tech marketplace, a surgeons’ association, and two supplement brands whose industry text merely contained the word “health”. The stricter cohort of 18 comes out at 94% (17 of 18), higher than the loose one.
- The sample could be too small to mean anything. Twenty-two is small, and no individual size band clears significance alone: the three band-level p-values are 0.17, 0.08 and 0.14.
- The method could be manufacturing effects. Consumer-facing companies in this scan look worse than business-facing ones (42 of 72 against 30 of 45) — and that difference is pure composition, because consumer companies concentrate in the small-company band.
Two of those are worth stating plainly rather than burying. Because our hand audit moved the number in the direction we were already arguing, the looser and more conservative 91% is what we report, not the 94%. And the consumer-versus-business claim, run stratified through the identical code path, returns p=0.8410 — the machinery reports nothing when there is nothing there. If a re-scan next quarter reaches 60 regulated companies and the gap closes, this post is wrong, and we will say so on this page.
What are they hiring for, if authentication is already working?
Consent, records and suppression — the parts of an email program that leave no public trace. Read the postings rather than the titles and that is what the regulated employers are actually staffing. Only 24 of the 117 postings in this scan mention compliance or regulation in any form.
| What the posting says | Postings |
| Names GDPR | 7 |
| Names CAN-SPAM | 6 |
| Names HIPAA | 4 |
| Names the TCPA | 1 |
| Distinct companies naming at least one statute | 14 |
| Uses compliance or regulatory language, names no statute | 10 |
| Distinct companies using any compliance language | 24 |
The statute rows are mentions, not exclusive categories — four companies name more than one, which is why 18 mentions come from 14 companies. Eleven of the 24 are in the regulated group, which is only 22 of the 117-company sample. A regulated company here is roughly twice as likely to write a compliance obligation into the job description as everybody else.
What those postings ask for is unglamorous, and consistently the same four things — suppression list management and sunsetting rules, subscription and preference-centre handling, proof of how and when an address arrived on the list, and retention of that proof. This is the half of deliverability a DNS lookup cannot see. We can tell you from outside whether a domain’s DMARC policy is enforcing. Nobody outside the company can tell you whether it can produce the sign-up record for an address it mailed 18 months ago. That asymmetry is the whole point: authentication is publicly auditable, so it gets audited, written about and eventually fixed, while consent is private and so it does not. It is the same blind spot behind why a bounce rate is really a list problem.
The industry’s own consensus document has drawn that line for a decade. Announcing the M3AAWG Sender Best Common Practices, Michael Adkins, then chairman of the board at M3AAWG, put it directly:
While the laws on obtaining users’ permission to send commercial email vary around the world, these best practices are based on tangible industry experience – on what works and what is problematic in getting marketing emails delivered to recipients. Laws are necessary to define what high-volume senders can and can’t do within a jurisdiction. These best practices outline what they should do operationally to help improve email deliverability and to operate as a good citizen of the global Internet community.
Michael Adkins, then chairman of the board, M3AAWG — 10 March 2015, announcing Sender Best Common Practices v3.0, still the current version
✓
✗
!
Free contact list reality check
powered by Amino
Profile a list in your browser — nothing is uploaded →
What do the email and text-message rules actually say?
They are built on opposite defaults, and that is what makes a combined role hard. Both statutes are quoted here rather than summarised, and this post makes no assessment of any company’s compliance.
| Commercial email | Calls and texts to wireless |
| Statute | 15 U.S.C. § 7704 | 47 U.S.C. § 227 |
| Obligation triggered by | the recipient objecting | consent obtained beforehand |
| Quoted deadline | “more than 10 business days” | not applicable |
Email is written around objection
CAN-SPAM requires a working way to opt out and sets a deadline once someone uses it. From 15 U.S.C. § 7704(a)(4)(A), current through laws in effect on 27 August 2026:
If a recipient makes a request using a mechanism provided pursuant to paragraph (3) not to receive some or any commercial electronic mail messages from such sender, then it is unlawful— (i) for the sender to initiate the transmission to the recipient, more than 10 business days after the receipt of such request, of a commercial electronic mail message that falls within the scope of the request;
The obligation is triggered by the recipient objecting. The opt-out mechanism the same section requires must remain, in its words, “capable of receiving such messages or communications for no less than 30 days after the transmission of the original message.”
The wireless side is written around permission given first
The TCPA’s prohibition is worded the other way round. From 47 U.S.C. § 227(b)(1)(A), same currency date:
to make any call (other than a call made for emergency purposes or made with the prior express consent of the called party) using any automatic telephone dialing system or an artificial or prerecorded voice— … (iii) to any telephone number assigned to a paging service, cellular telephone service, specialized mobile radio service, or other radio common carrier service
Whether that provision reaches any particular sending setup is a legal question turning on the equipment used, and not one this post answers. The structural point stands on the words alone: one statute is drafted around a recipient objecting afterwards, the other around consent obtained beforehand.
Why does one job posting now carry two channels?
Because employers have started merging them, and fast. Fifteen of the 117 postings in this scan put email and SMS under a single owner — 1 in May, 1 in June, 5 in July and 8 in August. Eight of the fifteen say so in the job title, and seven read literally “Email & SMS”. Every one of the fifteen is consumer-facing: not most of them, all fifteen.
That is a staffing decision with a records consequence. One person now runs two channels whose permission models start from opposite ends, on a stack where the email side and the text side usually record consent in different systems. The technical half of that job is the same problem twice. The records half is two different problems that look alike.
We are not claiming those fifteen companies have a consent gap. We did not measure that and could not — the sub-sample is far too small to support a posture claim in either direction. What is unmistakable is the organisational pattern, and it is new. It is the consolidation we saw when one team inherited whether email lands taken a step further: not just which department owns a channel, but how many channels one person owns. Where that role is being created at director level, it comes with a budget.
What did we not measure?
Consent practice — at all. This is the important one. We measured DNS, which is public. We did not audit anyone’s permission records, because nobody outside a company can. The argument that consent is where the unexamined risk sits is reasoning from what is absent, not a finding. No shape in this dataset can express whether a company’s records are good.
- Causation. Regulated companies in this scan configure email better. We cannot show regulation caused it rather than sector age, audit culture, or security staffing that travels with it.
- Inbound posture. MTA-STS, TLS-RPT and DANE were recorded but excluded from “clean” — adoption across the sample is 1%, 2% and 1%, too sparse to separate cohorts.
- Sample construction. These are companies that posted a job, not a random sample of companies. Hiring for email is itself evidence of investment, which makes the 55% figure for non-regulated companies a generous one.
- A single point in time. Every domain was audited once. Configuration drifts, and nothing emails you when it breaks.
What should you do about it?
The finding cuts against the usual advice, so the action does too.
- If you are in a regulated sector, your authentication is probably fine — confirm it, then stop. A one-minute audit settles it. Another quarter spent there is displacement activity.
- Put the effort into records instead. For any address you mailed last month, can you produce when and where it opted in? That question has no public answer, which is exactly why it goes unasked.
- If one person owns email and SMS, write down which system is the source of truth for each channel’s consent. In this sample the merge is happening on the org chart faster than in the data.
- If you are not in a regulated sector, treat 55% as the base rate. Nearly half the comparable companies audited here had at least one outbound gap. Start by checking whether your DMARC is actually enforcing.
- Re-check after any platform change. Reputation and configuration do not travel with you when you move to a new sending platform.
Free tools
Key takeaways
- Regulated companies had zero outbound authentication gaps 91% of the time (20 of 22), against 55% for the other 95 companies in this scan.
- The gap survives controlling for company size, the dominant confounder in this dataset: CMH p=0.0045, stratified permutation p=0.0029.
- Not one of the 22 regulated companies publishes a weak 1024-bit DKIM key, against 11 of the other 95 — a defect RFC 8301 ruled out for DKIM signing in 2018.
- Only 24 of 117 postings mention compliance at all — 7 GDPR, 6 CAN-SPAM, 4 HIPAA, 1 TCPA.
- Fifteen postings merge email and SMS under one owner, and all fifteen are consumer-facing — two channels whose permission models start from opposite defaults.
FAQ
Does HIPAA or GLBA require SPF, DKIM and DMARC?
This post makes no claim about what any regulation requires of any company. What our scan measured is that companies operating under sector regulators had cleaner outbound authentication than comparable companies of the same size — 91% (20 of 22) against 55% (52 of 95). Why that is true is not a question a DNS audit can answer.
Is email consent the same as SMS consent?
The two statutes are drafted from opposite defaults. CAN-SPAM at 15 U.S.C. 7704(a)(4)(A) makes it unlawful to keep mailing more than 10 business days after the receipt of an opt-out request. The TCPA at 47 U.S.C. 227(b)(1)(A) frames its prohibition around calls made without the prior express consent of the called party. Whether either reaches a particular program is a legal question for counsel.
How many companies were in this sample?
117 companies that posted an email, lifecycle or marketing-operations role between 26 May and 15 August 2026, each audited over DNS on the date it entered the dataset. Twenty-two were classified as operating in a regulated vertical.
Is a sample of 22 large enough to conclude anything?
It is small, and no individual size band is significant on its own. The result rests on three size strata all pointing the same way, which pooled gives p=0.0045. We also ran a claim known to be false — consumer versus business-facing posture — through identical code, and it returned p=0.8410.
Can I check my own consent posture?
Not from outside, and neither can we. Our list posture tool examines a list you already hold, in your browser, without uploading it. Whether your permission records are defensible is a question only your own systems can answer.
Sources
- 15 U.S.C. § 7704, “Other protections for users of commercial electronic mail” — uscode.house.gov. Text current through laws in effect on 27 August 2026. Retrieved 28 August 2026.
- 47 U.S.C. § 227, “Restrictions on use of telephone equipment” — uscode.house.gov. Text current through laws in effect on 27 August 2026. Retrieved 28 August 2026.
- Michael Adkins, then chairman of the board, M3AAWG, quoted in “Updated M3AAWG Best Practices for Senders Urge Opt-In Only Mailings”, 10 March 2015. Quotation verified word-for-word against the release before publication.
- M3AAWG Sender Best Common Practices, version 3.0, February 2015 — m3aawg.org. Listed as the current version as of 28 August 2026.
- RFC 8301, “Cryptographic Algorithm and Key Usage Update to DomainKeys Identified Mail (DKIM)”, January 2018 — rfc-editor.org. Raises the DKIM signing floor to 2048-bit RSA.
- HireAmino regulated-cohort measurement — aggregate dataset: cohort counts, size-band breakdowns, both cohort definitions, the null control and every test statistic. Company-level rows are deliberately not published, because naming the clean majority would implicitly identify the rest.
- HireAmino deliverability hiring scan — n=117 postings from 117 distinct companies, sourced from Indeed, Glassdoor and applicant-tracking boards between 26 May and 15 August 2026. DNS measured with the open-source Amino audit engine, the same engine behind our free audit tool.
Free deliverability monitoring
powered by Amino
We watch your records and email you when one breaks →