격리 · Multi-Tenant SaaS
SaaS 제품을 위한 이메일 인프라
Multi-tenant 플랫폼에서 대규모 이메일을 보내려면 고객별 isolation, compliance, tenant별 reputation protection이 필요합니다.
공유 평판 풀
control plane 없음Ein missbräuchlicher Tenant vergiftet den Pool — jeder Kunde degradiert.
Sendarix로 격리
blast radius 제한Der schlechte Tenant wird in den eigenen Pool quarantined — alle anderen bleiben gesund.
Multi-tenant 이메일 문제
한 tenant의 나쁜 목록이 모두를 무너뜨려서는 안 됩니다.
제품이 customer.com을 대신해 yourplatform.com에서 발송하면, 한 고객의 실패가 모든 고객이 의존하는 공유 reputation에 영향을 줍니다.
전통적인 이메일 플랫폼은 tenant별 isolation을 제공하지 않습니다. 한 고객의 list quality가 나빠지면 다른 고객의 발신 reputation도 손상됩니다. Sendarix는 isolation을 기본 운영 단위로 만듭니다.
| Tenant | POOL | 신호 | 상태 |
|---|---|---|---|
| acme-corp | dedicated-ip-12 | Saubere Sends | 정상 |
| northwind | shared-eu-3 | 안정 | 정상 |
| tenant_8842 | quarantine-1 | Beschwerden steigen | 격리됨 |
| globex | shared-us-1 | 안정 | 정상 |
대표 제품 UI — 예시 데이터이며 실제 고객 지표가 아닙니다.
고객별 발신 domain isolation
각 고객은 자신의 verified domain에서 발송하므로 한 고객의 reputation 문제가 다른 고객에게 닿지 않습니다.
고객이 발신 domain을 소유
각 고객은 자신의 domain에 Sendarix를 가리키는 DKIM과 SPF를 설정합니다. DNS control은 고객에게 남고 Sendarix는 domain owner가 아니라 relay로 동작합니다.
White-label subdomain delegation
White-label subdomain(예: notify.customer.com)에서는 SPF가 subdomain과 Sendarix를 모두 authorize하고 DKIM은 white-label domain으로 서명됩니다.
IP pool isolation
대용량 고객은 독립 warmup과 reputation history를 가진 dedicated IP pool에 배정될 수 있으며 email routing rule로 관리됩니다.
Tenant별 suppression 관리
한 고객 목록의 bounce나 complaint가 다른 고객의 suppression을 유발해서는 안 됩니다. Suppression list는 domain별로 격리됩니다.
Tenant별 suppression scope
Customer A에서 hard bounce가 발생하면 해당 주소는 Customer A domain에만 suppression됩니다. Customer B가 독립 permission을 보유하면 계속 발송합니다.
Cross-tenant complaint 처리
Feedback loop는 발신 domain별로 설정됩니다. 한 tenant의 complaint는 다른 tenant의 reputation 또는 suppression list에 영향을 주지 않습니다.
고객 self-service suppression
API로 suppression 관리를 제공해 고객이 unsubscribe와 list hygiene을 지원팀 없이 처리하도록 합니다.
Tenant별 audit trail
Compliance를 위해 suppression event history를 domain별로 보관합니다. GDPR과 CCPA는 요청 시 문서화된 suppression을 요구하며 tenant isolation이 이를 audit 가능하게 합니다.
Tenant별 programmable routing
Multi-tenant 플랫폼용 routing rule
각 고객 domain은 domain verification 시 email routing rule로 programmatically 설정되는 독립 routing config를 받습니다.
Failover는 routing domain별로 독립 설정됩니다. Customer A의 primary IP pool이 저하되면 traffic은 shared pool이 아니라 그 고객의 backup pool로 이동합니다.
When sending_domain = customer.com Then route through customer_dedicated_pool apply customer_warmup_schedule use customer_suppression_list alert bounce_rate > 3% → customer@example.com
B2B SaaS 이메일 compliance 요구사항
Multi-tenant 이메일에는 고객이 상속하는 의무가 있습니다. Sendarix는 auditor가 기대하는 control을 제공합니다.
GDPR - data processing
제품을 대신해 처리되는 customer data에는 DPA가 필요합니다. Sendarix Enterprise는 GDPR-specific terms를 포함하며 suppression과 deletion event는 계약된 retention period 내에서 처리됩니다.
CAN-SPAM - unsubscribe 처리
모든 commercial email에는 functional unsubscribe가 필요합니다. Multi-tenant에서는 플랫폼 전체가 아니라 해당 고객 목록에서 unsubscribe되어야 합니다.
Healthcare SaaS 평가
Healthcare 플랫폼은 전송 전 message content에 PHI가 포함되는지 평가해야 합니다. 요구사항과 계약은 enterprise sales와 논의하세요.
Compliance review용 audit logging
Email event, suppression change, routing modification에 대한 audit log를 API로 제공하여 security 및 compliance review에 활용할 수 있습니다. security and compliance를 참고하세요.
고객별 monitoring과 alerting
각 고객 program에는 모든 고객에 대한 ops team이 아니라 올바른 고객에게 알리는 독립 threshold가 필요합니다.
24h rolling window에서 > 2%이면 alert. 수신자: 등록된 고객 email.
24h 동안 > 10%이면 alert. 임시 provider issue 또는 quota problem을 나타냅니다.
7일 동안 > 0.1%이면 alert. 0.3%에서는 대부분의 major provider가 filtering을 시작합니다.
고객의 30일 평균 대비 > 5 percentage points 하락 시 alert.
관련 제품
