University Email Usage and Bulk Messaging Standard
Purpose
This standard defines appropriate use of university email services and establishes requirements for sending bulk or broadcast messages. The goal is to protect message deliverability, institutional reputation, data security, and regulatory compliance while ensuring effective communication across the university community.
Scope
This standard applies to all faculty, staff, students, contractors, and university-affiliated systems that send email using university-managed domains or services.
Guiding Principles
- Individual mailboxes are intended for person-to-person or small-group communication.
- Bulk or broadcast messaging must use centrally managed services designed for scale, compliance, and monitoring.
- Email usage must align with data classification, audience context, and business purpose.
- Improper bulk email practices pose operational, security, and reputational risk to the university.
Appropriate Use of Individual Mailboxes
Individual user mailboxes may be used for:
- Direct correspondence
- Small group collaboration
- Academic and administrative communication tied to an individual’s role
Individual mailboxes must not be used for large-scale distribution, automated sending, or recurring announcements without IT approval for time-limited access to restricted distribution groups.
Appropriate Use of Shared Mailboxes
A shared mailbox is a centrally managed address accessed by multiple authorized users to support a functional role.
Shared mailboxes may be used for:
- Inbound functional communication (inquiries, service requests, departmental contact)
- One-to-one or small group replies related to an inbound request
- Supporting shared responsibilities across a team
Shared mailboxes may be used for bulk or broadcast messaging with approval from Information Security.
Bulk and Broadcast Messaging Requirements
Messages sent to large audiences (generally more than 250 recipients, recurring distributions, or automated messages) must be delivered through approved university messaging platforms.
Approved platforms provide:
- Rate limiting and delivery controls
- Sender authentication and domain protection
- List management and opt-out handling
- Logging, auditing, and reporting
- Reduced risk of spam classification or account suspension
Approved Platforms
Distribution Groups
- Announcements (w/approval)
- Working (w/approval)
- Students/Gradstudents/Lawstudents (w/approval)
- Department Groups
- Functional Groups
- Application User Groups
3rd-party platforms
- Moodle/Canvas/LMS
- RaveAlert
- MailChimp
- Qualtrics
- SendGrid
- Starrez
- Slate
- Symplicity
ListServ (lists.elon.edu)
Approved Bulk Messaging Use Cases
| Use Case | Approved Services |
|---|---|
| Academic & administrative announcements | Colleague, LMS (Moodle), academic/administrative distribution lists (approved senders), enterprise bulk email platforms |
| Emergency & safety notifications | Emergency notification systems (email/SMS/push) |
| University-wide or departmental broadcasts | Centrally managed and restricted distribution lists or communications platforms with approval |
| Events, programs, and engagement | Event platforms or marketing automation tools |
| Alumni, advancement, and external outreach | CRM and advancement messaging systems |
Bulk messaging must not be sent from personal mailboxes using BCC or expanded distribution lists.
Prohibited Practices
The following are not permitted:
- Mass emails sent from individual mailbox accounts
- Use of BCC to simulate bulk messaging
- Automated scripts sending email through user accounts
- Sending restricted or regulated data via bulk email
- Bypassing approved platforms for convenience
Data Protection & Compliance
- Email content must comply with data classification standards (e.g., FERPA, HIPAA, PCI).
- Sensitive or restricted data must not be transmitted via bulk email.
- External messaging must comply with applicable regulations (e.g., CAN-SPAM).
Exceptions
Exceptions require documented business justification and approval from IT and University Communications. Approved exceptions must be time-limited and reviewed periodically.
Responsibility
Senders are responsible for ensuring their email usage complies with this standard. IT and University Communications are responsible for maintaining approved messaging platforms and enforcing compliance.
Summary
Individual mailboxes are not broadcast systems and will be rate-limited to limit the amount of senders reached. Bulk or automated messaging must be conducted only through approved university services designed to ensure reliability, security, and accountability.
Addendum: Email Usage FAQs
General FAQ (All Users)
- Why can’t I just BCC a large group?
BCC-based distribution bypasses delivery controls, increases spam risk, and can result in account throttling or suspension. Approved bulk messaging tools protect both senders and recipients. - What counts as “bulk email”?
Generally, messages sent to more than 250 recipients, recurring announcements, automated messages, or communications to role-based audiences (e.g., all students, all staff). - What if I only need to send one message, one time?
If the audience is large or role-based, approved bulk messaging tools or distribution groups must still be used, even for one-time messages. - Can I send sensitive information by email?
Sensitive or restricted data must not be sent via bulk email. Follow university data classification and handling standards. - What happens if a use my email account to send a bulk message?
Message sending may be temporarily restricted for your account. If your account is restricted from sending messages due to sending a bulk message, please contact the Service Desk to resume sending.
Faculty FAQ
- How should I message students in my course?
Use the LMS (Moodle/Canvas) email function for course announcements and class-wide messages. Microsoft Teams provides an option to send email to channel participants.
Staff FAQ
- How do I send a message to all staff in my department?
Use centrally managed department distribution lists or approved communications platforms. - What should I use for operational notifications (e.g., outages)?
Approved IT or service management communication channels are used for operational notifications such as outages and campus-wide alerts. - What should I use for campus-wide announcements or blasts?
Please contact Information Technology for approval and time-limited access to send an email announcement to the Elon community.
Students & Student Organizations FAQ
- Can student organizations email all students?
Only through university-approved engagement or event platforms and in accordance with student communication policies. - Can I use my university email to promote events or causes?
Approved student engagement tools are used listed above. - What if I’m an officer of a recognized student group?
Work with Student Life or IT to access approved messaging tools.
IT, Developers & System Owners FAQ
- Can applications send email directly through SMTP?
Applications must use approved email services or APIs. Direct SMTP from applications or scripts is not permitted without vetting and approval. - Can we integrate third-party email services?
Yes, but only after security review and approval to ensure authentication, logging, and compliance controls are in place. - Are system-generated emails considered bulk messaging?
Yes. Automated or high-volume system emails must use approved services and follow this standard.
When in Doubt
If your message is:
- Going to many people
- Sent automatically or repeatedly
- Role-based (students, staff, alumni)
- External-facing
Use an approved bulk messaging service or contact IT/University Communications for guidance.