Never drop a send because a provider is having a bad hour.
Four independent limit tiers — the rule, the provider, the pair, and the mailbox — each with per-minute and per-day dimensions. When a tier is full, the send waits in a visible queue and releases at the next window. Nothing is silently lost.
The launch email that never arrived.
It’s Tuesday 10 a.m., you clicked Send on the launch email, and 40 percent is throttled before lunch. The ESP silently dropped the retries. Nobody told the support team; they only found out when the customer emailed to complain that the launch never reached them. The refund policy update in the same message never landed either — and the compliance clock kept ticking as if it had.
Queue the overflow. Release at the next window.
When a limit fills, sendrules holds the overflow in a queue keyed to the tier that stopped it. Nothing is dropped. You can watch the queue drain against the release window in real time; you can redistribute overflow to a sibling provider on the same rule; you can override the hold if the send is time-critical and you accept the reputation cost. What you never do is find out on Wednesday that Tuesday’s launch didn’t land.
Four tiers of limits, in the order they apply.
Overflow is a visible hold, not a silent throttle.
Every held message shows up in Activity with the tier that stopped it, the current queue depth, and the projected release time. Your on-call team can see the shape of the backlog against the release window; your support team can answer “when will my customer get this?” without paging engineering. Overrides are logged with actor and reason, so a rushed release doesn’t become a mystery on Thursday.
A rule capped at a million. A provider capped at half.
Your marketing rule has a daily ceiling of one million. The primary provider under it has a contracted daily ceiling of five hundred thousand. A new IP on the same provider is on a warming ramp of twenty thousand a day. On a Tuesday, the marketing team schedules one-point-two million.
The first five hundred thousand go through the primary provider until its ceiling is reached. The queue promotes the next five hundred thousand to your secondary provider on the same rule. The remaining two hundred thousand hit the rule ceiling and hold until the next window — visible in Activity, on the release clock, with the option to raise the rule limit if the business needs them out tonight. The warming mailbox never sees more than its twenty thousand, because the mailbox tier caps it regardless of what the rule or provider allow.
The message you didn’t send is a bill you didn’t collect.
A dropped transactional email is a password reset that never arrived, an invoice that missed the payment window, a compliance notification that didn’t reach the recipient inside the statutory clock. A dropped marketing send is a launch that under-delivered without an explanation the CMO can act on. Neither shows up in the ESP dashboard as a failure — they show up as messages that were never sent, and by the time you notice, the customer has already noticed too.