# Audit an email send before release

Email teams can miss consent, suppression, authentication, and claim risks before a campaign launches. This skill applies a structured SEND review and states the evidence, gaps, score state, and release verdict.

## Install

```bash
npx skillstore add aaron-he-zhu/email-quality-auditor
```

## Metadata

- Status: approved
- Slug: aaron-he-zhu-email-quality-auditor
- Version: 19.0.0
- Author version: 19.0.0
- Skillstore revision: r2
- Version status: valid
- Tree hash: 0cc51e76ae8e55c64d63dc65db74fe93065bea75cc981dcf607aa71248fbebea
- Author: aaron-he-zhu
- GitHub username: aaron-he-zhu
- License: Apache-2.0
- Repository: https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/email/deliver/email-quality-auditor
- Ref: adcb3549b15782055d0beb6d29f113d20de08f92
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: allowed
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands, network, filesystem
- Quality score: 77
- Quality tier: bronze
- Public page: https://skillstore.pages.dev/skills/aaron-he-zhu-email-quality-auditor
- Manifest: https://skillstore.pages.dev/api/skills/aaron-he-zhu-email-quality-auditor/manifest

## Capabilities

- Reviews one email program or planned send within a declared observation window.
- Evaluates 20 SEND criteria using dated evidence and confidence labels.
- Checks authentication, consent, suppressions, claims, engagement, and outcome evidence.
- Separates verified blockers from unknown or missing inputs.
- Produces SHIP, FIX, BLOCK, or UNDECIDED outcomes when evidence supports them.
- Explains measurement limits for open rates and Apple Mail Privacy Protection.

## Use Cases

- Release a promotional campaign: Check a planned promotion for authentication, consent, opt-out, and claim blockers before the marketing team sends it.
- Assess newsletter program health: Review a newsletter over a defined period and identify evidence gaps, engagement caveats, and operational fixes.
- Prepare an audit record: Create an evidence-based readiness assessment that separates verified controls from unknown inputs for internal review.

## Prompt Templates

### Review a newsletter

```
Audit this newsletter for the last 90 days. I will provide provider reports, consent records, suppression status, and campaign results.
```

### Check a promotional send

```
Review this promotional email before release. Check DMARC, consent events, live suppressions, rendered copy, and order evidence. Mark missing evidence as Unknown.
```

### Compare provider cohorts

```
Audit this retention program across providers for the declared window. Reconcile cohorts, segment Apple Mail Privacy Protection exposure, and assess direct actions separately from opens.
```

### Request a release trace

```
Perform a SEND audit for this cold-outbound program. Provide a trace for each veto check, list source dates and confidence, and return UNDECIDED if evidence is incomplete.
```

## Limitations

- It does not send email or change provider settings.
- It cannot prove inbox placement from DNS records alone.
- It needs current consent, suppression, provider, and outcome evidence for a complete score.
- It does not replace legal advice or a formal compliance review.

## Best Practices

- Provide dated source evidence for each claim, metric, and control.
- Declare the program type, market, provider, and observation window before scoring.
- Treat unknown evidence as unknown instead of assuming a control passed.

## Anti Patterns

- Do not use open rate alone to claim recipient attention or campaign success.
- Do not treat missing consent records as proof that consent exists.
- Do not request a release verdict without current suppression and claim evidence.

## Security Audit

- Audited at: 2026-07-26T10:14:54.622\+00:00
- Summary: All 34 static findings are false positives caused by Markdown backticks, fixed local reference links, and homepage metadata. The reviewed instructions emphasize evidence-based email audits, prohibit autonomous sending and provider changes, and require explicit authorization before persistence. No prompt injection, exfiltration intent, or user-controlled command or path execution was found.

## Stats

- Views: 1
- Downloads: 5
- Favorites: 0
- Popularity score: 0
