AudienceVerify

Independent verification for newsletter sponsorships

Your open rate is not a number.
It is an estimate of Apple's behaviour.

Apple Mail Privacy Protection opens your email before your reader does. Every media kit in this industry is priced off a metric that stopped meaning anything in 2021 — and the platforms that verify it are the same ones taking a cut of the deal.

We verify a different number, we publish the rules we use, and we take nothing from the transaction.

Verify your newsletter — free Read the standard

What we publish, and what we refuse to

FigureHow we treat it
Verified CTR The headline. Unique clicks ÷ delivered volume, trailing 90 days, read from your ESP. A click needs a human.
Verified Delivered Published where the source attests it. Where a source can only report sent, we publish that instead and label it a proxy.
List size and velocity Published. Velocity is marked derived with its formula, because we compute it from our own history rather than reading it from anywhere.
Open rate Shown, with the MPP exposure note attached — and excluded from every ranking and filter on this site. It is not a price signal.
Anything the source cannot attest Left blank and named. We do not estimate a figure and we never upgrade one to a stronger provenance than it arrived with.

Those rules are a versioned public document, not a policy we can quietly change: the AudienceVerify Standard 1.0.0-draft.

Verified newsletters

Ranked by Verified CTR. Open rate is not used, here or anywhere else on this site.

#PublicationNicheVerified CTRDelivered (90d)Verified
No fully verified publications yet.

Get verified

Free, and it stays free. It is not locked to a marketplace, because we do not run one. Read what we do with your credential before you paste one.

Next you prove control of the sending domain with a DNS TXT record or a file on your site, and then the badge issues.

What each source can attest

SourceDeliveredUnique clicksResulting tier
beehiiv yes yes full
Kit proxy only not exposed partial

What we do with your credential

We are asking you to connect the system that holds your subscriber list. Here is exactly what we do with it, and what we deliberately cannot do.

We never store your subscribers. A sync reads your campaign statistics, computes the aggregates in the standard, and discards the API response. There is no table in our database that can hold an email address or a per-recipient event. That is structural, not a policy we have to remember to follow.

We prefer read-only access. Where an ESP offers scoped OAuth we request read-only scopes and nothing else. Sources that only issue full-access API keys are supported, and we say so here and on every attestation.

SourceAccess we requestNotes
beehiiv read-only OAuth Read-only OAuth scopes publications:read and posts:read. Exposes a bot-filtered unique click figure (unique_verified_clicks).
Kit API key v4 exposes recipients (sent, not delivered) and total_clicks only. No unique-click field, so Verified CTR cannot be issued for Kit publications.

Credentials are encrypted under a key held outside the database, so a database leak alone does not expose them. We are a small operation on a single server and we do not run a managed key service — preferring read-only sources is what actually limits the blast radius, and we would rather state that plainly than imply more.

We verify the domain, and we say how. Before a badge issues you prove control of the sending domain, by DNS TXT record or by a file on the site. Every attestation names which of the two we accepted, because "verified domain" without saying how is exactly the kind of unexamined claim this project exists to argue against.

What we log about visitors: the public forms are rate limited, so we store per submission a keyed hash of the caller's address and a timestamp, under the same key that encrypts credentials. No readable IP address is kept, the rows expire within the hour, and nothing about them is history.

You can revoke us at any time. Withdraw the credential in your ESP and the next sync fails. We do not publish a zeroed figure when that happens; your last attestation simply ages and is marked stale after 35 days. The failed read does appear on your attestation, as a dated gap with a coarse reason — a trail with silent holes in it would be worth nothing to the sponsor reading it. The underlying error text is not published.

For sponsors

Every attestation carries its provenance: which figure came from the ESP API, which was derived, and which the source could not supply at all. Where a number cannot be verified, we say so instead of estimating it.

Revocation list

A certification that cannot be lost is worthless. Every withdrawn attestation is listed here permanently, with its reason.

PublicationRevokedReason
No revocations to date.