Email Marketing & Newsletter
Dotdigital
Provenance unknown Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Dotdigital Group plc · dotdigital.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Persona-weighted verdicts run 4.7 to 6.2. Dotdigital is a SaaS marketing platform for automated, data-driven campaigns across email and SMS; its strongest scored area is integrations, clustered at 7: over 200 named integrations, tiered per-minute API rate limits published per package, and program webhooks that reach almost any RESTful API. Campaign and automation scores run 6 to 7 on the no-code journey builder, with abandoned-cart enrolment, exit conditions and A/B testing. The weakest counted criterion is sovereignty, 3 to 4: the trading entity is UK-registered, EU hosting is one account-region option alongside US and Australia, and the privacy policy states information may be stored and processed in any country, including the United States, under the Data Privacy Framework and standard contractual clauses. Consent and proof spreads widest, 4 to 6: lower scores weigh double opt-in enforced by default only for signup forms and some API methods, plus bulk imports landing on an unknown opt-in type; the higher mark credits vendor-held proof for verified double opt-ins. Pricing transparency scored 0 to 1, reported but not counted; no prices are published.
Speaks for it
- Over 200 integrations named, including Shopify, Adobe Commerce, BigCommerce, Microsoft Dynamics and Salesforce
- API rate limits published in tiered per-minute detail per package
- Program webhooks reach almost any RESTful API with selectable authentication methods and per-minute rate limiting
- SPF, DKIM and DMARC documented in depth, with vendor-provided records and 2048-bit DKIM keys as the default
- Contact export covers single contacts, bulk, lists and automation programs, framed for subject access requests
Held against it
- EU hosting is an account-region option alongside US and Australia rather than a guarantee
- The privacy policy states information may be stored and processed in any country, including the United States, under standard contractual clauses and the Data Privacy Framework
- Double opt-in is enforced by default only for signup forms and some API methods, with bulk imports landing on an unknown opt-in type
- We found no public information on exporting engagement history, campaigns or templates
- We found no public information on dedicated-IP warm-up, seed or inbox-placement testing, or engagement-based sunsetting
Best for
- You run an e-commerce lifecycle programme and want abandoned-cart journeys plus Shopify, BigCommerce or Adobe Commerce connectors
- Your developers build and test their own integrations and want published rate limits plus webhooks to almost any RESTful API
- You want a no-code journey builder across email and SMS with exit conditions and A/B testing of copy, CTAs and design
Avoid if
- You need guaranteed EU data residency or an EU-registered contracting entity — EU hosting here depends on the account's region, and the trading entity is UK-registered
- You rely on bulk imports and expect vendor-held proof of consent for every contact — imports land on an unknown opt-in type by default, and vendor-held proof is documented only for Verified double opt-in
- You must take engagement history, past campaigns and templates with you when you leave — we found no public information on exporting these
- You want deliverability operated as a service — we found no public information on dedicated-IP warm-up, seed or inbox-placement testing, or engagement-based sunsetting
The scores
Campaigns & automation
Show reasoningHide reasoning
How this is scored
Building the mail and the journey around it: editor, templates, segmentation, triggered sequences, A/B testing.
0 — One-off broadcasts from a fixed template; no segmentation and no automation of any kind.
3 — A drag-and-drop editor and simple list segmentation, but automation is a single welcome mail and there is no testing.
5 — Reusable templates, attribute and behaviour segmentation, multi-step automations on common triggers, and subject-line A/B testing.
8 — A visual journey builder with branching on behaviour and data, dynamic content per segment, send-time optimisation, and testing that reports significance rather than raw counts.
10 — Journeys treat the whole lifecycle: event-driven entry from other systems, branching on any attribute or event, holdout groups for measurement, and automations a marketer can read months later without a diagram.
The CRM Manager
The program builder is documented with exit conditions, program nodes and triggered enrolment on list joins, unsubscribes and abandoned carts, and the pages show A/B testing across copy, CTAs and design plus segmentation from behavioural, order and preference data. What I cannot see is branching on event data, send-time optimisation, or split tests that report significance rather than raw engagement — for a lifecycle programme, that last gap is the one that stings. 1 4 5 7
The Deliverability Engineer
The no-code program builder with exit conditions and validation, abandoned-cart enrolment, welcome and unsubscribe triggers, cross-channel automation into Facebook and Google audiences, and A/B testing of copy, CTAs and design clears the journey-builder level. We found no public information on send-time optimisation or tests that report statistical significance, so it stops short of the top. 1 4 5 7
The Data Protection Officer
The no-code program builder runs multi-step, multi-channel journeys — list-join, unsubscribe, abandoned-cart and reply triggers across email, SMS and social — with segmentation, personalisation built on behavioural and order data, and A/B testing of copy, call-to-actions and design. We found no public information on send-time optimisation, on testing that reports statistical significance rather than raw engagement, or on holdout groups for measurement, which keeps a strong journey tool short of the top. 1 4 5 7
The Shop Owner
The no-code program builder runs multi-step journeys with exit conditions, and the documented abandoned-cart program is exactly the flow that earns its keep in my shop; triggered campaigns across email, SMS and MMS, welcome-on-list-join, autoresponders, A/B testing of copy, CTAs and design, and segments built from order and behaviour data are all evidenced. I found no public information on send-time optimisation, significance reporting for tests, dynamic content per segment, or holdout groups, so I stop short of the higher marks. 1 4 5 7
The Integrator
The no-code program builder is a real journey tool — triggered campaigns on list joins and unsubscribes, abandoned-cart enrollment, daily and weekly scheduling, exit conditions, and A/B testing of copy, CTAs and design — with a substantial documentation collection behind it. I found no public information on branching on behaviour or data, dynamic content per segment, send-time optimisation, or tests that report significance rather than raw counts, which is what the top of this criterion asks for, so I place it one step above the middle. 1 4 5 7
The Skeptic
The program builder is documented as a no-code journey tool with exit conditions, enrolment on list join or unsubscribe, abandoned-cart and welcome programs, and A/B testing of copy, call-to-actions and design, across email, SMS and ad audiences. We found no public information on branching on arbitrary data, send-time optimisation, or A/B results reported with significance, which is what the top of the scale asks for. 1 4 5 7
Deliverability infrastructure
Show reasoningHide reasoning
How this is scored
Whether the mail arrives — authentication, sending reputation, bounce and complaint handling — judged on what the vendor documents rather than the inbox rate it advertises.
0 — No documentation of authentication or bounce handling; deliverability appears only as a marketing number.
3 — SPF and DKIM setup documented, but no DMARC guidance, no stated bounce policy and shared sending only.
5 — SPF, DKIM and DMARC documented with a custom sending domain, automatic hard-bounce suppression, and complaint-loop handling stated.
8 — The above plus dedicated-IP options with a documented warm-up, seed or inbox-placement testing, engagement-based sunsetting, and published guidance on list hygiene.
10 — Deliverability is operated as a service: reputation monitoring surfaced to the customer, per-domain and per-ISP diagnostics, enforced authentication before first send, and postmaster or blocklist handling the vendor documents doing on the customer's behalf.
The CRM Manager
SPF, DKIM and DMARC are documented with vendor-provided DNS records and a default DMARC policy, hard bounces are suppressed automatically with soft bounces classified and converted, and a sender-reputation score built from opens, clicks, complaints, bounces and Data Watchdog results is surfaced inside the account — though only for shared-IP senders. I found no public information on dedicated-IP warm-up, seed or inbox-placement testing, or engagement-based sunsetting. 6 7
The Deliverability Engineer
SPF, DKIM and DMARC are documented with vendor-provisioned DKIM records and custom from addresses, hard bounces are auto-suppressed, persistent soft bounces convert to hard, and a sender reputation score built from open, click, complaint and bounce levels is surfaced in the account and recalculated every 30 days — documentation, not an advertised inbox rate. We found no public information on dedicated-IP warm-up, seed or inbox-placement testing, or engagement-based sunsetting, which is what separates this score from the next. 6 7 9
The Data Protection Officer
SPF, DKIM and DMARC are documented for a custom sending domain, with vendor-provided DNS records, 2048-bit DKIM as the default and DMARC reporting routed to the vendor; hard bounces are suppressed automatically, persistent soft bounces are converted, and a sender-reputation score is surfaced in the account and recalculated every 30 days from opens, clicks, complaints and bounces. We found no public information on dedicated-IP warm-up, seed or inbox-placement testing, or engagement-based sunsetting; the reputation feature covers shared-IP accounts only, and complaint suppression is documented as advice to the sender rather than handling the vendor states it performs. 6 7 9
The Shop Owner
SPF, DKIM and DMARC are documented in detail — default policy levels, 2048-bit keys, records provided during setup — with stated compliance to the Gmail, Yahoo and Microsoft authentication requirements, and hard bounces are suppressed automatically while persistent soft bounces are converted. A sender-reputation screen, evaluated every 30 days from opens, clicks, complaints, bounces and Data Watchdog scores, is surfaced in the account for shared-IP senders. I found no public information on dedicated-IP warm-up, seed or inbox-placement testing, or engagement-based sunsetting. 6 7
The Integrator
Authentication is properly documented — SPF, DKIM and DMARC with a vendor-provided DKIM record, default DMARC monitoring, and stated compliance with the Gmail, Yahoo and Microsoft requirements — hard bounces are suppressed automatically, persistent soft bounces convert to hard, and a sender-reputation score is surfaced in account settings with named indicators. I found no public information on dedicated-IP warm-up, seed or inbox-placement testing, or engagement-based sunsetting, so this is well-documented infrastructure rather than deliverability operated as a service. 6 7 9
The Skeptic
SPF, DKIM and DMARC are documented in real depth — key sizes, DMARC policy options, BIMI's enforcement requirement — hard bounces are suppressed automatically, persistent soft bounces are converted, and an in-account sender-reputation readout is recalculated every 30 days. We found no public information on dedicated-IP warm-up, seed or inbox-placement testing, or engagement-based sunsetting; the reputation feature is documented as available to shared-IP accounts only, and DMARC ships configured to a 'none' policy with changes routed through support. 6 7
Consent, proof & tracking limits
Show reasoningHide reasoning
How this is scored
How subscribers arrive and what the sender can prove afterwards: double opt-in, logged consent, unsubscribe handling, and whether open and click tracking can be limited or switched off.
0 — Single opt-in with no consent record; tracking is always on and cannot be disabled.
3 — Double opt-in available but not the default, and the consent record is a timestamp without the source, IP or the wording consented to.
5 — Double opt-in as the documented default with a stored consent record including source and timestamp, one-click unsubscribe, and tracking that can be turned off per campaign.
8 — Consent is reproducible as evidence: the confirmation mail and form wording versioned and retrievable per subscriber, unsubscribe honoured across lists, tracking off-by-default available, and retention rules for inactive subscribers.
10 — Built for the burden of proof: a per-subscriber consent history an authority would accept, documented handling of Art. 15 access and Art. 17 erasure requests, pixel-free and link-tracking-free sending as a supported mode, and preference-centre granularity rather than all-or-nothing.
The CRM Manager
Verified double opt-in is documented with vendor-held proof of confirmation, a customisable confirmation mail, rate limits on confirmation sends and automatic expiry of pending contacts after 30 days, and the default regulatory setting enforces it for signup forms and some API methods — though bulk imports land on an unknown opt-in type. The captured pages describe a consent view of opt-in type and last subscribed date with no source, IP or wording shown, tracking that can only be switched off for transactional sends, and an unsubscribe that may take up to 24 hours to take effect. 2 4 8 9
The Deliverability Engineer
Double opt-in is enforced by default only for signups from forms and some API methods, bulk imports default to an unknown opt-in type, and the vendor states it does not hold the consent record for double opt-ins — though proof of verified double opt-ins is kept in its records and a single-contact export is documented as supporting subject access requests. Tracking can be turned off for transactional mail only, while a preference centre and 30-day auto-expiry of pending contacts lift this above the middle. We found no public information on versioned and retrievable form wording, or tracking off by default for marketing sends. 4 8 9 10
The Data Protection Officer
Verified double opt-in is engineered well — addresses stay off lists until confirmation, bot sign-ups and complaints are named risks it guards against, confirmation mails are capped and expire, and pending contacts auto-expire after 30 days — but the documented default enforces it only for signup forms and some API methods, imported contacts start with an Unknown opt-in type, and API additions can bypass pending status when double opt-in is off. The captured pages give different accounts of consent proof: one states the vendor does not hold the record of consent for double opt-ins, another that proof of Verified double opt-in is kept in vendor records, and nothing documents what that proof contains beyond a subscribed date and an opt-in type. Open tracking is an invisible pixel, the tracking switch we found covers transactional mail only, and an unsubscribe may take up to 24 hours to process. 2 4 7 8 9
The Shop Owner
Double opt-in is available and recommended, but the documented default enforces it only for signup forms and some API methods, and bulk imports arrive with an unknown opt-in type. The captured pages describe the consent record differently for verified double opt-in, where the vendor keeps proof in its records, versus other double opt-ins, where it says it does not hold the record and I must have it available; the single customer view shows a subscribed date and opt-in type without source or wording. Open and click tracking can be turned off for transactional mail, and I found no public information on switching tracking off for marketing campaigns. 2 4 7 8 9
The Integrator
Verified double opt-in is engineered seriously — customisable confirmation mail, a cap of four confirmation emails, rate limiting, pending contacts expiring after 30 days, and proof of consent kept in the vendor's records for verified opt-ins — but the documented default only enforces double opt-in for signup forms and some API methods, plain double opt-ins get no vendor-held consent record, and bulk imports land on an unknown opt-in type. Tracking can be switched off only for transactional emails while opens are recorded by an invisible pixel, and an unsubscribe can take up to 24 hours, which leaves this just below the middle of the criterion. 2 4 8 9
The Skeptic
Verified double opt-in keeps proof of the opt-in in the vendor's records, with rate-limited confirmation mails that expire, auto-expiry of pending contacts after 30 days, and a preference centre. But the default regulatory setting enforces double opt-in only for signup forms and some API methods — bulk imports land as 'Unknown' opt-in type unless switched — the vendor states it does not hold the consent record for standard double opt-ins, and a tracking off-switch is documented only for transactional mail, with unsubscribe taking up to 24 hours. 2 4 7 8 9
List ownership, import & exit
Show reasoningHide reasoning
How this is scored
Whether the list and its history remain the sender's: import with attributes intact, full export including engagement history, deletion that executes, and no metering that prices leaving out of reach.
0 — Export is addresses only; engagement history, segments and automations cannot leave.
3 — CSV import and export of subscriber fields, but engagement history and unsubscribe state are not exportable.
5 — Full subscriber export including custom attributes, subscription status and unsubscribe state, plus API access sufficient to sync elsewhere.
8 — Everything exportable in open formats — subscribers, engagement history, campaigns and templates — with documented deletion of a subscriber across all records, and no export throttling.
10 — Exit is a documented feature: full-fidelity export of the whole account, contractual data return, deletion that is evidenced rather than asserted, and migration tooling in both directions.
The CRM Manager
Contact export is documented in single, bulk, list and program scopes covering all contact data fields plus per-contact Insight data as JSON, CSV import supports partial updates, column skipping and correction of wrong mappings, and there is an API with published rate limits to sync elsewhere. I found no public information on exporting engagement history, campaigns or templates, on full-account export, or on export throttling; exported files are kept for seven days. 4 10 11 12
The Deliverability Engineer
Contacts can be exported one at a time, in bulk, or from lists and automation programs — a CSV of every contact data field plus Insight data as JSON per collection — and CSV import supports partial updates and corrected re-imports. We found no public information on exporting engagement history, unsubscribe state, campaigns or templates, on documented deletion across all records, or on full-account export, so only the subscriber record itself is documented as exportable. 10 11
The Data Protection Officer
Contact export is genuinely granular — a single contact as CSV of all data fields plus per-collection insight data in JSON, in bulk, from lists and from automation programs, with requester tracking — and the CSV import path documents partial updates, skip options and field correction. We found no public information on exporting engagement history, campaigns or templates, on whole-account export or contractual data return, and deletion of a contact is referenced only as a program action without documentation of it executing across all records. 4 10 11
The Shop Owner
Contacts can be exported singly, in bulk, from a list or from a program, with every contact data field in CSV and Insight data as JSON, and the CSV import path handles partial updates and field corrections — my customer attributes can leave with me, over an API documented well enough to sync elsewhere. Deletion of contacts is available through programs and manual suppression-area actions. I found no public information on exporting engagement history or past campaigns and templates, or on deletion evidenced across all records; export files are retained for 7 days and gated behind exporter permissions. 4 10 11 12
The Integrator
CSV import is handled with care — partial updates, skip-column, preserved identifiers, and re-import to fix wrong mappings — and export covers single contacts with all data fields plus insight data as JSON, bulk, per-list and per-program exports, retrievable for seven days with the requester tracked, and programs can delete contacts from the account. I found no public information on exporting engagement history, unsubscribe state, campaigns or templates, so I stop at the middle: the subscriber record can leave, the history apparently cannot be shown to. 4 10 11
The Skeptic
Contacts export to CSV with insight collections in JSON, individually, in bulk, from lists or from automation programs, explicitly framed for subject access requests, and the CSV import path handles partial updates, skip-columns and re-import to fix bad mapping. We found no public information on exporting engagement history, campaigns or templates; exported files are stored for only 7 days, and a documented full-account exit is absent from the captures. 2 4 10 11
Integrations & API
Show reasoningHide reasoning
How this is scored
The connection surface a newsletter lives on: shop and CRM systems, events in and out, webhooks, and an API somebody can build against without a partner agreement.
0 — No API and no named integrations; the list is maintained by CSV upload.
3 — A handful of native integrations and a read-mostly API, with no webhooks and no documented rate limits.
5 — Named integrations for common shop and CRM systems, a documented REST API with keys, and webhooks for the core subscriber events.
8 — Maintained bidirectional integrations with named systems including at least one major shop platform, event webhooks with retries, documented rate limits, and a sandbox.
10 — The tool is a component rather than a destination: transactional and marketing sending on one API, events flowing both directions, versioned API with a deprecation policy, and integrations the vendor maintains rather than lists.
The CRM Manager
Over two hundred integrations are advertised with named shop and CRM platforms including Shopify, Salesforce and Microsoft Dynamics, API rate limits are published in tiered detail per package, and program webhooks reach almost any RESTful API with real-time messaging-event webhooks, configurable authentication and testing against a contact before activation. I found no public information on webhook retries or redelivery, a sandbox environment, or API versioning with a deprecation policy. 1 12 13
The Deliverability Engineer
Over 200 integrations with named major shop and CRM platforms including Shopify, BigCommerce and Adobe Commerce, real-time messaging-event webhooks, program webhooks that can talk to almost any RESTful API with selectable methods, authentication types and per-minute rate limiting, plus tiered API rate limits published per package. We found no public information on webhook retries or a sandbox, which is what this level asks for on top. 1 12 13
The Data Protection Officer
Over 200 integrations with named major platforms including Shopify, Salesforce and Microsoft Dynamics; program webhooks that reach almost any RESTful API, real-time messaging-event webhooks with a choice of authentication types, reusable templates and a test step; and rate limits documented per tier and package with a stated path to raise them. 1 12 13
The Shop Owner
Shopify, BigCommerce, Adobe Commerce and Shopware are named among over 200 integrations, and consent-based e-commerce linking is documented — the orders-and-carts plumbing I need. Program webhooks reach almost any RESTful API with authentication options, per-request rate limiting, reusable templates and testing against a contact, and API rate limits are published per package down to the tier, with transactional mail on SMTP or API. I found no public information on webhook retries or a sandbox, the vendor leaves request code to your own developers, and e-commerce integration runs partly through named suppliers rather than entirely in-house. 1 2 3 12 13
The Integrator
This is the part I can actually wire in: published rate limits per package with tiered per-minute numbers, webhooks inside the journey builder that call almost any RESTful API with selectable authentication, global headers, method, content-type and per-minute throttling plus a test before sending, named connectors including Shopify, BigCommerce and Adobe Commerce, transactional sending by SMTP or API, and a real-time messaging-events webhook. 1 3 12 13
The Skeptic
Over 200 integrations are named, including Shopify, Adobe Commerce, BigCommerce, Microsoft Dynamics and Salesforce, and API rate limits are documented in unusual detail — tiered per-minute limits per package, with a support path to raise them. Program webhooks reach almost any RESTful API with configurable authentication, methods and rate limiting; we found no public information on webhook retries, a sandbox, or an API versioning and deprecation policy, and the vendor writes that webhook request code is the customer's to provide and test. 1 3 12 13
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where subscriber data and behavioural tracking live, who the contracting entity is, and which subprocessors touch the send. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which in this category is heavily.
0 — US vendor and contracting entity, US hosting, subprocessors unnamed; subscriber behaviour leaves the EU with no stated basis.
3 — EU hosting offered as an option or for storage only, while sending, tracking or support access remains non-EU, or the subprocessor list is absent.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — sending infrastructure, analytics, support tooling — are non-EU without an explained safeguard.
8 — EU or DACH hosting with a named data-centre provider, EU contracting entity, complete subprocessor list published, and any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, entity, hosting, sending and every subprocessor in the EU, certification published, and no transfer that needs a Schrems II argument to survive.
The CRM Manager
The EU region is offered as an option on named Azure and Google facilities, while the contracting entity, dotdigital EMEA Limited, is UK-registered with a Dutch subsidiary as EEA representative, and the privacy policy states information may be stored and processed in any country with facilities or service providers, including the United States. The subprocessor list is published and includes US providers, with the Data Privacy Framework and Standard Contractual Clauses named as the transfer mechanisms — which, as I weigh it for a European list, is reliance on transfer safeguards rather than sovereignty. 2 3
The Deliverability Engineer
The contracting entity is UK-registered with a Dutch affiliate as EEA representative, EU hosting depends on the account's region rather than being standard, and the privacy policy states information may be stored and processed in any country with facilities or service providers, including the United States, under Standard Contractual Clauses and the Data Privacy Framework. A subprocessor list is published naming Azure, Google Cloud, Cloudflare, ClickHouse and Partner Hero among others, several of them non-EU, and I weigh that chain heavily for this category. 2 3 8
The Data Protection Officer
An EU region is named facility by facility on Azure and Google Cloud, a subprocessor list with purposes is published, and EU model clauses and a Data Privacy Framework posture are stated — but the trading entity is UK-registered with the Dutch subsidiary only as EEA representative, EU residency depends on the account's region rather than being guaranteed, and the privacy policy reserves storage and processing in any country with facilities or service providers, including the United States, resting on Standard Contractual Clauses. Where a subscriber's behavioural data lives is therefore answered only by a transfer argument, with US group companies and US-hosted regions in the chain, which I weigh heavily against. 2 3
The Shop Owner
The contracting entity is UK-registered with a Dutch subsidiary as EEA representative; EU hosting exists as an account region on named Azure and Google facilities, while the privacy policy states information may be stored and processed in any country with facilities or service providers, including the United States. A subprocessor list with names and purposes is published, transfers rest on standard contractual clauses and the Data Privacy Framework, and ISO 27001, ISO 27701 and Cyber Essentials Plus are verifiable. I weigh this heavily, and region-dependent residency with non-EU support and sales tooling keeps me at a middling mark. 2 3
The Integrator
The contracting entity is UK-registered with a Dutch subsidiary named as EEA representative, EU hosting is one selectable region alongside US and Australia rather than a standard, and the privacy policy states personal information may be stored and processed in any country where the vendor has facilities or providers, including the United States, under Standard Contractual Clauses and the Data Privacy Framework. A subprocessor list is published on the trust page, which earns real credit, but support runs through Zendesk and Intercom, and as a buyer weighing this heavily I take a UK entity with region-dependent EU residency as the lower end of this criterion. 2 3
The Skeptic
The contracting entity is UK-registered with a Dutch subsidiary named only as EEA representative, EU hosting is one region option alongside US and Australia regions, and the privacy policy states information may be stored and processed in any country including the United States under the Data Privacy Framework and standard contractual clauses. A subprocessor list is published on the trust page, which lifts this off the floor, but it includes US-headquartered services for analytics, logs and support, and we found no public information on where the sending infrastructure itself sits. 2 3
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a sender can compute the real invoice for their list size and send volume — including overage, extra domains and automation limits — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A headline price per contact tier exists, but send limits, overage rates or the tier where automation begins are not stated.
5 — Contact-tier prices public with the billing period stated and send limits given, but at least one commonly needed capability sits in an unpriced tier or add-on.
8 — Every tier priced publicly with contact and volume limits, overage rates, feature boundaries and VAT treatment stated; only genuinely custom volume lacks a number.
10 — Complete price computability: a calculator producing the annual invoice for a given list size and send frequency, including overage, additional domains and dedicated IPs.
The CRM Manager
We found no public information on prices in the captured pages — no tier prices, send limits, overage rates or VAT treatment, and the packages that appear are named Standard and Enhanced without a number. As far as the public record shows, the real invoice is a sales conversation. 1 12
The Deliverability Engineer
We found no public information on pricing on the captured pages: no contact-tier price, no billing period, no send limits, no overage rates and no VAT treatment, and even the API packages that govern call rates are named without a price. A buyer cannot compute an invoice from what is published, which is the bottom of this scale. 1 12
The Data Protection Officer
We found no public pricing information on any captured page — no tier prices, no stated send limits, no overage rates, no VAT treatment — while the captured material names packages tied to a Customer Success Manager for commercial changes. A sender cannot compute even a rough invoice for their list size and send volume from what is published here. 1 12
The Shop Owner
I found no public information on prices anywhere in the captured pages: no contact tiers, no send limits, no overage rates, no VAT treatment. Packages appear only as names — Email & SMS marketing and CXDP — each attached to API rate limits, and anything beyond runs through a Customer Success Manager. As a shop that has to know the invoice before committing, I have nothing to compute from. 1 12
The Integrator
I found no public information on prices of any kind — no contact tiers, no send limits, no overage rates — and the only commercial signals are 24/7 live chat, dedicated onboarding and your own CSM, which reads as a sales-led motion. A buyer cannot begin to compute an invoice from what is published. 1
The Skeptic
We found no public information on prices, contact tiers, send limits or overage rates on any captured page; the only tier structure visible anywhere is internal package names for API rate limits, with increases routed through a Customer Success Manager. A buyer cannot compute any invoice from what is published here. 1 12
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in GB ⚠ unverified | 1/3 pts | 2 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU optional ⚠ unverified | 1/3 pts | 3 Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. The trading entity dotdigital EMEA Limited is UK-registered (outside the EU/EEA), with Dutch subsidiary Dotdigital B.V. named as the EEA representative.
- Weak sourcing — Data residency. EU storage depends on the account's region rather than being guaranteed, and the privacy policy states information may be stored and processed in any country with facilities or service providers, including the United States.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on pricing on the pages we read (dotdigital.com, dotdigital.com/terms/privacy-policy, dotdigital.com/trust-center, marketing.help.dotdigital.com/en/collections/5621923-automation, marketing.help.dotdigital.com/en/articles/8205355-get-started-with-automation, marketing.help.dotdigital.com/en/articles/8199002-understand-email-authentication and 7 more). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 6 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 compliance fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 integrations fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 legal fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
Sources (13)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page dotdigital.com Checked 22 Sep 2026 Details →
- 2 Terms of service — found from the homepage dotdigital.com Checked 30 Sep 2026 Details →
- 3 Security / trust page — found from the homepage dotdigital.com Checked 30 Sep 2026 Details →
- 4 Campaigns & automation — found from sitemap marketing.help.dotdigital.com Checked 30 Sep 2026 Details →
- 5 Campaigns & automation — found from sitemap marketing.help.dotdigital.com Checked 30 Sep 2026 Details →
- 6 Deliverability infrastructure — found from sitemap marketing.help.dotdigital.com Checked 30 Sep 2026 Details →
- 7 Deliverability infrastructure — found from sitemap marketing.help.dotdigital.com Checked 30 Sep 2026 Details →
- 8 Consent, proof & tracking limits — found from sitemap marketing.help.dotdigital.com Checked 30 Sep 2026 Details →
- 9 Consent, proof & tracking limits — found from sitemap marketing.help.dotdigital.com Checked 30 Sep 2026 Details →
- 10 List ownership, import & exit — found from sitemap marketing.help.dotdigital.com Checked 30 Sep 2026 Details →
- 11 List ownership, import & exit — found from sitemap marketing.help.dotdigital.com Checked 30 Sep 2026 Details →
- 12 Integrations & API — found from sitemap marketing.help.dotdigital.com Checked 30 Sep 2026 Details →
- 13 Integrations & API — found from sitemap marketing.help.dotdigital.com Checked 30 Sep 2026 Details →