Reviews (3,187)
NIGHTMARE - Major spam and spoof issues caused by Omnisend
UPDATE 9/23/26: We've been unsuccessful in getting any meaningful assistance from omnisend. The reply here, for the world to see, does not resolve any of the issues we continued to experience. Live chat does not reply with resolutions. There is no phone support. No way to get our email address removed from their system. We are being held hostage by omnisend while they fail to help.
ORIGINAL POST 9/22/26: The SPF record you are required to enter for omnisend causes major spam or spoof emails.
Google had us remove their SPF record, which resolved the spam issue.
Unbeknownst to us this caused omnisend to stop sending our flows for 60 days. No notification from omnisend, but they sure kept billing us.
Suport regarding this issue with Josh Hargett was so frustrating we have decided to move away from omnisend entirely.
Thank you for taking the time to share your experience. We’re sorry this situation has been so frustrating, particularly with the volume of messages reaching your inbox and the disruption to your automations. We also regret that your initial support experience didn’t make an already difficult situation easier to navigate.
Given the seriousness of your concerns, our Deliverability team reviewed the case in detail. The messages reviewed were bounce notifications resulting from your email address being spoofed as the sender of messages sent elsewhere. In this type of spoofing, someone external can forge a domain in the “From” field without needing access to the mailbox, website, or Omnisend account. When those messages cannot be delivered, failure notices can be returned to the address they falsely claimed to originate from.
An SPF record does not generate spam, provide access to a mailbox, or enable someone to send through an Omnisend account. It tells receiving mail servers which services are authorized to send email on behalf of a domain. We do understand why the timing made the issue appear directly connected to the SPF change. With the previous, stricter configuration, unauthorized messages could be rejected earlier in the delivery process, before a bounce notice was generated. Changing the configuration affected how some receiving servers handled those messages, which could make the existing spoofing activity visible through bounce notifications.
To help address the underlying issue, our team has recommended strengthening DMARC enforcement, which is designed to help receiving servers handle messages that falsely claim to come from your domain. We’ve also requested the original email files with their full routing information so our Deliverability team can investigate the source further and provide the most appropriate guidance.
We also recognize your concerns about your automations stopping after Omnisend was no longer included in your domain authentication, as well as the communication, billing, and support experience surrounding that period. These account-specific concerns are being reviewed directly with you to ensure they receive the proper attention.
We appreciate the time you’ve spent raising these concerns, and we want you to know that your experience matters to us. While our investigation indicates that Omnisend did not cause the underlying spoofing activity, we understand why the timing and volume of these notifications led you to connect the two. We remain committed to supporting you, addressing the concerns you’ve raised, and ensuring you receive the level of attention and assistance you expect from our team.