Skip to main content
← Back to glossary
Trust & safety

Allowlist

ما هو Allowlist?

هذا المصطلح متوفر حاليًا باللغة الإنجليزية فقط.

An allowlist is the set of destinations or categories a sending platform explicitly approves to receive messages — phone numbers, email addresses, recipient domains, or sender-provided consent attestations. Where a blocklist denies by default, an allowlist permits by default: when an allowlist is active, any destination not on it is blocked before dispatch. The pairing matters because compliance definitions care about which direction the default runs.

More detail

When an allowlist gate is active, senders get certainty that no destination can slip through by accident — approved recipients pass, anything else drops. Where a commercial sender's duty is to deny (opt-outs, prohibited categories), a blocklist is the right gate; where a sender needs to restrict sends to a verified, attested set (a closed beta, an internal test sandbox, an explicitly verified-recipient program), an allowlist is the right gate.

The blocklist/allowlist pairing names the two polar send-time policies between them: deny-by-default gates the abusive or non-consented destination out; permit-by-default gates everything except the explicitly approved destination in. Both are hard send gates — a send path gated by either drops the destination at dispatch rather than scoring or ranking it.

الأسئلة الشائعة

When should a sender use an allowlist instead of a blocklist?
Whenever the goal is restrict-to-approved rather than deny-the-bad: a closed test or beta program, an internal sandbox, or a verified-recipient flow. For general opt-out and trust-safety enforcement, the blocklist (deny list) is the industry default.
Is an allowlist the opposite of a suppression list?
Conceptually, yes — it permits instead of denies. But it is not a re-permit mechanism: a destination a recipient opted out of does not re-enter circulation by being appended to an allowlist. The explicit re-permit happens only after a fresh, verified opt-in, and the suppression gate honours it once.
Why list the default direction explicitly?
Because compliance and trust-and-safety definitions care about it: deny-by-default (blocklist) versus permit-by-default (allowlist) is the polar difference between blocking known-bad destinations and gating everything except approved ones. The pairing is precise vocabulary for that choice.

Build it on Orbit

Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.