Skip to content
Free tool for credit unions

Check your email campaign before it sends

Paste a campaign and get a plain-language report in about a second: what is wrong, which sentence caused it, and what to change instead. Built for the marketing side of a credit union, not for a compliance officer.

  • Runs in your browser, nothing uploaded
  • No signup, no email required
  • Plain text or HTML

A campaign that both sells and informs counts as marketing, and the stricter rules apply to the whole thing.

This runs on your computer, not ours. The scanner is JavaScript on this page. Nothing you paste is sent to Lemon Head Design or anywhere else. Open your browser network tab and watch if you like, or read the source.
Your report shows up here.

Every finding names the rule, quotes the sentence that triggered it, and tells you what to change. Account numbers and Social Security numbers are masked in the report itself, so it is safe to share with your team.

What it looks at

The things that get caught after the send

These are the failures that survive three rounds of copy review, because everyone is reading the words and nobody is checking the plumbing.

Required elements

The parts a promotional email has to carry, checked as structure rather than as wording.

  • Opt-out present, and an actual working link
  • Valid physical postal address
  • Identified as a promotional message
  • Subject line that matches the body

Claims you cannot make

Language that promises something underwriting decides, or that nobody authorized.

  • Guaranteed approval, pre-approved, no credit check
  • We will waive, we will approve, we guarantee
  • Lowest rates anywhere and similar superlatives
  • Deadlines and consequences that are not real

Member data

Anything identifying that should never have made it into an email.

  • Social Security numbers
  • Card numbers, checksum-validated
  • Account numbers, read in context
  • Any request asking members to reply with credentials

Merge fields

The failure that only happens at scale, and happens to the whole list at once.

  • Fields whose names suggest an account number or balance
  • Tags that will ship as literal text if they do not resolve
  • Works with Mailchimp, Constant Contact, HubSpot and GoHighLevel syntax

Campaign HTML

Extra checks that only run when you paste the built email rather than the copy.

  • Unsubscribe styled like a link but not linked
  • Images with no alt text
  • Image-only emails with no live text
  • Tracking and redirect domains worth confirming

Notices and escalations

Different rules for the emails that are not marketing at all.

  • Disclosures missing paper copy and electronic delivery language
  • Marketing mixed into a required notice
  • Speculation inside a security notice
  • Complaints, legal notices, estates, bankruptcy and fair lending flags

The whole rule set, written out

All 53 checks, what each one actually looks for, and what the report tells you to do when it fires. If you would rather know exactly what this thing does before you paste a campaign into it, read it first — that is the entire reason it is published.

Why bother

Email is the one channel you cannot recall

A wrong sentence on a web page is a five-minute fix. The same sentence in a campaign is in forty thousand inboxes and cannot be edited, corrected, or taken back.

  • The copy gets read. The footer does not. Address blocks and unsubscribe links break during template edits, and nobody proofreads the part they have seen a hundred times.
  • Merge fields fail quietly. A field wired to the wrong core column looks fine in the builder and puts an account number in every inbox on the list.
  • Marketing language creeps into notices. A cross-sell added to a change-in-terms email turns the whole message into a promotional send, with everything that comes with it.
  • Good intentions write the worst incident notices. The instinct to reassure produces sentences that turn out not to be true, in the one email guaranteed to be read closely later.

Want us to look at the next one?

We write and build member email campaigns for credit unions. This scanner is the checklist we run against our own work. Send us a note and we will review a recent campaign with you, free, on a short call.

Your info stays private. No spam.

Questions

What this is, and what it is not

Does my campaign get uploaded anywhere?
No. The scanner is JavaScript running on this page in your own browser. Nothing you paste leaves your computer, there is no request to our server when you press Scan, and we never see the campaign. That is deliberate, because a tool you can only use on copy that has already been approved is a tool nobody uses.
Does a clean scan mean the email is compliant?
No, and we would rather say that plainly than let you assume otherwise. The scanner catches mechanical failures: missing elements, risky phrases, exposed identifiers, structural problems. It cannot tell whether a rate is accurate, whether a disclosure is the right disclosure, or whether the tone fits the situation. A clean scan is not an approval to send, and it does not replace your compliance review.
Is this legal advice?
No. Lemon Head Design is a web design and marketing agency, not a law firm. The checks are built around common patterns drawn from CAN-SPAM, GLBA and Regulation P, the E-Sign Act, and published NCUA and CFPB expectations, but the tool enforces safe patterns rather than interpreting the law. Final determination on anything you send belongs to your credit union's compliance team.
Why does it flag things that are actually fine?
Some checks are marked "to confirm" rather than critical, and those are prompts rather than problems. A dollar figure is worth confirming came from the core system even when it did. If something is flagged critical and you are certain it is correct, that is a judgment call you get to make; the tool's job is to make sure you make it on purpose.
Can I check an internal email or a breach notice?
Yes. Pick the type in the dropdown, or let it detect. Security notices get the strictest rules, including flags for speculation and for any marketing content mixed in. Internal staff emails get checked for member data exposure and for whether a case or CRM reference would be safer than putting the detail in email.
Do you offer this as a plugin for our own site?
Yes, for credit unions on one of our maintenance plans. The plugin version runs in your WordPress dashboard, stores a record of every scan with who approved it, and exports that record as a CSV for your campaign file. Ask us about it on the call.
Who built this and why?
Lemon Head Design. We have been building websites since 2007 and we write member email campaigns for credit unions, so this started as our own internal checklist. Publishing it costs us nothing and saves you the send you would rather have back.

Find the leaks before your competitors do.

Run a free 60-second audit. You'll see your site's speed score, security gaps, and the SEO holes anyone with a tool can already see. Then decide if you want our help.

⚡ We take on a limited number of new clients each quarter — spots fill fast

Or call us directly at 801-797-3492

801-797-3492