Home/Features/Delivery Protection

Reliability

Message Delivery Protection

Automatic pacing, portfolio budget tracking, suppression and quality monitoring that stop a WhatsApp number from being damaged, with the reason always shown in plain language.

By Chirag Darji · Updated 26 Aug 2026 · 14 min read

Plans: All plans, including Free. Every protection on this page (pacing, portfolio budget tracking, auto-park, suppression, consent handling, template pause detection, quality monitoring and owner alerts) runs the same way on every plan; there is no tier where delivery protection is switched off.

On this page
  1. What you get
  2. How it works
  3. Why does pacing exist, and what does it actually do?
  4. What is the daily messaging limit, and how is it enforced?
  5. What are the five reasons a campaign parks itself, and what happens after?
  6. Why is "suppressed" treated differently from "failed"?
  7. How does STOP and START consent handling actually work?
  8. What protects a number from Meta's own shared API limits?
  9. With VGraple CRM vs a tool with no delivery protection
  10. Who this protects
  11. What Meta allows
  12. Plans and limits
  13. Recent improvements
Broadcast delivery settings in VGraple CRM: quiet hours and marketing frequency cap

In short

  • A token-bucket pacer sends below Meta's throughput ceiling and slows itself further the moment your quality rating drops
  • A daily portfolio budget is tracked live so a campaign parks itself before Meta starts rejecting sends
  • Suppressed recipients (opted out, blocked, marketing-stopped, capped, US-paused) are never billed and never retried
  • Every automatic stop names the exact reason, in plain language, on the campaign itself

Delivery protection is the set of automatic controls that keep a WhatsApp number sending at a pace and to an audience Meta will actually accept, so a campaign slows itself and a bad send stops itself before Meta starts restricting the number, rather than a business discovering the damage from a wave of failures. Every WhatsApp CRM in this category gets the same complaint most often: messages that silently fail to deliver. This page explains, plainly and without naming names, what actually causes that and exactly what VGraple CRM does about each cause.

What you get

  • A token-bucket pacer that sends below Meta's throughput ceiling and adapts to your live quality rating
  • A rolling 24-hour portfolio budget tracked in real time, with automatic park-and-resume when it runs out
  • Five distinct automatic stop conditions, each with its reason shown in plain language
  • Suppression logic that separates "we refused to send" from "Meta rejected it," so suppressed recipients are never billed or retried
  • STOP/START consent handling with a single confirmation per transition and a documented way back in
  • Automatic detection of a paused or dropped template, with running campaigns parked immediately
  • A shared circuit breaker for Meta's own app-level API limits, so one exhausted quota does not cascade
  • Owner alerts on every account-level protection event, across in-app, mobile push and email

How it works

  1. Every send passes through the pacer first. Before a batch of messages goes out, the token-bucket pacer for that number checks whether it has capacity at the current rate; if not, it waits. This runs invisibly on every broadcast, sequence step and flow send, not just large campaigns.

WhatsApp broadcast campaign report in VGraple CRM with delivered, read and replied stats per contact

  1. The portfolio budget is checked continuously. While a campaign sends, the daily messaging-limit usage for the whole business portfolio is tracked live; the campaign is allowed to keep going only while headroom remains.

  2. A problem stops the campaign, with the reason shown. The moment one of the five automatic stop conditions is detected, the campaign parks itself and the broadcast page states, in plain language, which one it was and when (or whether) it will resume on its own.

  3. The org owner is alerted. Anything account-wide, a quality collapse, a portfolio-wide marketing halt, a template pause, reaches the owner as an in-app alert, a mobile push notification, and, where configured, an email, so the first sign of trouble is not a customer complaint.

  4. Suppression is checked again at the moment of send. Even for an audience built hours or days earlier, every recipient is re-checked against opt-out, blocked, marketing-stopped and frequency-cap status immediately before sending, so a contact who opted out in between never receives the message.

Why does pacing exist, and what does it actually do?

A WhatsApp number that sends faster than Meta's throughput ceiling gets throttled, and repeated throttling is one of the fastest ways to damage a number's standing. VGraple CRM paces every send through a token-bucket limiter, a small burst allowance on top of a steady rate, set to 50 messages a second by default: comfortably under Meta's roughly 80/s ceiling so a short burst of retries never trips a hard limit, while still finishing a large campaign in a reasonable time.

WhatsApp channel settings in VGraple CRM with Embedded Signup and coexistence mode connect options

The rate is not fixed. It adapts to the number's live quality rating, because sending slower is the single most effective thing a sender can do to protect a number that is already struggling: YELLOW halves the rate to 25/s, RED cuts it to a tenth, 5/s. A coexistence number, one also used in the WhatsApp Business app on a phone, is paced at 4/s regardless of quality, because Meta's own ceiling for coexistence numbers is far lower than a Cloud API-only number's. If Meta itself pushes back mid-send with a throughput error (130429), the pacer halves its rate immediately and stays there; recovery is deliberate rather than automatic, because a campaign that has already tripped the limit once should finish the rest of its run slower, not immediately test the same ceiling again.

Example

A cosmetic brand's Friday sale broadcast is sending at 50/s when Meta returns a handful of 130429 errors on a burst. The pacer halves the rate to 25/s for the remainder of that campaign; the send takes a little longer to finish, and the number does not accumulate a longer run of throughput violations that a quality reviewer would notice.

What is the daily messaging limit, and how is it enforced?

Meta caps how many unique people a WhatsApp business can start a conversation with in a rolling 24 hours, based on a messaging tier (from 50 to 100,000 unique recipients) that Meta assigns and can raise as sending history builds trust. Since 2024, this limit applies to the entire business portfolio, every phone number under the same business, not to one number alone, so two campaigns from two different numbers under the same business draw from the same daily budget.

VGraple CRM counts unique recipients your portfolio has actually started template conversations with in the trailing 24 hours, live, and checks the remaining headroom before a campaign is allowed to keep sending. When the budget runs out mid-campaign, the send parks itself with a resume time set to the moment the rolling window reopens and continues automatically, with no manual restart. This exists because the alternative, discovered the hard way before this system existed, is a number handed a 10,000-contact audience sending all 10,000 attempts and collecting most of them back as failures, with every failure itself counting against the number's quality.

What are the five reasons a campaign parks itself, and what happens after?

A campaign that keeps firing into a problem it cannot fix wastes the daily budget and risks the number, so the delivery engine stops itself the instant it detects one of five specific conditions, and the reason is written on the campaign in plain language, not left as a silent stall.

ReasonWhat triggers itRecovery
Template paused by MetaError 132015 (quality review) or 132016 (sustained low quality)Stays paused until the template is released or resubmitted; escalates to permanent disabling if unresolved
Portfolio pacingError 135000, a business-wide marketing halt Meta applies to young or fast-growing portfoliosAll marketing sending across the organisation pauses for about an hour; utility and service messages are unaffected
Quality rating redThe sending number's live quality rating from MetaEvery running campaign on that number pauses outright so continued sending cannot make the rating worse
Over your conversation quotaYour plan's monthly conversation limit reachedPauses until the quota resets or you upgrade
Failure-rate breakerMore than 35% of the last 200 sends failedStops immediately so a bad list or a broken template does not burn through the rest of the budget

The failure-rate breaker deliberately excludes suppressed recipients from its count. A campaign sent to a heavily marketing-capped audience behaving exactly as it should, refusing sends the platform already knows would fail, must never trip a breaker meant to catch something actually going wrong.

Why is "suppressed" treated differently from "failed"?

A failed send means Meta accepted the attempt and then rejected it, or a delivery error arrived later. A suppressed send means the platform refused to attempt it in the first place, because the recipient opted out, is blocked, has no valid WhatsApp number, told WhatsApp to stop marketing messages from this business specifically, sits inside a Meta frequency-cap window, or is a United States number during Meta's marketing pause on US numbers.

The distinction is not cosmetic. Meta has enforced retry penalties at the WhatsApp Business Account level, applied to the account, not the individual send, since 30 April 2026, for businesses that keep re-attempting sends Meta has already refused. A tool that treats suppression and failure the same way will eventually retry a suppressed recipient by accident, and the penalty lands on the account. VGraple CRM checks every recipient again at the exact moment of send, not just when the audience was first built, so a contact who opts out between scheduling and firing is excluded correctly, and "Retry failed" is built structurally so it cannot pick up a suppressed row.

Meta policy

Meta's per-user marketing frequency cap (error 131049) is adaptive per recipient across every business messaging them, not specific to your account, and lifts after roughly 24 hours or when the recipient replies to you. A related code, 131050, means the recipient tapped "stop marketing messages" specifically for your business and persists until they opt back in. Utility and Authentication templates are exempt from both.

WhatsApp's own opt-out keywords, STOP and its common variants (STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, OPT OUT), are matched as an exact, whole-message reply rather than a substring search on purpose: "we can start on Monday" is an ordinary sentence, and unsubscribing someone who was trying to book an appointment is a worse outcome than occasionally missing a keyword typed in an unusual way, because they then have to notice and ask to be restored.

A recognised opt-out sets the contact's opt-out state and suppresses further business-initiated messaging; it does not gag the business from answering a question that contact asks inside the normal service window, matching how Intercom, Zendesk and Klaviyo all separate marketing consent from customer service. The confirmation is sent exactly once per transition, never repeated on a duplicate STOP, because a customer sending STOP a second time is telling you the first one did not work, and answering it the same way a second time only confirms their suspicion. START, UNSTOP, RESUME and SUBSCRIBE restore messaging and are only ever honoured for a contact who is currently opted out, so the words stay completely inert for everyone else.

What protects a number from Meta's own shared API limits?

Separately from your own sending behaviour, Meta enforces a request quota on its Graph API at the app level, shared across every organisation using the platform. When it trips, calls like a profile lookup start failing for everyone at once, and a per-contact retry schedule cannot fix that, because every contact backs off on its own timer and they interleave, keeping the app pinned at the ceiling indefinitely. A single shared circuit breaker checks before spending quota and arms itself the moment Meta reports the limit is hit, with the cooldown escalating on repeated trips rather than resetting to the same short window every time, so a persistently exhausted quota is not hammered every thirty minutes.

With VGraple CRM vs a tool with no delivery protection

A tool with no automatic protectionVGraple CRM
Sending speedFixed, or as fast as the API allowsAdapts live to quality rating; slows automatically on a throughput warning
Daily limit awarenessDiscovered from a wave of failuresTracked live; campaign auto-pauses before the limit is hit
Quality rating dropNo automatic responseEvery running campaign on the number pauses outright
Suppressed vs failedNot distinguished; suppressed contacts get retriedExplicitly separated; suppressed rows are never retried
Paused templateCampaign keeps trying and keeps failingDetected immediately; campaign parks with the reason shown
Consent handlingManual, or a basic keyword matchSTOP/START handled with a single confirmation and a documented way back
Who finds out, and howThe business, from customer complaints or a failure reportThe owner, immediately, across in-app, mobile push and email

Who this protects

A salon running a festive broadcast to 3,000 contacts benefits from pacing that automatically slows down if the number's quality rating dips mid-campaign, instead of continuing at full speed and making the rating worse. See WhatsApp CRM for salons.

A clinic sending appointment reminders as utility messages never has those reminders caught by the marketing frequency cap, because utility and authentication templates are exempt from it by Meta's own rules, and VGraple CRM's category checks keep that boundary honest.

A D2C brand with a large contact list benefits most from the daily portfolio budget: a 50,000-contact win-back campaign parks itself automatically when the daily limit is reached and resumes on its own the next day, instead of the business finding out from a wall of failures. See WhatsApp CRM for D2C.

A real-estate agency messaging US-based NRI buyers benefits from the marketing-pause check on United States numbers catching the restriction before a send is attempted, rather than after it fails. See WhatsApp CRM for real estate.

What Meta allows

Meta policy

WhatsApp Cloud API allows roughly 80 messages a second per number for combined sending and receiving (20/s for coexistence numbers), and answers 130429 above that. The daily messaging limit is enforced per business portfolio, not per number, based on a Meta-assigned tier. MARKETING templates are subject to a per-user frequency cap (131049) and per-business opt-out (131050); UTILITY and AUTHENTICATION templates are exempt. Meta has enforced account-level penalties for retrying suppressed sends since 30 April 2026.

VGraple CRM's defaults sit under every one of these ceilings by design, not as a configuration choice you have to make: 50/s instead of 80/s, live tracking of the rolling 24-hour portfolio budget instead of discovering it from failures, and pre-flight suppression checks that stop a send before Meta has to reject it.

Plans and limits

Delivery protection is not a feature you turn on: it is the default sending behaviour on every plan, including Free, with no separate toggle and no additional cost. Pacing, portfolio budget tracking, auto-park with resume, suppression checks, STOP/START consent handling, template pause detection, quality monitoring and owner alerts run identically regardless of which plan an organisation is on.

Recent improvements

  • 2026-08-19: The pause-reason system shipped, naming the exact cause (template pause, portfolio pacing, quality collapse, quota, failure-rate breaker) on every parked campaign instead of leaving a stalled campaign to guess at.
  • 2026-08-18: Sending moved into a dedicated durable worker on a Postgres-backed queue, so a deploy or crash mid-campaign resumes from the recipients still pending instead of losing progress.
  • 2026-07-14: Delivery error handling rebuilt across the whole 2026 Meta error-code set (131049, 131050, 131047, 131026, 130472, 132015, 132016, 135000 and more), each mapped to a plain-language reason instead of Meta's raw one-line description, and marketing-cap suppression windows (24 hours after 131049, 30 days after 131050) added so reminders and campaigns stop attempting sends inside them.
  • 2026-07-14: Consent keyword handling fixed so a repeated STOP is never answered with a duplicate confirmation, and every opt-out reply names the way back in.

Frequently asked questions

What is "delivery protection" and why does it matter?
It is the set of automatic guards that keep a WhatsApp number sending at a rate and to an audience Meta will actually accept, rather than firing at full speed until Meta starts rejecting or restricting the number. Delivery failures caused by a number's own sending behaviour, not Meta's rules being unclear, are the single most common complaint about tools in this category.
How fast does VGraple CRM actually send?
50 messages a second per number by default, deliberately under Meta's roughly 80/s ceiling. A YELLOW quality rating halves that to 25/s, RED cuts it to 5/s, and a coexistence number (shared with the WhatsApp Business app) is capped at 4/s regardless of quality.
What happens when Meta says I am sending too fast?
Error 130429 means the number exceeded its throughput. The pacer halves its rate immediately and does not recover automatically; a campaign that has tripped this once finishes the rest of its run slower on purpose, since recovering the rate immediately is how a number re-trips the same limit.
What is the daily messaging limit, and how is it different from pacing?
Pacing controls how fast you send; the daily messaging limit caps how many unique people your whole business portfolio, every number under the same business, can be messaged in a rolling 24 hours. VGraple CRM tracks both live and stops a campaign before either is exceeded, rather than after.
What does "suppressed" mean, and why is it never retried?
Suppressed means the platform refused to attempt the send, because the recipient opted out, is blocked, has no valid WhatsApp, told WhatsApp to stop marketing messages, sits in a Meta frequency-cap window, or is a US number during Meta's marketing pause. Meta has enforced account-level penalties for retrying these since April 2026, so "Retry failed" is built to never touch them.
How do STOP and START work?
A contact who replies STOP (or UNSUBSCRIBE, CANCEL, END, QUIT and close variants) is opted out of business-initiated messaging automatically and gets a single confirmation naming how to come back; replying START restores it. The confirmation is sent once per transition, never repeated on a duplicate STOP, since answering a repeated STOP the same way just confirms to the customer that the first one did not work.
Does opting out block a customer from getting a reply to their own question?
No. Opting out stops broadcasts, sequences and other business-initiated messages; it does not stop a human agent from answering a question the customer asks inside the normal 24-hour service window, the same distinction every serious messaging platform (Intercom, Zendesk, Klaviyo) makes between marketing consent and customer service.
What happens automatically when my number's quality rating drops?
The pacer immediately reduces the sending rate (half on YELLOW, a tenth on RED), and if the rating collapses to RED, every campaign currently sending from that number is paused outright so continued sending cannot make the rating worse.
Can a paused template silently keep a campaign trying to send?
No. Meta's template-pause errors (132015 for a quality review, 132016 for sustained low quality) are detected on the delivery side, and any campaign using that template parks itself with the reason shown, rather than continuing to attempt sends the template cannot deliver.
How do I find out when something is protecting my number, rather than just guessing why a campaign slowed down?
Every automatic stop, whether pacing, a budget park, a quality drop or a template pause, is written in plain language on the campaign and, for anything account-wide, sent as an in-app alert, a mobile push and, where configured, an email to the org owner.
Does delivery protection cost anything extra?
No. It runs on every plan, including Free, with no separate toggle to turn it on and no add-on fee. It is the default sending behaviour, not an optional safety net.

Run your WhatsApp on VGraple CRM

Free forever plan, official Meta WhatsApp Business API, set up in 15 minutes. No card needed.