Extends the newsletter suite with two boundary cases: redirects (301/302/307/ 308) must be treated as failures with the user-safe error, and the POST must carry no credential of any kind — no api-key/auth-token/cookie headers, and no token/secret in the body or URL.