All resources
Deliverability 7 min read

Why your emails can land in spam, and what you can do about it

You can send a legitimate email to someone who knows your business and still have it rejected, delayed or placed in a spam folder. There is rarely one clear cause.

Mailbox providers consider several signals when processing incoming email. These include whether the sender can be authenticated, the reputation of the sending domain or IP address, recent sending behaviour, recipient complaints and the way the message has been constructed.

No single change can guarantee inbox placement. However, there are several areas every sender should check.

Start with email authentication

Email authentication helps receiving providers confirm that a message genuinely came from the domain shown in the email. The three methods most businesses encounter are SPF, DKIM and DMARC.

SPF

SPF identifies the servers and services authorised to send email using your domain. When a business begins using a new email platform or sending service, that service may need to be added to the domain’s SPF configuration.

DKIM

DKIM adds a digital signature to an outgoing message. The receiving provider checks that signature against information published in the sender’s DNS (domain name system) records. This helps confirm that the message came from an authorised source and was not altered after it was signed.

DMARC

DMARC checks whether the domain used in the visible sender address aligns with the domain authenticated through SPF or DKIM. Most servers these days also run a domain mismatch check, comparing the sender address, the reply-to address and the return path to make sure they all use the same domain. DMARC can also tell receiving providers how to handle messages that fail those checks.

  • p=none monitors failures without requesting quarantine or rejection.
  • p=quarantine asks providers to treat failing messages as suspicious.
  • p=reject asks providers to reject failing messages.

A p=none policy meets the minimum DMARC requirement published for many bulk-sender programs. Moving to a stronger policy should be done after all legitimate sending services have been identified and correctly authenticated. It is worth noting that some email services treat messages with a p=none value as spam even when they are not.

Authentication settings should be reviewed whenever a business changes its email platform, adds a sending service or changes its domain configuration.

Requirements vary by provider and sending volume

Mailbox providers publish their own sender requirements.

Gmail requires all senders to use SPF, DKIM and DMARC. Senders delivering more than 5,000 messages per day to personal Gmail accounts must meet additional unsubscribe and complaint-rate requirements. Yahoo requires SPF, DKIM and DMARC for all senders, and stronger authentication for senders it classifies as bulk senders. Outlook.com also requires SPF, DKIM and DMARC for domains sending more than 5,000 messages per day to its consumer addresses.

Domain mismatch checking is now close to universal, although the level varies. Some providers even check the links in the email to confirm they match the sender’s domain.

These requirements change. High-volume senders should check the current guidance for the providers receiving most of their messages.

Sending behaviour can affect delivery

Mailbox providers monitor the volume and pattern of email arriving from sending domains and IP addresses. Sudden increases in volume, or large bursts of email, can result in messages being delayed or rate limited.

There is no single hourly volume that suits every sender. Appropriate sending rates depend on previous volume, sender reputation, the recipient providers involved and the responses returned by their servers. Reviewing those server responses during a campaign makes it possible to slow or pause sending when problems appear.

Send to people who expect the message

Mailbox providers pay attention when recipients report messages as spam. Sending promotional messages to people who did not request them, using old contact data, or continuing to send after someone has unsubscribed can all increase complaint rates.

  • Remove addresses that permanently fail.
  • Honour unsubscribe requests.
  • Avoid unverified contact lists.
  • Avoid purchased lists unless they come from a recognised source with suitable opt-in policies.
  • Review contacts who have not engaged for an extended period.
  • Make it clear who sent the message and why the recipient received it.

A smaller relevant list is generally more useful than a larger list containing invalid or uninterested recipients.

Make unsubscribing straightforward

Promotional and subscription emails should provide a clear way for recipients to stop receiving them. Major mailbox providers have also introduced technical one-click unsubscribe requirements for many bulk promotional messages.

An easy unsubscribe process gives recipients an alternative to reporting the message as spam. The instructions shown in the email should be clear, functional and easy to find.

Use accurate sender details and subject lines

The visible sender name, sender address, reply-to address and subject line should accurately describe the message.

  • Do not pretend a marketing email is a reply or a forwarded message.
  • Do not use a sender name that misrepresents the organisation.
  • Do not use a subject line that does not match the contents.
  • Use an address that can receive replies when replies are expected.
  • Make the reason the recipient received the message clear.

Certain words and phrases can contribute to a higher spam score, particularly when combined with excessive punctuation, capital letters, misleading claims or other risky signals. Prodocom maintains a reference list to help businesses identify wording that may increase risk before sending — ask us for a copy.

A single word does not automatically send an email to spam. The wider message, sender reputation, authentication and sending behaviour all matter too. Treat the list as a best-practice guide that gives a campaign the best possible chance of delivery, not as a definitive blacklist.

Sent and accepted are not the same as inbox placement

Depending on the system you use, sent and accepted are effectively the same thing.

  • Sent or accepted means the sending system released the message and the receiving server accepted or queued it.
  • Failed means the receiving system rejected it, or the address could not be reached.
  • Opened or clicked describes later tracking activity and does not prove inbox placement. A large share of recorded opens and clicks are actioned by the recipient’s server rather than a person, so make sure your reports distinguish server activity from user activity.

A receiving server accepting a message does not guarantee that it appeared in the recipient’s primary inbox. The provider may still place it in another folder or apply additional filtering.

A useful campaign report shows the status and server response for each recipient, rather than only the total number of messages released.

What to check before sending

  1. Confirm which platforms and systems send email using your domain.
  2. Check that SPF, DKIM and DMARC are configured correctly.
  3. Use accurate sender and reply-to details.
  4. Send only to recipients who reasonably expect the message.
  5. Remove addresses that have permanently failed.
  6. Include a clear unsubscribe option where required.
  7. Avoid sudden or unusual changes in sending volume.
  8. Review server responses, failures and complaint information after sending.

None of these steps guarantees that every message will reach the primary inbox. Together they reduce avoidable delivery problems, and make it easier to identify what happened when a message fails.

Need help reviewing your setup?

Talk to Prodocom about reviewing your email setup before your next campaign.

Keep reading

More from our guides.