How Email Deliverability Works and Why Messages Land in Spam
The question I have been asked most often in twenty-odd years of running mail is some version of "why did my email go to spam?" It comes from small business owners, from developers whose app sends signup confirmations, and once from my own...

The question I have been asked most often in twenty-odd years of running mail is some version of "why did my email go to spam?" It comes from small business owners, from developers whose app sends signup confirmations, and once from my own mother, whose church newsletter was suddenly vanishing for half the congregation. The answer is almost never one thing. It is a score, built by the receiving mailbox provider from many small signals, and you only control some of them.
So rather than a checklist of tricks, here is how a receiving server actually decides, roughly in the order it decides, and where people usually go wrong.
What happens between send and inbox
When you send a message, your mail server looks up the recipient domain's MX records in DNS to find out which servers accept its mail. It opens a connection, announces itself, and hands the message over. At each step, the receiving side is gathering evidence.
- The connection. Which IP address is talking? Does it have a reverse DNS name that matches what the server claims to be? Is it on a public blocklist such as those run by Spamhaus?
- The envelope and headers. Who claims to be sending, and does that domain publish SPF and DKIM that back up the claim? Does the visible From domain line up with them, as DMARC requires?
- Reputation. How has mail from this IP and this domain behaved recently? Do people open it, reply, move it out of spam, or report it?
- Content. Does the message look like known spam or phishing? Are the links pointing to domains with a bad history?
- The individual recipient. Has this person written to you before? Did they mark your previous messages as spam?
A message can be rejected at step one and never be read at all. More often it is accepted and then placed in the inbox, the promotions tab or the spam folder based on everything above.
Reputation is the part that matters most
If I had to rank the signals, reputation sits clearly at the top. Large mailbox providers like Gmail and Outlook see billions of messages a day and they watch how real people react. If many recipients delete your messages unread, or click "report spam", your reputation falls, and so does placement for everyone you send to.
Google publishes guidance for bulk senders that asks them to keep user reported spam rates below 0.3 percent, and it recommends staying well under 0.1 percent. Those numbers look tiny. For a list of 20,000 people, 0.3 percent is just 60 complaints. One poorly targeted campaign can blow past that in an afternoon.
Reputation attaches to two things. Your sending IP address, which matters a great deal if you run your own server or use a dedicated IP, and your domain, which follows you even if you switch providers. That second part surprises people. Moving to a new email service does not wash away a domain's history.
Mailbox providers do not ask whether your mail is legitimate. They ask whether their users want it.
Authentication: necessary, not sufficient
SPF, DKIM and DMARC are the entry ticket. Without them, much of your mail will struggle with major providers, and since 2024 Gmail and Yahoo have required them for anyone sending in bulk. With them, you have proven only that the mail really comes from you. You have not proven anyone wants it.
The detail people miss is alignment. DMARC passes only when the domain in the visible From line matches the domain that passed SPF or DKIM. A common mistake: a company sends newsletters from [email protected] through a marketing platform, the platform signs with its own domain, and DMARC fails even though every record "exists". Setting up custom DKIM signing for your own domain in the platform fixes it.
The same lessons apply to games and apps that send account emails; I described a studio that learned it the hard way in how online game studios send messages to players.
The myth I would retire: spam trigger words
Many guides still publish lists of words to avoid: "free", "guarantee", "act now", "winner", dollar signs, exclamation marks. People rewrite perfectly ordinary messages to tiptoe around them.
I think this is mostly folklore from the early 2000s, when filters really did lean on keyword scores. Modern filters at large providers rely far more on reputation, authentication and how recipients behave. A trusted sender can write "free shipping this weekend" and land in the inbox. A sender with a poor reputation can write a gentle, word perfect note and still land in spam.
Content still matters in other ways. Messages that are a single large image with almost no text, links through shorteners or domains with bad histories, and mismatches between link text and destination all hurt. But the specific words are a small factor next to who you are and how people treated your last fifty emails.
Common causes I see in practice
| Symptom | Likely cause |
|---|---|
| Everything suddenly in spam after a big send | Old or purchased list, high bounces and complaints |
| Only Microsoft addresses affected | IP reputation at Outlook, check their sender support pages |
| DMARC failures in reports from a service you use | Missing custom DKIM or SPF include for that service |
| Rejected at connection with a blocklist mention | Sending IP listed, often from a compromised account or shared IP |
| Newsletter lands in promotions tab | Working as intended, that is not spam |
My mother's church newsletter, by the way, fell into the first row. A volunteer had imported an old spreadsheet of addresses from 2012. About a fifth bounced, and the provider throttled the account. Removing the dead addresses and sending only to people who had opened something in the past year brought placement back within a few weeks.
A sensible first week
If your mail is landing in spam, I would work through it in this order. First, look up your domain's SPF, DKIM and DMARC records and confirm they pass using the headers of a message you sent to a Gmail account; Gmail's "show original" view lists the results plainly. Second, register your domain with Google Postmaster Tools, which shows your domain reputation and spam rate once your volume is large enough. Third, clean your list of addresses that bounce or have not engaged in a long time.
If you are tempted to run your own mail server to escape all this, read what self hosting your own email really takes first, because a fresh server starts with no reputation at all. More background lives in the email infrastructure section.
More from the blog
Self Hosting
What Self Hosting Your Own Email Really Takes
I set up my first mail server in 1998 for a small engineering firm of twelve people.
Games
Explore How Gaming Communities Run Their Own Chat Servers
Before Discord became the default, a raid night in World of Warcraft usually meant everyone opening TeamSpeak or Ventrilo and...
Games
Discover the Dev Tools Behind Modern Online Game Launches
When a new online game launches, players see a trailer, a store page and, with luck, a login screen that lets them in.