Emails go to spam for four overlapping reasons: authentication fails or is missing (SPF, DKIM, DMARC), sender reputation is weak (your domain or IP has a poor track record), content and list hygiene trip filters (spammy wording, dead addresses, no unsubscribe), and — since February 2024 — you simply don't meet the bulk-sender rules that Gmail and Yahoo now enforce. The good news: every one of these is diagnosable from an email's own headers and fixable with DNS and process changes. Here's the practitioner's version.
The real reasons mail lands in spam
Filters score every message. The big levers, in rough order of impact:
- Authentication and alignment. If SPF, DKIM and DMARC don't pass and align with your From domain, you look like a spoofer.
- Reputation. Receivers track how recipients react to your domain and sending IP. Complaints, spam-trap hits and blocklist entries sink you.
- Infrastructure signals. Missing reverse DNS (PTR), mismatched HELO, and sending from shared or "dirty" IP space all count against you.
- Content and engagement. Link-heavy or deceptive content, image-only emails, and mailing people who never open lower your score.
- List hygiene. Sending to invalid or recycled addresses generates bounces and spam-trap hits that wreck reputation fast.
Email authentication in 90 seconds
Three records do the heavy lifting. You need all three working together.
| Record | What it proves | Common failure |
|---|---|---|
| SPF | Which IPs/hosts may send for your domain | A new sending service not added; more than 10 DNS lookups (permerror) |
| DKIM | The message wasn't altered and came from an authorized signer | Selector not published; key rotated and DNS not updated |
| DMARC | SPF/DKIM align with the visible From domain; what to do on failure | No record at all; alignment fails because mail is sent via a third party |
The subtlety most people miss is alignment: SPF or DKIM can technically "pass" for the sending service's own domain while still failing DMARC because they don't match the domain in your From header. That mismatch is a leading cause of legitimate mail being quarantined.
The 2024 Gmail/Yahoo (and Microsoft) sender rules
In February 2024, Gmail and Yahoo made authentication mandatory for bulk senders (broadly, anyone sending more than ~5,000 messages a day to their users), and Microsoft has been rolling out comparable requirements. If you send newsletters, product email or any volume marketing, these are now table stakes:
| Requirement | Detail |
|---|---|
| SPF and DKIM | Both must be set up and passing for your sending domain |
| DMARC published | At least p=none; the From domain must align with SPF or DKIM |
| One-click unsubscribe | RFC 8058 header on marketing mail; honour requests within 2 days |
| Spam complaint rate | Keep below 0.10%; never exceed 0.30% |
| Valid PTR / rDNS | Sending IPs need matching forward and reverse DNS |
Diagnose your own deliverability
Don't guess — read the evidence. Find an email that landed in spam, open its original/source, and check:
- Authentication-Results header. Look for
spf=pass,dkim=passanddmarc=pass. Anyfail,softfailornoneis your lead. - The Received chain and sending IP. Confirm the mail left the infrastructure you expect, then check that IP against major blocklists.
- Reverse DNS. The sending IP should resolve to a hostname that matches your HELO.
- Filtering headers. Many receivers stamp
X-spam-score or category headers that hint at why it was filtered.
Reading raw headers by hand is tedious and error-prone. Our free, in-browser Email Header Analyzer parses the Authentication-Results, traces the hop-by-hop delivery path, flags SPF/DKIM/DMARC verdicts and surfaces business-email-compromise indicators — all client-side, with nothing uploaded to a server. If you're investigating spoofing of your own brand, pair it with SquatWatch to catch lookalike domains, and MSTenantLookup to confirm a sender's Microsoft 365 tenant.
Transactional vs. marketing — and how long recovery takes
Treat the two streams differently. Transactional mail (password resets, receipts, alerts) is exempt from the one-click-unsubscribe rule and should ideally be sent from a dedicated subdomain so a marketing reputation problem never delays a password reset. Marketing mail carries the unsubscribe and engagement obligations and is where complaint rates actually move. Splitting them onto separate subdomains (and separate DKIM selectors) isolates risk and makes your DMARC reports far easier to read.
On recovery: reputation is earned slowly and lost quickly. A blocklist delisting can clear in hours to days once the root cause is fixed, but mailbox-provider reputation — the score Gmail and Microsoft keep on your domain and IP — typically takes two to four weeks of consistent, low-complaint, well-authenticated sending to rebuild. There is no fast button; the levers are fix authentication, cut complaints, and stay consistent.
The fix-it checklist
- Publish SPF listing every service that sends for you; keep it under 10 DNS lookups.
- Enable DKIM on every sending platform and publish the selector; rotate keys carefully.
- Publish DMARC at
p=nonewithruareporting, review reports, then move toquarantineandreject. - Add one-click unsubscribe to marketing mail and process opt-outs within two days.
- Warm up new IPs/domains gradually; never blast cold volume from a fresh sender.
- Clean your list — remove hard bounces and unengaged addresses; never buy lists.
- Monitor Google Postmaster Tools and your DMARC reports continuously.
A full SPF/DKIM/DMARC setup walkthrough is on its way as a companion guide; in the meantime the analyzer above will tell you exactly which of the three is letting you down.
Frequently asked questions
Why are my emails suddenly going to spam?
A sudden change usually points to one of three things: an authentication break (an SPF/DKIM/DMARC record was edited or a new sending service was added without being authorized), a reputation hit (a spike in volume, complaints or a blocklist entry), or a content trigger. Read the message headers of a spam-foldered email — the Authentication-Results line tells you immediately whether auth passed.
Do I need all three of SPF, DKIM and DMARC?
Effectively yes. SPF authorizes sending IPs, DKIM cryptographically signs the message, and DMARC ties them to your visible From domain and tells receivers what to do on failure. Since February 2024, Gmail and Yahoo require all three (DMARC at minimum p=none) for bulk senders, and Microsoft has been rolling out the same expectations. One or two of the three is no longer enough.
What is a good DMARC policy to start with?
Start at p=none with reporting (rua) so you can see who is sending as your domain without affecting delivery. Once legitimate sources all pass SPF or DKIM with alignment, move to p=quarantine and then p=reject. Going straight to p=reject before you've reviewed reports is the fastest way to block your own mail.
What spam complaint rate is too high?
Google asks bulk senders to keep the spam complaint rate below 0.10% and warns that going above 0.30% will hurt delivery. Even a brief spike above that threshold can push a domain's mail to spam for weeks, so monitor it in Google Postmaster Tools.
How do I check why one specific email went to spam?
Open the original message and inspect its headers. Look at Authentication-Results for spf=, dkim= and dmarc= verdicts, check the Received chain and sending IP, and review any X-spam or filtering headers the receiver added. Our free Email Header Analyzer parses all of this in the browser so you don't have to read raw headers by hand.