MAILCRAFT
Home Features Pricing About Blog Contact Log in Get Started →
Deliverability best practices

Twelve reasons your emails land in spam

Wydruki z wykresami, smartfon i laptop na ciemnym biurku

A spam filter does not judge your content, it judges the sender

Emails land in spam mostly for technical reasons. Not because the subject line says “sale”. Not because of an exclamation mark or a red button in the template. Whether a message gets through depends above all on who you are to the receiving server: what domain you use, which IP you send from, what you have been doing for the past few weeks and how people react to your mail. Deliverability is the sum of those signals, not a verdict on your writing style.

The order runs opposite to intuition. The receiving server first checks authentication and sender reputation, and only then looks at the content. Fail the first stage and the best copywriting in the world changes nothing.

At MailCraft we run our own fleet of sending servers. Blocks at the big mailbox providers, warming up new IP addresses, the slow grind of getting out of filters - I know it first hand, not from someone else’s write-ups. Below are twelve causes in four areas: domain authentication, sending infrastructure, list quality and message content. Consent comes at the end, because law and deliverability meet at the same point. Most of these reasons disappear once warming up a sending domain is done properly.

Reasons 1-3: no domain authentication

Reason 1: SPF missing or broken. An SPF record lists the servers allowed to send on behalf of your domain. Typical failure: a company changes provider and the old record stays in place. The second typical one: too many DNS lookups. The limit is ten expansions of mechanisms such as include, and every provider you add eats part of the pool. Once you cross the limit, SPF does not end with a warning but with a permanent error.

Reason 2: DKIM with no signature, or a signature that does not match From. A key expires, a selector disappears from DNS, an intermediary changes the message after signing - and verification fails. The signature alone is not enough. It has to cover the right domain.

Reason 3: no DMARC, or a dead p=none. A policy set once and then abandoned, with no reporting address, reads to the big providers as neglect.

And then there is alignment. SPF and DKIM have to point to the same domain the recipient sees in the From field. Technical validity without alignment does not pass DMARC. It is worth going separately through the Gmail and Yahoo sender requirements, because they set today’s minimum for every sending domain.

What to check in DNS before your first send

  • an SPF record covering the server you actually send from, within ten lookups,
  • a public DKIM key under an active selector,
  • a DMARC record with a rua address,
  • correct MX records for the domain, even if you do not receive mail on it,
  • separate entries for the sending subdomain, if you split off marketing traffic.

Tip: start with DMARC at p=none and a rua address. Read the reports for two weeks, find the systems sending on your behalf without your knowledge (there are usually more of them than anyone in the company remembers), and only then tighten to quarantine.

Reasons 4-6: sending infrastructure and IP reputation

Reason 4: no PTR, or a PTR that does not match HELO. Reverse DNS is the first thing the receiving server checks, before it even sees the subject line. An IP address with no name, or with a name different from the one in the HELO greeting, looks like a random host. Some filters drop such connections straight away, without reading anything.

Reason 5: Return-Path on a different domain than From. The envelope and the header are two different things. When the envelope sender points to the provider’s domain, bounces come back into the void and SPF alignment falls apart. Your own mailbox then cannot see who really does not exist on the list.

Reason 6: a cold IP and a cold domain thrown straight into a big campaign. A new address has no history. Sudden volume out of an empty history is a classic spammer pattern.

Warm-up looks mundane: volume growing day by day, starting with your most engaged recipients, separate pools for transactional and marketing mail. Positive reactions early on build a buffer for later. Boring? Very. It works. We wrote it out in an eight-week IP warmup plan.

At low volume a dedicated IP can be worse than a well-managed shared pool - sending too rarely does not build reputation, it dilutes it. Our own blocks taught us one thing: getting out takes stopping the sending, removing the cause and patience. The unblock form alone will not settle it. What you get on our side of the infrastructure is described in the platform feature overview.

Reasons 7-9: quality of the recipient list

Reason 7: bought lists, or lists imported by accident. Sets like these hold spam traps - addresses created or abandoned in order to catch senders who have no consent. A single hit can set your domain reputation for months. There is no shortcut here and no good supplier of such lists.

Reason 8: bounces you do not handle. A hard bounce means the recipient does not exist. Sending to that address again tells the filter that the sender does not read server responses and does not clean the list.

Reason 9: a dead list. You send for months to people who have not opened anything. No reaction works like a silent complaint - filters learn from recipient behaviour, and zero engagement at high volume stands out plainly.

List hygiene in practice

  1. Remove hard bounces immediately, no exceptions.
  2. Drop soft bounces after a run of failed attempts in a row.
  3. Move addresses with no opens for several months into a re-engagement segment.
  4. Anyone who does not respond to re-engagement comes off the list.

Tip: going back to an old list? Send the first campaign only to people active in the last quarter. Treat the rest as a separate re-engagement campaign, in smaller batches, once the signals are rebuilt.

Reasons 10-12: content, headers and how the message is built

Reason 10: a carelessly built message. No plain text version, the whole content locked inside one image, code spat out by a WYSIWYG editor with tables nested without end. The filter has nothing to read, and that in itself is a signal. A text version costs a few minutes and simply solves the problem.

Reason 11: suspicious links. URL shorteners, redirect domains, tracking addresses on a shared domain with unknown history. You are responsible for the reputation of every host that appears in the message. Every one.

Reason 12: no List-Unsubscribe and no visible opt-out. A recipient who cannot find the link in the footer clicks “report spam”. That click costs far more than losing a single address.

The subject line and the preheader matter too, just not in the way people think. Capital letters are not the problem. The problem is a promise the content does not keep, because that generates complaints.

A tracking domain needs its own CNAME and a consistent reputation. If your links run through a host unrelated to your brand, you lose part of the trust built at domain level.

Tip: add a List-Unsubscribe header together with the one-click variant. An unsubscribe in one click is far cheaper than a complaint recorded at the provider.

Consent and the law: GDPR and article 398 of the PKE

Consent for marketing communication applies in B2B as well. A company address is not a rule-free target - if it leads to a specific person, GDPR protects it like any other.

The Polish Electronic Communications Law puts it plainly in article 398: you collect consent before sending commercial information, whatever the channel. Not after the first email. Not “unless they object”.

When a complaint comes, evidence is what counts. The date of sign-up, the exact wording of the clause, the source, the IP address of the person who signed up. Without that set you will not defend yourself before the regulator, or before a provider that asks for an explanation.

Treat double opt-in as a technical mechanism, not a decoration on the form. Confirmation by link filters out typos in addresses, spam traps and other people’s addresses entered out of spite. The same step that gives you proof of consent protects the list from addresses that ruin reputation.

Legal compliance and deliverability go together. A list collected legally generates fewer complaints, because people remember signing up. That is the foundation of the MailCraft email marketing platform with its own fleet of sending servers: consent, evidence and infrastructure in one place, instead of three separate tools that know nothing about each other.

What we do not promise and what is still ahead

Nobody gets around spam filters. You can only stop giving them reasons to block. Anyone who sells you an “inbox guarantee” is selling something they do not control.

There are gaps on our side too. Part of the list hygiene automation is on the roadmap, not in the panel - today some cleaning rules have to be set by hand. We say it openly, because it is better to know a limitation before a migration than after it. If you keep sign-up data in your shop or CRM, check the list of available integrations first.

Filters change the rules without warning. The requirements of the big providers grow every year: what was enough at small volumes is now the minimum for everyone. Domain authentication has stopped being optional.

The honest limitation sounds like this: no provider will guarantee you the inbox. At most it guarantees correct configuration on its side, clean infrastructure and a fast response when something gets blocked. The rest depends on what you send and who you send it to.

Summary: what to do first when your emails land in spam

Order matters. DNS and authentication first, then infrastructure, then the list, content last. The other way round? Then you are polishing subject lines on messages that will not pass verification anyway.

A one day plan

  1. Stop sending. More campaigns only deepen the problem.
  2. Check SPF, DKIM and DMARC, and their alignment with the domain in the From field.
  3. Verify the PTR, the HELO name and the Return-Path domain.
  4. Go through the bounce logs and remove every hard bounce.
  5. Cut addresses with no reaction over recent months from the list.
  6. Add a plain text version and a List-Unsubscribe header.
  7. Resume sending with a small batch to your most engaged recipients.

Reputation breaks in a day and rebuilds over weeks. Plan the repair on that scale and do not count on a result after one fix in DNS. The evidence is usually sitting in the logs, so start by reading a bounce report.

If you are migrating from another provider or working your way out of a block, get in touch with our deliverability team. We will go through the configuration and the warm-up plan together.