Skip to content
Deliverability

Email Deliverability Checklist Before Your First Campaign

A practical pre-send checklist covering permission, authentication, list quality, unsubscribe design, testing and sensible launch pacing—so your first campaign starts with a sound deliverability foundation.

Your first campaign is not simply a design exercise. Every message also introduces your sending domain, your list quality and your operational habits to mailbox providers. A beautiful email sent to people who did not expect it—or sent from a poorly configured domain—can be filtered, ignored or reported as spam. Conversely, a modest but useful campaign sent to a clearly opted-in, well-prepared audience has a much stronger starting point.

This email deliverability checklist is designed for the period before your first substantial marketing send. It focuses on the things you can verify, rather than on supposed “spam trigger words” or other shortcuts. Deliverability is not a single setting: it is the outcome of technical authentication, recipient permission, sending behaviour and the response your emails earn over time.

First, Distinguish Delivery From Deliverability

Delivery means the receiving mail server accepted the message. Deliverability is the broader question of whether the message reaches a useful place—normally the inbox or a relevant tab—and is seen as wanted by the recipient. An accepted message can still land in spam, be placed in a low-attention folder, or be ignored.

That distinction matters because a low hard-bounce rate alone does not prove that a campaign is healthy. You also need to consider complaints, unsubscribes, engagement, authentication results and placement across the mailbox providers your audience actually uses.

The Pre-Send Deliverability Checklist

Work through this in order. If a core item is not ready, postpone the campaign rather than compensating with a larger send or a more aggressive subject line.

1. Confirm That Every Recipient Has A Defensible Reason To Receive This Email

Start with the list, not the template. Ask: Where did each address come from, what did the person expect when they supplied it, and what exactly are we about to send?

  • Use addresses collected directly through your own forms, checkout, event registration, account creation or a documented offline process.
  • Keep a record of the source, date, wording shown at collection, subscription category and any later preference change.
  • Exclude people who opted out, complained, hard bounced, or whose consent does not cover this message type.
  • Do not use bought, rented, scraped or appended lists. “Verified” only means an address may be technically reachable; it does not establish permission or recipient expectation.
  • Segment the first send to the most recent and clearly engaged group instead of mailing every historical contact at once.

For UK marketing email, the rules depend on the recipient and context, but the ICO says organisations will normally need consent to send unsolicited marketing email to individual subscribers. The limited “soft opt-in” for existing customers has conditions, including marketing similar products or services and offering an opt-out when details are collected and in subsequent messages. The ICO also makes clear that sole traders and certain partnerships are treated differently from corporate subscribers. Treat this as operational guidance, not a substitute for legal advice on your circumstances. (ICO guidance)

Example: A retailer has 18,000 contacts from five years of sales. Its first campaign should not automatically go to all 18,000. A safer starting segment may be customers who opted in and have purchased or interacted recently, excluding anyone already suppressed. Older contacts can later be approached through a separate, carefully planned re-permission strategy where appropriate.

2. Make Your Sender Identity Obvious And Consistent

Recipients should immediately recognise who is emailing them. Use a stable, human-readable From name, a monitored reply address, and a From domain that belongs to your organisation. Avoid abruptly changing the From name, switching domains, or using a free consumer mailbox as the public face of a commercial campaign.

Separate marketing from essential operational mail where possible. For example, news@example.co.uk can send newsletters while orders@example.co.uk sends receipts. This helps recipients understand what they are receiving and limits the chance that marketing complaints affect important account or purchase communications. Gmail’s subscription guidance similarly recommends using different sending addresses for subscription and non-subscription messages. (Google’s sender guidance)

  • Check that replies go somewhere a person can monitor or that the reply handling is clearly explained.
  • Use the same sender identity in the signup form, welcome email and first campaign.
  • Include your organisation’s identity and appropriate contact details in the footer.
  • Use a branded tracking domain where available, rather than leaving campaign links on an unfamiliar third-party domain.

3. Authenticate The Sending Domain Before You Need It

Email authentication proves that your sending platform is authorised to send for your domain and helps receivers identify spoofing. It is fundamental infrastructure, not a deliverability “hack”.

Control What It Does Pre-Send Check
SPF Lists services authorised to send mail for a domain. Ensure every legitimate sending service is accounted for and that you do not publish competing SPF records.
DKIM Adds a cryptographic signature that lets recipients verify key parts of the message were authorised and not altered. Send a test and inspect headers to confirm DKIM passes for the domain you use in the From address.
DMARC Builds on SPF and DKIM, requiring the visible From domain to align with a passing authenticated domain and publishing instructions for failures. Publish a record, begin with monitoring if you need visibility, review reports, then strengthen policy when you understand all legitimate senders.

Gmail requires all senders to personal Gmail accounts to use SPF or DKIM, and requires bulk senders—those sending more than 5,000 messages per day to Gmail accounts—to use SPF, DKIM and DMARC. For direct mail, the visible From domain must align with either SPF or DKIM for DMARC to pass. Gmail also recommends 2048-bit DKIM keys where supported. (Google’s sender guidance)

Also establish the less visible basics: your sending service should use TLS; sending IP addresses need correctly matched forward and reverse DNS where you operate the infrastructure; and the domains used in links should resolve properly over HTTPS. If you use a managed sending platform, ask it which DNS records you must publish and send a real test after they are live—do not stop at seeing records in your DNS control panel.

In Email Foundry, authenticated SMTP, tracking-domain monitoring and campaign preflight are particularly useful at this point: use them to surface missing or inconsistent configuration before a campaign is scheduled, then verify the results in an actual received message.

4. Build A Suppression-First List Process

A suppression list is a safety control: it prevents addresses that must not receive marketing from being reintroduced through imports, segments or integrations. It should include unsubscribes, hard bounces, abuse complaints and internal test addresses where relevant. Never delete unsubscribes merely to make a contact total look better.

Before the first campaign:

  1. Deduplicate contacts and standardise obvious formatting errors.
  2. Remove or suppress hard bounces and previous complaints.
  3. Check that preference and consent fields are mapped correctly after any import.
  4. Validate new or uncertain addresses, but do not treat validation as permission.
  5. Build the send segment with explicit inclusion rules and explicit exclusions.

Address verification can reduce avoidable bounces, particularly after an import. Email Foundry’s Reoon verification can support this check. It should sit alongside—not replace—good acquisition practices, suppression handling and a careful first segment.

5. Give People An Immediate, Genuine Way To Leave

Unsubscribing should be easier than marking an email as spam. Put a clear unsubscribe link in the email body, make it work without requiring a login, and ensure it updates sending eligibility promptly. A preference centre is helpful when people may want fewer emails or different categories, but it must not become an obstacle to stopping marketing altogether.

For promotional and subscription messages, implement standards-based one-click unsubscribe as well as the visible footer link. RFC 8058 specifies an HTTPS List-Unsubscribe URI and a List-Unsubscribe-Post: List-Unsubscribe=One-Click header, covered by a valid DKIM signature. (RFC specification)

Gmail requires one-click unsubscribe and a clear in-message unsubscribe link for qualifying bulk senders’ marketing and subscribed messages. Its current subscription guidance also says senders should honour unsubscribe requests within 48 hours. Yahoo likewise recommends SPF, DKIM and DMARC authentication alongside a clearly visible body unsubscribe link. (Google’s sender guidance)

Test this yourself. Subscribe a test address, unsubscribe using the footer, then try to include that address in a fresh segment. It should be excluded. Repeat with the one-click header path if your platform provides it.

6. Make The Email Useful Before Making It Clever

Spam filtering is not defeated by avoiding a list of words. Mailbox providers assess many signals, including authentication, reputation, recipient actions and message characteristics. The practical content goal is simpler: make the email match the promise that led someone to subscribe.

  • Use a subject line that accurately previews the email. Do not disguise an offer as a reply, receipt or urgent account alert.
  • Put the main value and call to action near the top, without relying on a giant image to communicate the entire message.
  • Use live HTML text, descriptive links and meaningful image alternative text.
  • Check every link destination, including social icons, preference links and the hosted web version.
  • Keep the campaign focused. One primary message is usually easier for recipients to understand than six competing promotions.
  • Ensure the email works with images blocked and on a narrow mobile screen.

Use a plain-text alternative as well as the HTML version. It gives recipients and systems a readable fallback, and it is an opportunity to check whether your campaign still makes sense without visual design.

Email Foundry’s standalone template preview, visual builder, reusable blocks and hosted “View This Message Online” snapshots can make review more consistent. The important point is not the tool: it is having a defined reviewer check copy, rendering, links, legal footer and unsubscribe function before approval.

7. Test The Actual Message, Not Just The Draft

A preview catches layout problems; an inbox test catches a different class of problems. Send the finished campaign to a small internal seed list containing accounts at Gmail, Outlook and any mailbox provider that matters disproportionately to your audience. Review the received message on desktop and mobile.

Check the message headers as well as the presentation. At minimum, confirm SPF, DKIM and DMARC are passing, the From and return-path arrangements are expected, and tracking links use the intended domain. Gmail Postmaster Tools can show authentication, spam rate, reputation and compliance information once sufficient eligible traffic exists; it is a monitoring resource, not a replacement for testing. (Google’s sender guidance)

For a more structured assessment, tools such as Email Foundry’s Deliverability Test, Live Delivery receiver and inbox-placement testing can provide a repeatable preflight process. Treat results as diagnostic signals rather than a promise of identical inbox placement for every recipient.

8. Plan A Conservative First Send

There is no universal safe sending volume. The right pace depends on domain history, list size, audience freshness, provider mix and engagement. What is risky is a sudden large volume from a new or previously quiet sending identity—especially to old contacts.

Begin with the segment most likely to recognise and value the message. If results are healthy, expand gradually in planned batches. Keep marketing and transactional mail streams distinct, avoid several overlapping campaigns, and do not attempt to “make up” for low engagement by increasing frequency.

Provider-aware warm-up, editable pacing, Safe Sending Speed and Marketing Pressure controls are relevant Email Foundry features here. They can help operationalise a staged plan, but they cannot make an unconsented or stale list safe to mail.

A 30-Minute Final Preflight

Area Final Question Pass Condition
Audience Why is each person included? A documented source and appropriate permission or customer relationship exists.
Exclusions Have opt-outs, complaints and hard bounces been removed? Suppression rules are active and checked against the send segment.
Identity Will recipients recognise the sender? Stable From name, branded domain and monitored reply route.
Authentication Do tests show SPF, DKIM and DMARC passing? Authentication and alignment are confirmed in received headers.
Unsubscribe Can someone stop marketing easily? Visible body link works; one-click headers are present for relevant mail.
Message Does copy fulfil the signup expectation? Accurate subject line, useful content, clear primary action and working links.
Rendering Does it work in real inboxes? Seed tests reviewed with images on and off, on mobile and desktop.
Launch Is the first volume proportionate to your history? Engaged segment first, sensible batches and an owner assigned to monitor results.

What To Monitor Immediately After Sending

Do not regard “campaign sent” as the finish line. Watch hard bounces, complaint signals, unsubscribes, replies, delivery errors and engagement by segment and mailbox provider. A small number of unsubscribes is often healthier than frustrated recipients using the spam button; look for unexpected spikes rather than trying to drive unsubscribes to zero.

If performance is weak, pause expansion and investigate systematically. Start with the audience source and segment rules, then authentication and technical headers, then message relevance and cadence. Avoid repeatedly re-sending the same weak campaign to non-engagers. Email Foundry’s List Health, engagement scoring, Deliverability Root Cause Engine and mailbox-provider monitoring are useful for separating list, content and infrastructure signals during that review.

Practical Action Plan

  1. Today: document every contact source, build a permanent suppression process and choose the small, most clearly opted-in first segment.
  2. Before design approval: configure and test SPF, DKIM, DMARC, your sending domain and tracking domain. Assign someone to own DNS and someone to own campaign approval.
  3. Before scheduling: send to a cross-provider seed list; test desktop and mobile rendering, every link, footer details, replies and both unsubscribe routes.
  4. At launch: send in measured batches rather than treating the full database as a first test. Keep the next campaign unscheduled until you have reviewed the response.
  5. Within 24–48 hours: review bounces, complaints, unsubscribes, replies and provider-level diagnostics. Record what you learn and update the next segment, content plan or pacing accordingly.
  6. For every future campaign: repeat the preflight. Deliverability is maintained through consistent, recipient-respecting practice—not achieved once and forgotten.

Frequently asked questions

What Is The Most Important Deliverability Check Before A First Campaign?

Confirm that the recipients genuinely expect your marketing email and that unsubscribes, complaints and hard bounces are excluded. Strong authentication cannot compensate for an unwanted or stale list.

Do SPF, DKIM And DMARC Guarantee Inbox Placement?

No. They establish trustworthy authentication and are essential requirements or recommendations for major mailbox providers, but inbox placement also depends on reputation, recipient behaviour, content and sending patterns.

Should I Send My First Campaign To Every Contact?

Usually not. Start with the most recent, clearly opted-in and engaged segment, then expand carefully after reviewing results.

Is Email Address Verification The Same As Consent?

No. Verification can indicate whether an address is technically deliverable. It does not prove that the person agreed to receive marketing or expects your campaign.

Do I Need A Visible Unsubscribe Link If I Use One-Click Unsubscribe Headers?

Yes for relevant bulk marketing mail to Gmail: Gmail’s sender guidelines call for one-click unsubscribe support and a clearly visible unsubscribe link in the message body. A visible preference link is also good recipient experience.

How Quickly Should Unsubscribes Be Honoured?

They should be processed promptly and reliably. Gmail’s subscription guidance says to honour requests within 48 hours; operationally, immediate suppression is the safer target wherever your systems allow it.

Should Transactional And Marketing Emails Use The Same Sender Address?

It is better to distinguish them where practical. Different addresses or streams help recipients recognise message types and can reduce the risk that marketing complaints affect important receipts, alerts or account messages.

Sources and further reading

More practical guides

Email Marketing

How To Build A Safe Daily Sending Allowance

A safe daily sending allowance is not a fixed number copied from another sender. It is a controlled, provider-aware plan that protects consent, reputation and customer experience while allowing volume to grow when the evidence supports it.

Read article →