How Email Deliverability Actually Works
A practical explanation of how mailbox providers decide whether to accept, filter, junk or reject your emails — and what marketers can control.
Email deliverability is often reduced to a single question: “Did the campaign send?” That is the wrong question. Sending is the moment your platform hands a message to the mail system. Deliverability is the broader outcome: whether a mailbox provider accepts that message, trusts it and places it where the recipient is likely to see it.
That distinction matters because a campaign can show a high delivery rate while still performing poorly. Messages may be accepted but filtered into spam, placed in a low-attention tab, delayed, or delivered to people who no longer want them. Conversely, a modestly sized, well-targeted campaign can outperform a much larger send because recipients recognise it, want it and interact positively.
There is no universal “inbox score” and no legitimate provider can guarantee inbox placement. Each receiving organisation uses its own combination of authentication checks, sending reputation, recipient behaviour, content signals and traffic patterns. The fundamentals, however, are consistent.
Deliverability, Delivery And Inbox Placement Are Different
| Term | What It Means | Example |
|---|---|---|
| Sent | Your sending system attempted to hand the email to the recipient’s mail server. | 10,000 campaign messages leave your platform. |
| Delivered | The recipient’s server accepted the message during SMTP transfer. | 9,850 messages are accepted; 150 hard-bounce because the addresses do not exist. |
| Inbox placement | An accepted message appears in the inbox rather than spam or another filtered area. | Some accepted messages appear in Gmail Spam despite not bouncing. |
| Engagement | What people do after receiving it: read, click, reply, ignore, unsubscribe or report spam. | Recipients click a product guide or mark the campaign as junk. |
SMTP is the protocol used to transfer email between servers. A successful SMTP acceptance is valuable, but it is not proof of inbox placement or reader attention. That is why a delivery rate alone cannot diagnose a deliverability problem.
The Decision Mailbox Providers Make
When a provider such as Gmail, Yahoo or Outlook receives a message, it evaluates a chain of evidence. The exact weighting is private and can change, but the practical process looks like this:
- Is the message technically valid? The provider checks the connection, message structure, sending IP and domain configuration.
- Can the sender’s identity be verified? Authentication records help prove that the visible sender domain authorises the mail.
- Does the sender have a trustworthy history? The provider considers domain, IP, link and sending-pattern reputation.
- Is this message expected and useful to this recipient? Consent, frequency, recency and past engagement all influence the answer.
- Does the message contain warning signals? These may include deceptive presentation, suspicious links, malformed HTML, attachment risk or a sudden change in sending behaviour.
- What should happen now? The provider may accept to inbox, accept to spam, defer temporarily (a soft bounce), reject, or rate-limit the traffic.
This is why deliverability is not a copywriting trick or a DNS-only project. It is an operating discipline spanning infrastructure, consent, data quality, campaign planning and measurement.
Authentication: Proving That Your Email Is Really Yours
Authentication does not make unwanted email welcome. It does give mailbox providers a reliable identity to evaluate, and it protects your domain from basic impersonation. The essential standards are SPF, DKIM and DMARC.
SPF
Sender Policy Framework (SPF) is a DNS record that lists the systems permitted to send mail for a domain used in the technical envelope sender. It is useful, but it can break when messages are forwarded because the forwarding server, rather than the original sender, may be assessed.
DKIM
DomainKeys Identified Mail (DKIM) adds a cryptographic signature to the message. The receiving provider uses a public key published in DNS to check that an authorised domain signed the mail and that the signed portions were not altered in transit. DKIM is particularly useful because its signature can survive many normal forwarding scenarios.
DMARC And Alignment
Domain-based Message Authentication, Reporting and Conformance (DMARC) ties authentication to the domain people see in the From: address. To pass DMARC, SPF or DKIM must pass and the authenticated domain must align with the visible From domain. “Alignment” means the domains match exactly or, under relaxed alignment, share the same organisational domain. A valid DKIM signature from an unrelated domain is therefore not enough. (IETF specification)
A practical example: a retailer sends from offers@example.co.uk. If its email service signs with DKIM using d=example.co.uk, DMARC alignment can pass. If it signs only with d=mailvendor.example, the signature may be valid but it will not align with the customer-facing domain.
For senders reaching personal Gmail accounts, Google requires SPF or DKIM for all senders, and SPF, DKIM and DMARC for senders exceeding 5,000 messages per day to Gmail accounts. It also requires alignment between the From domain and either SPF or DKIM for direct bulk mail. Yahoo has similar requirements for bulk senders, including DMARC passing and alignment. (Google’s sender guidance)
What to do: inventory every system that sends as your domain: marketing platform, support desk, billing service, ecommerce tool, recruitment system and any internal SMTP relay. Configure and test each one. Start DMARC in monitoring mode if you need visibility first, review the reports, then move towards an enforcement policy only when you understand all legitimate traffic.
Reputation: The History Attached To Your Mail
Mailbox providers learn from patterns over time. Reputation is not one public number; it is a set of provider-specific judgements associated with identities and behaviour, including:
- Domain reputation: the history of the domain in your From address and DKIM signature.
- IP reputation: the history of the servers that transmit your mail. This matters more when using dedicated infrastructure, but shared-IP users still need to protect their own domain reputation.
- Link and tracking-domain reputation: the destinations and domains used in the message.
- Recipient-level reputation: how particular recipients have reacted to your messages.
- Traffic consistency: whether volume, cadence, audience and message type make sense compared with your established pattern.
A new domain has little history, not a bad reputation. The risk comes from trying to create history too quickly by sending a large, unqualified audience immediately. Gradual ramp-up lets providers observe real recipient responses while limiting the impact of early mistakes. Google explicitly advises increasing volume slowly and notes that volume, frequency and recipient feedback affect how quickly a sender can scale. (Google’s sender guidance)
Keep marketing and operational mail distinct where possible. A password reset, receipt or service alert is normally expected and time-sensitive; a promotional campaign is optional. Separating message streams by From address and, where your infrastructure permits, by sending route makes it easier to protect essential mail if promotional activity attracts complaints. Yahoo specifically recommends not mixing bulk marketing mail with user, transactional or alert traffic on the same IPs. (Yahoo’s sender guidance)
List Quality And Consent: The Strongest Deliverability Lever
A poor list can defeat perfect authentication. If many recipients ignore, delete or complain about a campaign, providers receive a clear signal that the mail is not wanted. Buying lists, scraping addresses and importing old contacts without a clear permission basis commonly create this problem. They also produce more bounces, spam traps and complaints.
Build lists through clear, specific permission. Tell people what they will receive and roughly how often. Preserve consent evidence: when, where and how they subscribed, plus the wording shown at the time. Consider a confirmation email for higher-risk acquisition sources; Google’s current subscription guidance recommends recipients confirm their address after entering it, describing this as double consent. (Google’s sender guidance)
Then segment by meaningful behaviour rather than treating every address equally. For example:
- Send a new-product launch first to recent purchasers and subscribers who have recently clicked related content.
- Give less-active subscribers a lower-frequency digest, not every campaign.
- Run a focused re-engagement sequence for long-inactive contacts, then stop promotional sending to people who do not respond.
- Suppress hard bounces immediately and investigate sudden increases in soft bounces by mailbox provider.
Open rate should not be the sole measure of engagement. Privacy features and security tools can fetch tracking pixels or inspect links automatically, creating opens and clicks that do not reflect human interest. Treat clicks, replies, conversions, unsubscribes, complaint feedback and longer-term purchasing behaviour as a fuller picture. Filter known machine-generated activity before making major targeting decisions.
In Email Foundry, engagement scoring, List Health, Smart Re-engagement, Marketing Pressure and bot/security-click filtering are useful here because they make this discipline operational: marketers can reduce pressure on fading audiences, identify a re-engagement cohort and avoid treating automated activity as genuine intent.
Content Matters, But Context Matters More
There are no magic “spam words” that explain modern deliverability. A provider considers the whole message and the surrounding relationship. A legitimate promotion can be filtered when it is unexpected or sent too frequently; a plain-text receipt can be trusted because the recipient expects it.
Still, content and construction can create avoidable risk. Before sending, check the following:
- Use a recognisable From name and address that match the brand and subscription experience.
- Make the subject line accurate; do not disguise an advert as a reply, alert or account notice.
- Use accessible HTML, a sensible text alternative and working links.
- Avoid excessive redirects, mismatched display URLs and unexplained short links.
- Host images and landing pages on reputable, properly configured domains.
- Keep the campaign relevant to the segment receiving it.
- Test rendering, links, authentication and inbox risk before a large send.
A visual builder and brand controls can reduce accidental inconsistency, but they do not replace a reason for the recipient to care. Email Foundry’s Advanced Campaign Preflight & Inbox Risk, standalone template preview and email tests are most valuable as a final check for broken links, sending configuration and avoidable message-level issues before the campaign is released.
Unsubscribing Is A Deliverability Feature, Not A Loss
If someone no longer wants a marketing email, an easy unsubscribe is better than a spam complaint. Include a clear unsubscribe link in the message body, honour the request promptly, and offer a preference centre where appropriate so people can choose a lower frequency or different topics.
For relevant marketing and subscription traffic, one-click unsubscribe is implemented in message headers, not merely through a footer link. RFC 8058 specifies the List-Unsubscribe and List-Unsubscribe-Post mechanism. Gmail requires one-click unsubscribe for marketing and subscribed messages from bulk senders and recommends fulfilling requests within 48 hours; Yahoo requires a functioning list-unsubscribe header for bulk marketing mail and says unsubscribes must be honoured within two days. (Google’s sender guidance)
Do not force a login, survey or multi-step process before processing the one-click request. You can still provide a preference centre in the email body, but it should be an option, not an obstacle. Transactional messages such as receipts and password resets are generally treated differently; do not use that distinction as an excuse to place marketing content in essential service emails. Google’s guidance distinguishes subscription messages from messages sent because of an explicit action or request, such as receipts and one-time passwords. (Google’s sender guidance)
Measure The Right Signals And Diagnose By Provider
A sudden decline in overall results can conceal a concentrated Gmail, Yahoo or Outlook issue. Break performance down by mailbox provider, sending domain, campaign type, segment and time. Look for a sequence rather than one metric in isolation:
- Authentication failures: investigate first; a DNS or signing change can affect every campaign.
- Deferrals and bounces: distinguish temporary rate limiting from permanent address failures.
- Complaint signals: stop or reduce the problematic stream rather than sending more aggressively.
- Inbox placement deterioration: compare engaged and inactive segments, recent acquisition sources and link domains.
- Engagement decline: review frequency, relevance and whether expectations have drifted.
Google Postmaster Tools provides domain-level data and diagnostics including spam reports, delivery errors and authentication information for eligible traffic. Microsoft’s SNDS provides registered-IP health data such as volume and complaint information, while JMRP can send copies of messages reported as junk by Outlook.com users. These tools do not bypass filtering; they help you identify what must be fixed. (Google’s sender guidance)
Use seed or inbox-placement tests as diagnostic samples, not as a promise that every recipient will see the same result. Real recipient engagement and their individual mailbox history remain decisive.
When Deliverability Drops: A Sensible Triage Order
Resist the temptation to change everything at once. Start with the highest-impact, most verifiable causes:
- Pause campaigns to cold, imported or heavily inactive segments.
- Check SPF, DKIM, DMARC alignment, tracking domains, Return-Path and sending routes using a recently received message’s headers.
- Review bounce codes and deferrals by provider.
- Compare complaint, unsubscribe and engagement trends before and after the drop.
- Check whether volume, frequency, content type, sender address or link domains changed.
- Send the next campaign only to the most recently engaged, clearly opted-in cohort.
- Increase volume carefully as positive signals return; do not “blast through” deferrals.
For complex cases, a root-cause view is more useful than a generic warning that a campaign is “risky”. Email Foundry’s Deliverability Root Cause Engine, provider-aware warm-up and pacing controls, Mailbox Provider Recovery and Deliverability Guardian are relevant when a team needs to isolate whether the issue is configuration, reputation, volume or audience behaviour and then make measured changes rather than guessing.
Practical Action Plan
- This week: create an inventory of every service that sends from your domains. Confirm SPF, DKIM, DMARC and From-domain alignment for each stream.
- This week: inspect a live message header at Gmail, Yahoo and Outlook. Record the authentication results, envelope sender, DKIM domain and return path.
- Within two weeks: review acquisition sources, consent evidence, bounce handling and suppression rules. Remove addresses that are invalid or have no defensible marketing permission.
- Within two weeks: ensure promotional and subscription messages carry a visible footer unsubscribe link and correctly configured one-click unsubscribe headers. Test the entire opt-out journey.
- For every campaign: segment first, begin with the audience most likely to welcome the message, and keep frequency consistent with the promise made at sign-up.
- Every month: monitor provider-level reputation, complaint feedback, bounces, deferrals and engagement. Review any material change before scaling volume.
- When changing infrastructure: preserve authentication, separate critical transactional mail from promotional traffic, and ramp deliberately rather than moving the full volume in one day.
Good deliverability is the result of earning trust repeatedly. Authenticate the identity, send only what people asked for, make leaving easy, respect signs of declining interest and use provider-level evidence to improve. Those practices are more durable than any short-term inbox-placement tactic.
Frequently asked questions
What Is The Difference Between Email Delivery And Deliverability?
Delivery means the recipient server accepted the message. Deliverability includes whether it was trusted, filtered to inbox or spam, and likely to be seen by the recipient.
Do SPF, DKIM And DMARC Guarantee Inbox Placement?
No. They establish and protect sender identity, but mailbox providers also assess recipient feedback, list quality, volume, content, links and sending patterns.
What Is DMARC Alignment?
It means the visible From-domain aligns with a domain that successfully passed SPF or DKIM. This prevents an unrelated valid signature from authenticating the visible sender identity.
Why Can A Delivered Email Still Perform Poorly?
A message can be accepted but routed to spam, ignored, or delivered to an inactive recipient. Delivery rate alone does not measure inbox placement or engagement.
Does Every Email Need A One-Click Unsubscribe Option?
One-click unsubscribe applies to marketing and subscription mail, not ordinarily to true transactional messages such as password resets or receipts. A clear body unsubscribe link remains good practice for promotional mail.
Should I Send To Inactive Subscribers To Improve Sales?
Not by default. Repeatedly mailing unengaged contacts can harm reputation. Use a limited re-engagement programme, then suppress people who do not respond.
Can Open Rate Be Used As The Main Deliverability Metric?
No. Privacy protections and security scanners can generate non-human opens or clicks. Combine engagement data with complaints, unsubscribes, conversions, bounces, deferrals and provider-level diagnostics.
Sources and further reading
- Email Sender Guidelines — Google Gmail Help
- Email Sender Guidelines FAQ — Google Gmail Help
- Email Subscription Guidelines For Senders — Google Gmail Help
- Sender Best Practices — Yahoo Sender Hub
- RFC 8058: Signaling One-Click Functionality For List Email Headers — IETF
- RFC 7489: Domain-Based Message Authentication, Reporting, And Conformance — IETF
- Email Sender Guidelines And Postmaster Tools FAQ — Google Gmail Help