How-to

Why your emails go to spam, and how to fix it

Last reviewed 21 September 2026

Diagnose it in eight steps rather than guessing: find out which of four things actually happened to the message, read the refusal if there was one, check authentication because it is the only part that is simply right or wrong, read your complaint rate where the provider publishes it, look at who you sent to, then look at what you sent, prove it with accounts you control, and fix in the order that moves the number. Content is the last thing to check, not the first.

A message that lands in a spam folder has not necessarily been judged badly written. Four different things get called going to spam and they have different causes: a message refused at the door and handed back to you, a message accepted and filed into the spam folder, a message accepted and sorted into a tab that is not the inbox, and a message that reached the inbox and was never opened. Only the second is a filtering decision about you, and most of the work of fixing it is finding out which of the four you actually have.

Work out which of four things happened

Start from the evidence you already hold rather than from a list of content advice. Your sending tool reports deliveries and bounces, and those two answer different questions: a bounce means the receiving server refused the message and said so, and a delivery means it accepted the message and told you nothing whatever about where it put it. No mailbox provider reports folder placement back to a sender, which is why this is a diagnosis rather than a lookup.

Then ask who is affected. Trouble at one provider and nowhere else is a reputation or authentication problem with that provider, because reputation is held per provider and is not portable: Gmail knows nothing about what Yahoo thinks of you. Trouble everywhere at once, starting on a particular day, is almost always something you changed — a new sending domain, a jump in volume, a list you imported, a link you started including.

And ask one reader to look. Somebody who can open their own mail will tell you in ten seconds whether your message is in the spam folder, in a Promotions tab, or sitting unread in the inbox, and that single observation eliminates most of the possible causes. The tab is the one most often mistaken for a filtering decision. It is a sorting decision, it is personalised for each reader, and a message in it was delivered to the inbox.

What each symptom usually means, and the first thing to check
What you can observeWhat it usually meansWhat to check first
The message bounced with a permanent 5xx refusalThe receiving server refused it outright and said why in the textThe wording of the refusal, which normally names the policy it failed
In the spam folder at one provider, fine at the othersA reputation or authentication problem specific to that providerThat provider’s postmaster dashboard and the authentication it reports
In the spam folder everywhere, starting on one daySomething you changed: a domain, a volume, a list, a linkWhat changed that day, before anything about the message itself
In the Promotions tab rather than the inboxNothing is broken; tabs are a personalised sorting decision, not a filterWhether readers were told what to expect, not your DNS records
Only new subscribers are affectedThe confirmation message is being filtered, not the courseThe from name and domain on the confirmation, and how fast it is sent
Everything arrives and nobody clicksNot a deliverability problem at allThe subject line, the first sentence, and what you promised at sign-up

Read the refusal, because it usually names the reason

A refusal is the most useful thing that can happen to you, because it is the only part of this system that explains itself. A permanent refusal carries a 5xx code and a line of text written to be read by the person who sent the message, and the large providers have made that text specific on purpose. Google states that mail which is not authenticated with SPF or DKIM may be marked as spam or rejected with a 5.7.26 error, so an unauthenticated message can arrive in either place and the refusal is the version that tells you. A domain sending in volume to Outlook.com without meeting Microsoft’s requirements for high-volume senders is refused with 550 5.7.515 and a sentence naming the sending domain and the authentication level it failed to reach.

So the first thing to do with a bounce report is to read the messages in it rather than count them. Sending tools summarise bounces as a rate, which is the one presentation that throws away the explanation. Group them by their text instead. A hundred refusals with one sentence in common is one problem with one fix; a hundred refusals with a hundred different sentences is a list problem, and belongs in the step about who you sent to.

A temporary refusal is a different signal and worth separating out. A 4xx is the receiving side asking you to slow down, and a sender that responds by retrying harder is behaving like one that does not listen. Deferrals that clear by themselves are ordinary. Deferrals that accumulate over hours are volume arriving faster than your reputation currently supports, which is a rate problem rather than a content one.

Check authentication first, because it is the only binary

Everything else in this diagnosis is a judgement about degree. Authentication is not: SPF either passes or it does not, DKIM either verifies or it does not, and DMARC either aligns with one of them or it does not. It is also the part the large providers turned from a recommendation into a floor. Google’s sender guidelines ask bulk senders for SPF, DKIM and DMARC on the sending domain; Yahoo’s sender best practices ask for SPF and DKIM together with a published DMARC policy of at least p=none that passes; Microsoft applies the same three to high-volume senders reaching its consumer mailboxes. Below those volume lines the authentication floor still applies, because unauthenticated mail is refused at any volume.

Check it from outside rather than from inside your own tool. Your provider’s dashboard will tell you it signed the message, and what matters is what the receiving side concluded, which is written in the Authentication-Results header of a message that actually arrived. Send one to an account you control at each of the large providers, open the original, and read the three verdicts. Three passes moves this entire section off your list in about ten minutes, and that is worth having before you touch anything else.

Two failures account for most of what turns up here, and neither looks broken from a dashboard. The first is a domain publishing more than one SPF record: they do not merge, and the result is a permanent error rather than a union of the two. The second is alignment. A message can be signed correctly and pass SPF for a domain that is not the one in the From line, so both checks pass, DMARC fails anyway, and nothing in your sending tool mentions it. Both are invisible until something reads the headers a receiver saw.

Read your complaint rate where the provider publishes it

A spam complaint is a reader pressing a button, and it is the strongest signal a provider has about you, because nothing else in the system is a person saying so outright. Google asks bulk senders to keep the spam complaint rate reported in Postmaster Tools below 0.10 per cent and never to reach 0.30 per cent, and Yahoo publishes the same ceiling. Those are the only numbers in this diagnosis that somebody enforces against you, and they are enforced by filtering rather than by a letter, so the first sign of trouble is a quiet fall rather than a notice.

Do the arithmetic once for the size of list you actually have, because the percentage conceals how few people it takes. The ceiling works out at three complaints per thousand delivered messages. A small sender has no statistical cushion at all, only a structural one: a handful of addresses that never really asked for the mail is a rate breach on a small list and a rounding error on a large one, which is the argument for confirming every address stated as arithmetic rather than as principle.

Getting at the number requires proving you control the domain, and the dashboard reports nothing for a domain sending too little to be measured. That silence is itself information. If your volume is below the point at which a provider will report a rate at all, your complaint rate is not what is filtering you, and the cause is somewhere else in this list — most often in authentication, or in a sending domain with no history at all.

Look at who you sent to before you look at what you wrote

The most common cause of a change that arrived overnight is a change in the audience rather than in the writing. A list imported from another tool, a list that sat untouched for a year, addresses collected at an event or for an unrelated purpose: each of those is a batch of people who are meeting you as a surprise, and surprise is what a complaint is made of. If something in this paragraph happened in the fortnight before your mail started being filtered, it is the first thing to investigate and the writing is the last.

Old addresses carry a specific hazard beyond being uninterested. An abandoned mailbox is eventually recycled by its provider into a trap, and mail to a trap is evidence of a sender who does not clean a list rather than of one message gone astray. The signals that an address is still real are the ones a person has to perform deliberately — a click, a reply, a purchase, a login — and an open is no longer among them, so an address with nothing deliberate against it in a year should be re-permissioned or retired rather than mailed again.

And check the list you must never mail. Everyone who unsubscribed and everyone who complained belongs on a suppression list that travels with you between tools, and the classic way to resurrect them is an export taken before they left, imported somewhere with no record of their leaving. That single mistake produces complaints from precisely the people most willing to make them, which is why the suppression list moves first in any migration and is reconciled on the way in rather than at send time.

Then look at the message itself

Content does matter, and it matters much less than the four things above, which is why it is fifth. The checks worth making on a message are mechanical rather than stylistic, and each of them is a thing a filter or a reader can act on. Work through them once, fix what is wrong, and then stop: the returns on rewording fall away sharply, and the time is better spent on the list.

What is not worth your time is a list of trigger words, or a score out of ten from a tool that claims to predict placement. No provider publishes the function it uses, nobody outside one can compute it, and a score assembled from a public rule set is measuring a filter that stopped being the state of the art many years ago. The word “free” in a subject line has never yet cost anybody an inbox on its own. An unfamiliar sending domain with three complaints per thousand has.

The mechanical checks, in the order they are worth making:

  • A one-click unsubscribe in the headers and a visible unsubscribe link in the body. A reader who cannot find the link uses the spam button instead, which is the same signal with a far worse consequence.
  • A message small enough to arrive whole. Gmail stops rendering at around 102,400 bytes and replaces the rest with a link, which frequently cuts off the footer carrying the unsubscribe link and the postal address. Google documents no threshold, so that figure is an observed constant rather than a promise and is worth leaving room under.
  • Text that reads completely with images switched off, because several clients and gateways block remote images by default and a message that is one large picture with no text is the shape a filter is most suspicious of.
  • Links pointing at a domain of your own. A link shortener inherits whatever reputation every other user of that shortener has earned, and a redirect chain is the pattern a filter cannot tell apart from an attempt to hide a destination.
  • A From name and address that stay the same from message to message, and a reply-to that a human being actually reads. A borrowed “Re:” prefix on a message that is not a reply is not a trick worth trying; it is the most reliably punished thing on this list.
  • One subject line that describes the contents. A message whose subject promises something the body does not deliver produces the complaint that the filter is watching for.

Prove it with accounts you control, not with a score

At this point you have a hypothesis and you need an observation. The instrument for that is a seed list: a set of addresses you control at the providers your readers actually use, mailed alongside a real send so that you can open each account yourself and see which folder the message reached. It is the only way to observe the difference between delivery and deliverability, because no provider reports it, and a handful of real accounts tells you more than any score.

Read a seed result as an indication rather than a measurement. Seed accounts have no reading history, no contacts and no engagement, and filtering is personalised, so a message that reaches a seed inbox can still be filtered for a reader who has never clicked one of yours. The useful reading is comparative: the same message to the same seeds before and after a change, which is a much stronger design than one absolute verdict.

The other real instrument is the feedback loop, which is the arrangement by which a provider reports back the messages its users marked as spam so that those addresses can be suppressed the same day. Most sending platforms enrol in the loops that exist and act on them without being asked; Gmail runs no per-message loop of the usual kind and publishes an aggregate rate in its dashboard instead. What you cannot use is your open rate. Since Apple shipped Mail Privacy Protection in 2021 a proxy may load the tracking pixel whether or not anybody read the message, so a fall in opens is consistent with being filtered, with nothing at all, and with a change in which mail clients your readers happen to use.

Fix in the order that moves the number, and then wait

Fix authentication first, because it is binary, cheap and refused mail never gets the chance to earn a reputation at all. Then clean the list: suppress everything that bounced permanently, everything that complained, everything that left, and everything with no deliberate action against it in a year. Then bring the volume down and raise it on a ramp ordered by how recently each person did something. Content comes last, and by the time you reach it there is usually nothing left to fix.

Then wait, and change one thing at a time while you do. Reputation is what a provider has learned from a pattern over days and weeks, so it does not respond to a single good send, and neither provider publishes what the recovery window is or how long it takes. Changing five things at once means that when the mail starts arriving again you will not know which change did it, and you will be in exactly the same position the next time.

There is one structural advantage worth using deliberately while you recover. A course sends one message per subscriber per day counted from the day that person confirmed, so the volume spreads itself across the days people happened to sign up instead of concentrating a month of mail into one hour. A broadcast to a whole list is the pattern that looks least like ordinary mail to a receiving provider; a sequence fans out by construction, and a sender rebuilding a reputation is better off with the shape that does not spike.

Common questions

Why are my emails going to spam all of a sudden?

Something changed, and it is usually not the writing. The candidates in order are: a new or newly used sending domain, authentication that broke or was never finished, a jump in volume, and a batch of addresses that arrived from somewhere else — an import, an old list, a form for something unrelated. Work out first whether the mail is being refused with a bounce or accepted and filed, and whether it is happening at one provider or all of them. One provider means reputation or authentication there; all of them, starting on one day, means something you did that day.

How do I stop my emails going to the spam folder?

In this order: publish SPF, DKIM and DMARC for the domain you send from and verify them on a message that actually arrived, not in your sending tool. Suppress everyone who bounced permanently, complained or unsubscribed. Stop mailing addresses with no click, reply or purchase in the last year. Bring your volume down and raise it on a ramp ordered by recency. Put a one-click unsubscribe in the headers and a visible link in the body. Then look at the message. Recovery is measured in weeks, and changing one thing at a time is what tells you which change worked.

Is the Gmail Promotions tab the same as the spam folder?

No. The Promotions tab is part of the inbox and a message there was delivered, not filtered. Tab sorting is personalised for each reader and is not something a sender configures, so it is not a fault to fix in your DNS or your headers. It matters only in that a reader who does not check that tab will not see the message on the morning it arrives, which is a question about what you promised at sign-up and how recognisable your From name is, rather than a deliverability problem.

Can I tell from my open rate whether I am being filtered?

No, and it is the most common false lead in this whole diagnosis. An open is inferred from a tracking pixel being loaded, and since Apple shipped Mail Privacy Protection in 2021 that pixel may be fetched by a proxy whether or not anyone read the message. A fall in opens is equally consistent with being filtered, with nothing being wrong, and with a shift in which mail clients your readers use. Use bounces, complaint rates reported by the provider, clicks, replies and a seed list instead.

The short version: find out whether the message was refused, filed as spam, sorted into a tab or simply ignored, because those are four different problems. Read any refusal you were given, since the text normally names the policy that failed. Settle authentication first because it is the only part that is either right or wrong. Read your complaint rate where the provider publishes it, and do the arithmetic for the size of list you actually have. Look hard at who you sent to before you look at what you wrote. Then prove it with accounts you control rather than with a spam score, fix in that order, and give it weeks rather than an afternoon. The sources below are where the thresholds and the refusal codes in this guide are published.

Sources

  1. Google’s email sender guidelines, which set the complaint thresholds and the authentication floor
  2. Google Postmaster Tools, where the complaint rate for a domain is reported
  3. Yahoo’s sender best practices, which publish the same complaint ceiling
  4. Microsoft’s requirements for high-volume senders to Outlook.com, including the 550 5.7.515 refusal
  5. Apple’s documentation for Mail Privacy Protection

Read next

This page is part of Email deliverability for small senders: what decides it, which is the complete guide to the subject.

These guides are about the format rather than about any particular tool. What this site itself does is on the home page, and the rest of the set is on the guides index .

Elsewhere on this site

The rest of this site comes at the same subject from other directions: guides on the format itself, a tool for one job each, a page for each kind of work, what to check when choosing software, a course written out in full, the courses people have actually published here, and one definition or figure at a time.

Thinking of writing one of these?

5dayemail hosts a five-to-ten day email course: you write it once, and everyone who joins your list gets one email a day, in order, starting from the day they confirm.

Accounts are opened a few at a time rather than by signing up. Leave your address and you will be written to when the next ones open.

One message, when there is room. No course emails, no newsletter, and the address is not passed on. Ask and it is deleted; what is kept, and for how long, is in the privacy policy.