Why Do Your Marketing Emails Land in Spam?
Why Do Your Marketing Emails Land in Spam?
Usually because your domain fails an authentication check, not because your subject line was too salesy. Gmail and Outlook.com now enforce hard technical requirements on anyone sending at volume. Miss one and your mail is filtered or rejected outright, no matter how good the content is.
We see this pattern constantly. A marketing team blames the copy, rewrites the campaign, and sends it again from the same misconfigured domain. Nothing improves, because the problem was never the words.
So before you touch the message, check the plumbing. Here is exactly what the two biggest inbox providers require, taken from their own documentation.
What Does Google Require From Bulk Senders?
Google's threshold is clear. Starting 1 February 2024, email senders who send more than 5,000 messages per day to Gmail accounts must meet its bulk sender requirements. That is 5,000 to Gmail addresses specifically, not 5,000 in total.
The requirements are a short list. Set up SPF and DKIM authentication for your domain. Set up DMARC for your sending domain. Use a TLS connection for transmitting email, a rule Google added in December 2023. Make sure your sending domains or IPs have valid forward and reverse DNS records, also called PTR records.
None of these are optional and none of them are graded on effort. They pass or they do not.
What Is the Spam Rate Number You Cannot Cross?
0.30%, and you should be aiming far below it. Google's guidance is to keep spam rates reported in Postmaster Tools below 0.30%, and then adds a stricter target: keep them below 0.10% and avoid ever reaching 0.30% or higher.
That second sentence is the one to internalise. The 0.30% figure is a cliff, not a budget. Touching it even once damages your reputation with Gmail, and reputation recovers slowly.
To put the number in human terms, 0.10% is one complaint per thousand delivered messages. A single badly targeted send to a cold list can breach that on its own, which is why we treat list quality as a deliverability control rather than a marketing preference.
What Does Outlook Require, and How Is It Different?
Microsoft's threshold is similar and its punishment is harsher. Microsoft defines a high volume sender as one sending 5,000 or more messages to Microsoft consumer email services, all using the same domain in the 5322.From address. That covers Outlook.com, Hotmail, Live.com and MSN.
Once you cross that line, both SPF and DKIM checks must pass, you must publish a DMARC record, and messages must pass DMARC validation with at least one of SPF or DKIM aligned to the domain in the 5322.From address. Microsoft's own documentation notes that a DMARC record of p=none is enough to satisfy the publishing requirement.
Fail it and the message does not get filtered, it gets refused. The bounce reads 550 5.7.515, access denied, sending domain does not meet the required authentication level. That is a rejection you can see in your logs, which is oddly helpful.
What Is Alignment, and Why Does It Break Things?
Alignment is the requirement that the domain doing the authenticating matches the domain in the visible From address. It is the single most common reason a team with SPF, DKIM and DMARC all configured still fails.
Here is the usual shape of it. You send through a marketing platform. SPF passes, because the platform's servers are authorised. DKIM passes, because the platform signs with its own domain. But the From address says yourcompany.com, and neither passing check is aligned to that domain. DMARC fails, and Microsoft rejects the message.
The fix is to set up a custom sending domain in your email platform so DKIM signs with a subdomain of yours. Most platforms support it, it takes a few DNS records, and it is the difference between delivered and refused.
Do You Really Need One Click Unsubscribe?
For marketing mail, yes. Google requires that marketing messages and subscribed messages support one click unsubscribe and include a clearly visible unsubscribe link in the message body. The technical implementation is defined by RFC 2369 and RFC 8058.
Notice it is both. A header that lets the inbox provider unsubscribe the user on their behalf, and a visible link in the email itself. Teams often implement one and assume they are done.
We think this rule is doing marketers a favour, even though it is presented as an obligation. Every person who unsubscribes easily is a person who did not press the spam button instead, and the spam button is the one that costs you 0.30%.
Should You Start DMARC at p=none or p=reject?
Start at p=none and move up. A DMARC policy of none means "monitor and report, change nothing", which is enough to satisfy both Google's and Microsoft's publishing requirements while you find out what is actually sending as your domain.
That discovery phase matters more than people expect. Almost every company we look at has forgotten senders: an old ticketing system, an invoicing tool, a recruiting platform, a survey service somebody set up two years ago. Move straight to a strict policy and you silently kill mail your business depends on.
Read the reports, authorise the legitimate senders, then tighten to quarantine and eventually to reject. The order is boring and it is the only order that works.
Does a Dedicated Sending Domain Help?
It helps a lot, and it protects the thing you cannot replace. Send marketing campaigns from a subdomain such as mail.yourcompany.com and keep your primary domain for the email your sales and support teams write by hand.
The reason is blast radius. If a campaign goes badly and reputation drops, the damage is contained to the subdomain. Your founder's replies and your invoices keep arriving. Mixing them means one bad list can take down business critical mail.
This is the same logic we apply to lifecycle email programmes, where automated and human mail have very different risk profiles and should not share a reputation.
What About the List Itself?
The list is where most spam complaints are born. Purchased lists, scraped addresses, and contacts imported from a conference badge scanner produce complaints at rates that no authentication setup can absorb.
The practical controls are unglamorous. Confirm opt in where you can. Remove anyone who has not opened in six to twelve months rather than emailing them harder. Suppress hard bounces immediately. And never quietly move someone from a content download into a weekly newsletter, which is the mechanism behind a surprising share of complaints, and one reason we are cautious about gated content.
A smaller list that wants to hear from you outperforms a large one that does not, on every metric including the ones Google measures.
How Do You Tell Whether It Is Working?
Instrument it before you need it. Set up Google Postmaster Tools for your sending domain, because it is the only place you can see the spam rate Google is actually measuring. Turn on DMARC aggregate reporting and read the reports. Watch bounce codes in your platform, because 550 5.7.515 is a specific diagnosis, not a generic failure.
Then send yourself test messages across Gmail, Outlook.com and a corporate Microsoft 365 tenant, and check the headers for SPF, DKIM and DMARC results. Open rates alone will not tell you this, and with modern privacy protections they are a poor signal anyway, which we cover in our piece on whether a B2B newsletter earns its place.
The goal is that a deliverability problem shows up as a number on a dashboard, not as a quarter of missing pipeline.
Where Should You Start This Week?
Check three things today. Does your domain publish a DMARC record. Does your marketing platform DKIM sign with your own domain rather than its own. Do your marketing emails carry a one click unsubscribe header as well as a visible link.
If any answer is no, that is your deliverability problem, and it is a DNS task rather than a copywriting task. Most teams can close all three inside a week, and the effect on delivered volume is immediate rather than gradual.
If your emails stopped landing and nobody can tell you why, we are happy to look at the sending setup with you and say which of these is the cause. You can find us at phoenix.studio.
Want a site that performs like this?
Tell us about your project. We will come back with a clear next step, no pressure.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Have a project like this?
Tell us where you want to go. We'll tell you how we'd get you there.