Why Are My Emails Going to Spam? A Developer's Checklist
Your API call returned 200, the logs say “delivered”, and the user says the email never arrived. Usually it did arrive — in the spam folder. “Delivered” means the receiving server accepted the message; where it files it is a separate decision, made from signals about you, your domain and the message.
This checklist goes through those signals roughly in the order they matter, and ends with how to find out which one is hurting you.
1. Authentication: SPF, DKIM and DMARC
Unauthenticated mail is the easiest thing for a filter to distrust, and Gmail and Yahoo now reject or junk bulk mail without it. Check that:
- SPF passes for the envelope sender, and your domain has exactly one SPF record.
- DKIM signs with your domain (
d=yourdomain.com), not only your provider’s. - DMARC passes with alignment, and the policy is not stuck at
p=none.
If any of these fail, fix them first; nothing else on this list compensates. The SPF, DKIM and DMARC setup guide has exact records and the common mistakes.
2. Sender reputation
Providers keep a reputation score for the sending IP and, increasingly, for the sending domain. It is built from how recipients react to your mail over time: opens and replies push it up; spam reports, mail to non-existent addresses and deletions without reading push it down. Reputation explains most “it worked yesterday” problems.
- New domains and IPs start with none. Ramp volume up gradually — see email warmup.
- Separate transactional from marketing. Send newsletters from a subdomain such as
news.yourdomain.comso a poorly received campaign cannot drag down password resets. - Check the provider dashboards. Google Postmaster Tools shows your domain’s spam rate and reputation for Gmail; Microsoft SNDS shows data for sending IPs you control.
3. Spam complaints
A “Report spam” click is the strongest negative signal a recipient can send. Gmail and Yahoo ask bulk senders to keep reported spam under 0.3%, and under 0.1% is a safer target. Complaints come from people who don’t remember signing up, who can’t find an unsubscribe link, or who are getting more mail than they expected.
- Only mail people who asked for it, and say who you are in the first line.
- Make leaving easy: a visible unsubscribe link and one-click unsubscribe headers (RFC 8058) on anything that is not transactional. An unsubscribe is harmless; a spam report is not.
- Stop mailing anyone who complains. Mailbox providers send complaint reports through feedback loops; make sure they reach your suppression list.
4. Bounces and list hygiene
Sending to addresses that don’t exist tells providers you don’t maintain your list, which is what spammers look like. Keep bounces well under 2%:
- Suppress hard bounces immediately and permanently.
- Validate addresses at signup and confirm them with a double opt-in email.
- Never import a bought or scraped list; they are full of dead addresses and spam traps.
- Stop mailing people who haven’t opened or clicked in months, or send them a re-permission message first.
The mechanics of doing this automatically are in email bounce handling with webhooks.
5. Content and formatting
Content matters less than it used to — reputation dominates — but it still tips borderline messages:
- Send a plain-text part alongside the HTML. A
multipart/alternativemessage looks like normal mail. - Avoid image-only emails; a single large image with no text is a classic spam pattern.
- Use links on your own domain. Public URL shorteners and links whose visible text shows a different domain than the actual URL are flagged.
- Keep the
From:name and address consistent, and use a real reply-to address rather thannoreply@where you can. - Don’t send a test like “test 123” to a big provider from a new domain — it is the least trustworthy message you could send.
6. Volume and consistency
Sudden spikes look suspicious. A domain that sends 200 emails a day and then 50,000 in an hour will be throttled with temporary 4xx deferrals, and some of that mail will be junked. Spread large sends out, and ramp up gradually after long pauses.
How to find out which one it is
Send the message to a mailbox you control at the provider in question, open it, and view the original source (Gmail: “Show original”; Outlook: “View message source”). The headers tell you most of what the receiver decided:
Authentication-Results: mx.google.com;
dkim=pass header.i=@yourdomain.com header.s=selector1;
spf=pass smtp.mailfrom=bounce.yourdomain.com;
dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=yourdomain.com- Any fail or none in Authentication-Results: fix authentication first.
- All pass but still in spam: it is reputation or content. Check Postmaster Tools for Gmail, and compare against a plain message with no links.
- Only one provider junks you: look at that provider’s reputation tools and your complaint rate there.
- Messages never arrive at all: look for a bounce or a
4xxdeferral in your sending logs — that is a delivery problem, not a filtering one.
If you use open and click tracking, remember it rewrites links and adds a pixel. That is normal and not a spam signal on its own, but if a tracked version lands in spam and an untracked one doesn’t, the shared tracking domain is the likely cause: switch to a custom tracking domain on a subdomain of your own. PostStack supports one with a single CNAME — see tracking.
The short checklist
- SPF, DKIM and DMARC all pass, aligned to your From domain.
- DMARC is at quarantine or reject, not none.
- Complaint rate below 0.1%, bounce rate below 2%.
- Hard bounces, complaints and unsubscribes are suppressed automatically.
- One-click unsubscribe on everything that isn’t transactional.
- Marketing on a separate subdomain from transactional mail.
- New domains and IPs warmed up gradually; no sudden volume spikes.
- HTML plus plain text, links on your own domain, no image-only mail.
PostStack handles several of these by default: it recommends DMARC at p=quarantine, suppresses hard bounces and complaints automatically, and adds one-click unsubscribe headers to broadcasts. The rest — who you mail and what you send them — is up to you.
Frequently asked questions
Why do my emails go to spam when they are delivered?
Delivered means the receiving server accepted the message. Whether it goes to the inbox or spam is a separate decision based on authentication, the reputation of your domain and IP, complaint and bounce rates, and the content of the message.
What spam complaint rate is too high?
Gmail and Yahoo ask bulk senders to keep reported spam below 0.3%, and recommend staying under 0.1%. A sustained rate above that is one of the strongest negative reputation signals.
How do I see why Gmail put my email in spam?
Open the message, choose Show original and read the Authentication-Results header for SPF, DKIM and DMARC results. If all pass, check your domain’s spam rate and reputation in Google Postmaster Tools.
Continue reading
A step-by-step guide to the three DNS records that authenticate your email: exact SPF, DKIM and DMARC examples, the mistakes that break them, and how to verify them with dig.
Email Bounce Handling with Webhooks: A Developer's GuideHow to handle email bounces and spam complaints with webhooks: classify bounces, verify signatures, process events idempotently and keep a suppression list that protects reputation.
Automate SPF, DKIM, and DMARC with HostStack DNSStop copy-pasting DNS records every time you add a sending domain. PostStack's HostStack integration publishes SPF, DKIM, DMARC, and return-path records straight into your zone and verifies in seconds.