DEV Community

Cover image for Why Does My Email Go to Spam? A Diagnostic Order That Actually Works
Denys Button
Denys Button

Posted on

Why Does My Email Go to Spam? A Diagnostic Order That Actually Works

A step-by-step order for diagnosing why email lands in spam: technical auth first, then reputation and engagement, then copy last. Stop guessing.

Why Does My Email Go to Spam? Diagnose It in the Right Order

Something worked last month. Now half your sends are landing in Promotions, spam, or nowhere at all, and everyone on the team has a theory. Someone wants to rewrite the subject line. Someone wants to swap the send time. Someone's convinced it's the word "free" in paragraph two.

Most of that is noise. After 16 years working email infrastructure and deliverability across 1,000+ sending domains — including ramping fresh domains to 20,000+ sends/day in 14 days without triggering blocks — the pattern is consistent: people diagnose in the wrong order. They start with copy because copy is the easiest thing to blame and the easiest thing to change. But copy is rarely the actual cause, and "fixing" it without checking the plumbing first just burns another send cycle and another chunk of reputation.

Here's the order that actually finds the cause, fastest.

Step 1: Technical authentication — check this before anything else

If SPF, DKIM, or DMARC is broken or missing, nothing else you do matters. Mailbox providers use these three records to decide whether your mail is even eligible to be evaluated as legitimate, let alone land in the inbox.

  • SPF — does the sending IP appear in the domain's v=spf1 record? Check for permerror from exceeding 10 DNS lookups, a common silent failure.
  • DKIM — is the message actually being signed, and does the selector's public key in DNS match what's in the d= and s= tags of the signature?
  • DMARC — is there a _dmarc TXT record, and are SPF and/or DKIM aligned with the visible From domain (not just passing in isolation)?

Run the domain through MXToolbox's SPF/DKIM/DMARC checkers and dig for the raw TXT records yourself:

dig TXT yourdomain.com
dig TXT _dmarc.yourdomain.com
dig TXT selector._domainkey.yourdomain.com
Enter fullscreen mode Exit fullscreen mode

If any of these are broken, fix them before touching anything else downstream.

Step 2: Domain and IP reputation

Authentication passing doesn't mean the sender is trusted — it means the mail is verifiably from you. Reputation is a separate question.

  • Check the sending IP and domain against major blocklists (Spamhaus, Barracuda, SORBI) via MXToolbox's blacklist tool.
  • Pull up Google Postmaster Tools for the domain — check IP and domain reputation buckets, spam rate, and delivery errors over the last 30 days.
  • New domain or new IP? Reputation isn't built yet. Sudden volume on an unwarmed domain looks identical to a burst of spam from a compromised account, and filters treat it that way.

Step 3: List quality and engagement

Once auth and reputation are clean, look at who you're actually mailing.

  • Bounce rate above ~2% on a single send is a signal your list has decayed or was never verified.
  • Spam complaint rate above ~0.1% (Gmail's Postmaster threshold) will suppress inbox placement even with perfect SPF/DKIM/DMARC.
  • Low open/engagement rates over time train Gmail and Outlook's ML filters to deprioritize you specifically, independent of content.

Step 4: Content — check this last, not first

Only once the first three layers are clean does content start to matter. And even then, it's rarely a single trigger word — it's structural: an unusually high link-to-text ratio, image-only emails with no text, a mismatched display name and From address, or missing a plain-text part. Legitimate mail with a slightly awkward subject line still gets delivered when the domain is trusted and the list is clean.

Why this order, and not the reverse

Filters layer their decisions the same way this checklist does — auth first, reputation next, behavior third, content last as a tiebreaker. If you start by rewriting subject lines on a domain with a broken DMARC record, you're optimizing a variable that isn't the bottleneck. You'll "fix" something, see no change, and conclude the whole system is a black box. It isn't. It's just being diagnosed backwards.

One thing this checklist explicitly does not include: tricks to fool spam filters — hidden text, invisible characters, zero-width joiners, cloaked links. Those get flagged the moment a provider updates its model, and the damage to domain reputation outlasts the campaign that triggered it. There's no shortcut around clean infrastructure.

Quick self-check

  1. Do SPF, DKIM, and DMARC all pass and align? (dig + MXToolbox)
  2. Is the domain/IP on any blocklist? (MXToolbox blacklist check)
  3. What's the domain's reputation in Google Postmaster Tools?
  4. What's the bounce rate and complaint rate on recent sends?
  5. Only after 1–4 are clean: review subject lines, HTML structure, and link ratios.

Running through this manually across SPF, DKIM, DMARC, blocklists, and warm-up takes real time to get right the first time. The Cold Email Deliverability Kit (https://remixdenis.gumroad.com/l/kit) is a 20-minute technical diagnostic checklist covering exactly these steps, plus a separate content-audit checklist and a compliant HTML/SMTP boilerplate — no evasion tricks, just the setup that gets mail delivered. If you want the deeper version with real diagnostic walkthroughs, the course Deliverability Diagnostics: What Actually Gets Email to the Inbox (https://remixdenis.gumroad.com/l/mclaie) goes further.

Top comments (1)

Collapse
 
elijahbrown profile image
Elijah Brown •

Agree on the order. For signup-driven lists, a lot of that step 3 decay starts at the form, with typo and throwaway domains that were never going to accept mail, so a DNS check on the domain at signup (Null MX included) keeps them from counting against the bounce rate later.