Browse templates
Guide · Email · Deliverability

How to improve email deliverability once you are already sending: authentication that keeps passing, a reputation you can read, and a list that stays clean.

This guide covers ongoing email deliverability for a B2B team that already sends. It explains what Google, Yahoo and Microsoft publish as requirements, and how authentication fails quietly.

Then sender reputation, how spam complaint rate is calculated, why bounces and list quality move it, what filters read in your content, and what to do after a reputation drop. Setting up a new domain is covered separately.

Last checked Sep 23, 202616 min readWritten for B2B teams that send sales email every week

What email deliverability actually means

Email deliverability is whether the emails you send reach the inbox, rather than the spam folder, a quarantine or an outright rejection. To improve email deliverability once a program is already running, you have to read what mailbox providers report, not what your sending tool reports.

The first half is acceptance: the receiving server took the email and returned a success code. The second half is inbox placement: the email was filed somewhere a person will look. An email filed as spam was accepted, so it counts as delivered on almost every dashboard.

That gap is why teams improve email deliverability by looking at provider feedback instead of their own send logs. Google, Yahoo and Microsoft each publish what they expect from senders, and each returns signals when you fall short. This page is about reading those signals while a program is running.

Starting from zero is a different problem with different rules. Our email warm up guide covers the first weeks of a new domain and mailbox. Everything below assumes the domain already sends.

Email deliverability vs delivery rate

Two numbers get called the same thing. The delivery rate is the share of emails a receiving server accepted. Email deliverability is the share that reached an inbox. The first stays high even when every email lands in spam, because a spam folder delivery is still a delivery.

No mailbox provider reports inbox placement back to you directly. The practical substitute is a handful of seed accounts you own at Gmail, Outlook.com and Yahoo, opened and read by a person after each campaign, plus the reply rate from the segment you emailed.

Marketing email programs and sales email programs read the same signals here, but they start from different places: one has subscribers who opted in, the other has prospects who did not.

No benchmarks here

Deliverability vendors publish inbox placement and average bounce figures measured on their own customers. None of those numbers appear on this page. The only percentages below are the ones Google and Yahoo publish as requirements.

What actually decides where a message lands

Filtering is not a single score. Mailbox providers combine identity checks that either pass or fail, a rolling reputation built from past behavior, and per-message signals from content and recipient response.

LayerWhat it checksHow fast it changes
AuthenticationWhether SPF, DKIM and DMARC pass and align with the From domainImmediately, on every email
InfrastructureForward and reverse DNS, TLS, RFC 5322 formattingImmediately, once DNS propagates
ReputationSpam history for the sending domain and the sending IPSlowly, over days and weeks
Recipient responseSpam reports, replies, deletions, unsubscribesDaily, and it drives reputation
Content and linksHeaders, display names, visible links, attachmentsPer message, per campaign
Sending patternVolume, consistency, which stream sends whatOver days, and spikes are read fast

The first two layers are binary and cheap to fix. The rest are earned. Teams usually spend their effort on subject lines while an authentication failure or a dirty list is doing the real damage.

The published rules you have to keep meeting

Three sets of published requirements govern most B2B email: Google for personal Gmail accounts, Yahoo for the domains it hosts, and Microsoft for Outlook.com. They overlap more than they differ.

RequirementGoogle (Gmail)YahooMicrosoft (Outlook.com)
Minimum authenticationSPF or DKIM for all sendersSPF or DKIM for all sendersSPF, DKIM and DMARC over 5,000 a day
Bulk sender lineMore than 5,000 messages a day, counted per primary domainNo volume threshold publishedMore than 5,000 emails a day
DMARCRequired for bulk senders, p=none is enoughValid policy, at least p=none, and DMARC must passAt least p=none, aligned with SPF or DKIM
Spam complaint rateBelow 0.3%, with 0.1% named as the target in the FAQBelow 0.3% for bulk sendersNo number published, hygiene practices listed instead
UnsubscribeOne-click for marketing mail from bulk senders, honored in 48 hoursList-Unsubscribe header, honored within two daysFunctional, clearly visible opt-out links
Reverse DNSValid forward and reverse DNS for sending domains or IPsValid, meaningful, non-generic PTR recordsNot listed in the high volume announcement
If you miss itRate limiting, spam foldering, rejection, no mitigationSpam folder or rejection with a specific error codeRejection with 550 5.7.515

Google's FAQ adds a detail worth planning around. Once a domain has crossed the 5,000 message line even once, it is permanently classified as a bulk sender, and reducing volume later does not remove the classification.

Yahoo deliberately declines to publish a volume threshold. It classifies a sender at the authenticated domain or From header domain level and reviews content and IP alongside volume.

Authentication: the part that is either right or wrong

Authentication answers one question: is this domain allowed to send this email? Three records answer it together, and each fails in its own way.

SPF

SPF publishes the list of hosts allowed to send for your domain. RFC 7208 defines it as a way for a domain to authorize the hosts that may use its name in the SMTP envelope. It validates the envelope sender, not the address your recipient sees.

DKIM

DKIM adds a cryptographic signature that lets the signing domain claim responsibility for a message, and lets receivers verify the content was not altered in transit. RFC 6376 requires signers to use RSA keys of at least 1024 bits. Gmail requires the same minimum and recommends 2048.

DMARC

DMARC ties the other two to the visible From address and tells receivers what to do when neither passes. RFC 9989, which replaced RFC 7489 in May 2026, defines three policies: none, quarantine and reject. Quarantine asks receivers to treat failures as suspicious, and reject asks them to refuse the message during the SMTP transaction.

Google and Yahoo both require DMARC alignment for bulk senders: the organizational domain in the From header must match either the SPF domain or the DKIM domain. Google says only one of the two needs to align, and recommends aligning both. RFC 9989 adds that a pass alone does not guarantee inbox delivery.

The SPF limit that breaks records quietly

Most SPF failures at established senders are not typos. They are lookup limits, reached gradually as the team adds another tool that sends mail.

  • Ten lookups, hard stop. RFC 7208 requires implementations to limit the terms that cause DNS queries, include, a, mx, ptr, exists and redirect, to ten during evaluation.
  • Over the limit means permerror. The RFC says implementations must return permerror when the limit is exceeded, so SPF fails for every email, not just some.
  • Void lookups count too. The same section says implementations should limit lookups that return no answer to two, with permerror above that.
  • Each vendor adds more than one. A single include can chain into several further lookups, which is why the count creeps up without anyone editing the record.
  • Microsoft names this failure directly. Its high volume sender FAQ says that exceeding ten DNS lookups may cause the SPF check to fail, and points to flattening or reducing includes.

Count the record, not the entries. A record with four includes can be over the limit, and a record with eight can be under it. Recheck after every new tool is connected to the sending domain.

Moving DMARC from none to enforcement

A policy of none satisfies every published requirement. It also does nothing about someone spoofing your domain, which is the reason DMARC exists.

p=nonereport only
Read reportsfind real senders
Align all sourcesSPF or DKIM
p=quarantinefailures to spam
p=rejectfailures refused
Week oneOngoingPer toolWhen cleanWhen confident

RFC 9989 defines the rua tag for aggregate reports, and calls p=none with those reports turned on monitoring mode. Yahoo strongly recommends including rua so you can monitor during setup. Microsoft sends aggregate reports to the address in your record and states it has no plans to send forensic reports.

Microsoft's own guidance is to move gradually from none to quarantine to reject, once legitimate sources are aligned, to avoid unintended mail loss.

RFC 9989 removes the old pct tag, so applying a policy to a percentage of failing mail is no longer part of the standard. A t tag covers testing instead: with t=y, the domain owner asks receivers to apply a quarantine policy as none and a reject policy as quarantine.

Sender reputation, and how to read it

Sender reputation is the rolling record a provider keeps about your domain and your sending IP. It is not a public score, and the only reputation view any of the three providers gives you directly is the Google Postmaster Tools dashboard.

RatingWhat Google says it meansPractical effect
BadHistory of sending a high volume of spam regularlyEmail is almost always marked as spam or rejected
LowHistory of sending a significant volume of spam regularlyEmail is likely to be marked as spam
MediumHistory of legitimate mail that occasionally sends spamFair inbox delivery, except when spam volume rises
HighHistory of very low spam rates and compliance with the guidelinesEmail is rarely marked as spam by Gmail

Google lists the behaviors that pull a rating down: sending spam, sending malware, sending from suspicious domains and sending unauthenticated messages. Messages that Gmail itself flags count toward that history, not only the ones recipients report.

Domain reputation and IP reputation are tracked separately. Google notes that a shared IP carries the activity of everyone on it, and that IP quotas are shared while SPF and DKIM quotas follow your domain. Yahoo recommends separating bulk mail from user mail by IP or DKIM domain for exactly this reason.

Spam complaint rate, the only published number

Two of the three providers publish a threshold, and they publish the same one. Google's sender guidelines say keep the spam rate reported in Postmaster Tools below 0.3%. Yahoo says keep your spam rate below 0.3%.

Google's FAQ is stricter than the guidelines page. It says to keep the user-reported spam rate below 0.1% and prevent it from ever reaching 0.3% or higher, and states that rates above 0.1% already have a negative effect on inbox delivery for bulk senders.

The impact is graduated rather than a cliff. Google describes rates of 0.3% or higher as having an even greater negative effect, and says spam rate is calculated daily and updated daily in Postmaster Tools.

How the number is calculated

  • Google counts inbox deliveries. The spam rate is the percent of messages delivered to engaged recipients' inboxes and then marked as spam, for DKIM-authenticated mail.
  • Yahoo does the same. Yahoo states its spam rate is calculated on mail delivered to the inbox, which is why your own calculation will differ.
  • A falling rate can be bad news. Google warns that if a lot of your mail is already being filed as spam automatically, the reported rate drops because fewer messages reach the inbox to be reported.
  • A rate of exactly zero deserves a second look. Google says an extremely low spam rate may mean something is affecting the accuracy of the data.

Small B2B volumes make this arithmetic brutal. At a few dozen emails to Gmail in a day, one complaint is far above 0.3% for that day. The defense is not clever content. It is sending to people who recognize the sender.

Feedback loops

Both Google and Yahoo will tell you which campaigns are being reported, if you ask. Yahoo's Complaint Feedback Loop sends a report in Abuse Reporting Format each time a user marks your email as spam, and it requires your DKIM signing domain to be enrolled through Sender Hub.

Google's Feedback Loop works by campaign identifier instead. Once set up, the Feedback Loop dashboard shows the average spam rate across campaigns and the number of unique identifiers per day, so you can tell which email type is generating the reports.

List quality, bounces and suppression

List quality is the input that moves every other number. Complaints come from people who did not want the email, and bounces come from addresses that should not have been on the list.

RFC 5321 splits server replies into two classes that matter here. A 4yz reply is a transient negative response that can succeed if repeated without changes. A 5yz reply is permanent, and repeating the same command will fail again.

SignalWhat it usually meansWhat to do with it
Permanent bounce (5xx)The address does not exist or the message was refused on policySuppress the address permanently, do not retry
Temporary failure (4xx)Throttling, a busy server or a temporary authentication errorSlow down, retry with increasing delays
Excessive unknown recipientsToo many invalid addresses in one runStop the campaign, re-verify the list source
Excessive user complaintsRecipients are reporting mail they did not ask forReview content and consent before sending again
Repeated non-responseThe contact is not the right person, or not interestedMove to a sunset list and stop after a set number of touches

Yahoo is explicit on both ends. It says list managers should have a policy for removing addresses that generate 5xx bounces, and it treats a large number of invalid recipients as a sign of an open relay or a bought list.

Microsoft's hygiene guidance for high volume senders is to remove inactive or invalid addresses regularly, monthly or quarterly, to lower bounces and complaints. Google puts it differently and asks senders to consider unsubscribing recipients who never open or read messages.

For outbound teams the practical version is upstream. A researched list of the right roles at the right companies bounces less than a bought one, which is the argument our prospect list guide makes from the pipeline side. Buying addresses is explicitly listed by Google as a practice to avoid.

Engagement, and what mailbox providers can see

Engagement is the deliverability factor senders talk about most and measure worst. Mailbox providers see whether an email is opened in the client, replied to, deleted unread, rescued from spam or reported. Your sending tool sees a tracking pixel load, which is not the same thing.

Google is blunt about the gap. It states that it does not track open rates, cannot verify open rates reported by third parties, and that low open rates are not necessarily an accurate indicator of deliverability or spam classification problems.

What providers do act on is whether your audience keeps choosing to read your emails. Google's spam rate is calculated on emails delivered to engaged recipients' inboxes, which means the people who still interact with your mail are the ones whose reports count.

  • Ask subscribers to confirm they still want the emails. Google asks senders to periodically send messages confirming that recipients want to stay subscribed.
  • Retire the ones who never answer. Google suggests considering unsubscribing recipients who do not open or read your emails at all.
  • Yahoo says the same from the other side. It warns that emailing users who are not reading, or who report the mail as spam, harms your delivery metrics and reputation.
  • Reconfirm inactive subscribers. Yahoo recommends sending a reconfirmation email to inactive subscribers periodically, and monitoring inactive recipients alongside hard and soft bounces.
  • Watch the signal in both directions. Google's deliverability analysis tool produces recommendations both when recipients do not interact and when they indicate they want more of your emails.
  • Help people self-select. Yahoo asks senders to set expectations at signup about what emails will arrive and how often, and to honor the frequency subscribers agreed to.

For outbound sales email the engagement metric that matters is not an open at all. It is a reply, positive or negative, because a reply is the one action a filter cannot misread. A segment that never replies is a segment to shrink, not a segment to email harder.

This is also where deliverability and audience selection stop being separate jobs. Targeting fewer, better-matched people raises engagement, lowers complaint rates and improves inbox placement at the same time, which is the argument the sales outreach hub makes about list size in general.

Content, headers and links filters read

Content rules are less mystical than folklore suggests. Google publishes them, and most of them are about honesty rather than word choice.

  • One address in From. Google's formatting guidance asks that From headers contain a single address, and that single-instance headers appear only once.
  • Display names identify the sender. Google asks that display names state who is sending, not what the message says, and lists examples like urgent alerts and fake reply markers as violations.
  • No fake threading. Subject lines should not start with Re: or Fwd: unless the message really is a reply or forward.
  • No hidden content. Using HTML and CSS to hide content may cause messages to be marked as spam.
  • Links should be visible and understandable. Recipients should know where a link goes before they click it.
  • Do not mix stream types. Google asks senders not to combine content types, such as putting promotions inside a receipt.
  • Attachments are a risk. Google lists unsupported attachments as a delivery error category with its own rejection reason.

Google's delivery error documentation also names content itself as a rejection reason, and says some content types, internet links among them, increase the chance a message is treated as spam. For cold outreach that argues for fewer links, not cleverer ones.

None of this makes a bad email land. It removes reasons for a filter to refuse a good one. The writing side sits in our subject line guide and outreach tips.

One-click unsubscribe, done properly

One-click unsubscribe is a header pair, not a link. RFC 8058 requires a List-Unsubscribe header containing one HTTPS URI, and a List-Unsubscribe-Post header containing exactly the value List-Unsubscribe=One-Click.

  • DKIM must cover the headers. RFC 8058 requires the message to carry a valid DKIM signature covering at least the two unsubscribe headers.
  • The URI carries the identity. The POST request may not include cookies or any other context, so the URI itself must identify the recipient and the list.
  • No redirects. The RFC states the sender must not return an HTTPS redirect for the POST.
  • A body link does not substitute. Google says a mailto link or a link to a preferences page in the body does not meet the requirement on its own.
  • Your infrastructure counts. Google notes that a successful request counts toward compliance even if a service in front of your servers blocks it from reaching you.

The windows are short. Google recommends removing recipients within 48 hours and shows Honor unsubscribe as needing work when requests take longer. Yahoo requires unsubscribes to be honored within two days.

Volume, consistency and stream separation

Mailbox providers watch the shape of your sending as well as its size. Google's guidance is to send at a consistent rate, avoid bursts, and avoid sudden volume spikes if you have no history of sending large volumes. It names doubling previous volume as an example that can trigger rate limiting.

The same page asks senders to increase volume slowly after any significant change, including a change to message format or sending infrastructure, and to ramp the changed segment separately from the rest.

  • Quotas differ by identifier. Google says DKIM and SPF quotas are specific to your domain, while an IP quota is shared by every sender on that IP.
  • One category, one address. Google recommends that messages of the same category share a From address, and different types use different addresses.
  • Separate the mail types. Yahoo asks senders not to send bulk or marketing mail from the IPs used for user and transactional mail.
  • Honor the stated frequency. Yahoo asks senders not to start daily mail to people who signed up for a weekly or monthly list.
  • Add mailboxes, not pressure. When a stream needs more volume, a second sending identity is safer than pushing one past a steady rate.

Cadence design and volume are the same decision in outbound. Our sales cadence guide covers the sequence side, and the cold email hub collects the rest of the channel.

Forwarding, ARC and the failures that are not yours

Some authentication failures happen after your server has done everything right. Microsoft's documentation explains why: server-based forwarding changes the message source, and the forwarding server is not authorized in your SPF record, so SPF fails as a false positive.

DKIM behaves differently. Because the signature lives in the headers and is not altered by forwarding, forwarded messages can still pass DKIM. That is the main reason to sign with DKIM even where only SPF is required.

ARC exists for the rest. It preserves the original authentication results across services that modify mail in transit, so a receiver can accept a message that would otherwise fail DMARC. Yahoo asks forwarders to implement ARC, and Microsoft describes trusted ARC sealers on the receiving side.

Google also notes that Postmaster Tools tries to exclude forwarded messages from dashboards but may not catch all of them, and that odd failure rates can come from forwarding or from replay attacks on old signed messages.

Monitoring with Postmaster Tools

Postmaster Tools is the closest thing to an objective email deliverability scoreboard any mailbox provider offers, and it only covers personal Gmail accounts, those ending in gmail.com or googlemail.com. Business mailboxes on Google Workspace are not included.

DashboardWhat it showsRead it when
Compliance statusWhether you meet each published sender requirementMonthly, and after any DNS change
Spam ratePercent of inbox deliveries marked as spam by recipientsWeekly, and after every campaign
Domain and IP reputationThe Bad, Low, Medium or High rating for eachMonthly, as a trend
AuthenticationPercent of mail passing SPF, DKIM and DMARCAfter any sending tool is added
Delivery errorsPercent of authenticated mail rejected or temp failed, with reasonsThe moment volume drops
Feedback loopSpam rate per campaign identifierWhen complaints rise and you need the source

Google says the information in Postmaster Tools helps senders meet the requirements in its email sender guidelines, and it costs nothing beyond verifying the domain you authenticate with.

Three limits are worth knowing before you trust a chart. Dashboard data is not real time and typically updates within 24 hours. Data may be withheld entirely on days when your volume is low, to protect user privacy. The tool reports in Coordinated Universal Time.

The compliance dashboard shows each requirement as Compliant, Needs work or No data found, and Google says changes can take up to seven days to appear after you fix something. That lag is the reason to change one thing at a time.

Reading the codes instead of guessing

Every mailbox provider tells you why it refused an email. The codes are the least ambiguous feedback in the whole channel.

CodeProviderWhat it means
4.7.23GmailMissing PTR record, or the forward lookup does not match the sending IP
4.7.27 and 4.7.30GmailRate limited because SPF or DKIM did not pass
4.7.31 and 4.7.32GmailNo DMARC record, or the From header is not aligned
4.7.28GmailSending quota exceeded, stop for at least ten minutes
5.7.25 to 5.7.30GmailBlocked for PTR, SPF, TLS or DKIM failure
550 5.7.515Outlook.comSending domain does not meet the required authentication level
421 and 451YahooTemporary block: traffic pattern, complaints or spam-like content
553 and 554YahooPermanent: invalid address, authentication failure or a policy block

Google's advice on quota errors is specific. Stop sending for at least ten minutes, then resume from a single connection, and add connections one at a time. If the error does not say which quota you hit, assume all three.

Yahoo's guidance on repeated complaint or volume errors is a 48 hour rule: if the error continues for more than two days after a change, review the outgoing messages and the mailing policy rather than retrying.

What to do after a reputation drop

Reputation damage is slow to repair and fast to worsen, and the instinct to send more to make up the shortfall is exactly wrong. Google describes temporary failures as a throttling tool, and warns that ignoring them is likely to lead to permanent failures.

  1. Stop the affected campaigns completely for a short period, then resume at a lower rate, which is Google's stated best practice for both temp fails and abuse-related permanent failures.
  2. Retry with exponential backoff rather than a fixed interval, increasing the delay between attempts.
  3. Fix what the codes name: authentication, PTR, TLS or formatting first, because those are binary and fast to verify.
  4. Cut the list to the segment most likely to reply, and suppress everything that bounced or never engaged.
  5. Check the domain and the sending IP against public blocklists. Google's stated remedy for an RBL listing is to contact the listing organization and request removal.
  6. Wait, and keep the spam rate down while you do. Google's one published recovery rule is that bulk senders become eligible for mitigation again when the user-reported rate stays below 0.3% for seven consecutive days.

Escalation is possible but conditional. Google accepts delivery issue reports in Postmaster Tools only when the domain is verified, you are the owner, and the domain already meets the sender guidelines. Senders who do not follow the guidelines are not eligible for mitigation at all.

Do not do this

Moving to a fresh domain to escape a bad reputation restarts every clock and keeps every cause. If the list and the message produced complaints on one domain, they will produce them on the next one, faster.

Email deliverability best practices for a B2B sending team

These email deliverability best practices follow directly from what the three mailbox providers publish, ordered by how much they move the outcome for a sales team rather than a newsletter.

  • Publish all three records, whatever your volume. Google recommends SPF, DKIM and DMARC for every sender, not only bulk ones.
  • Keep the From address able to receive replies. Microsoft lists a valid From or Reply-To that reflects the sending domain and accepts replies as a hygiene requirement.
  • Send from a domain that looks like a business. Google recommends authenticating the domain that hosts your public website, and a sending domain with no site behind it has nothing to verify.
  • Keep messages plain and short. Fewer links and no hidden formatting removes the content reasons for a block.
  • Offer a real way out in every stream. Google states that letting people opt out of your messages can improve open rates, click-through rates and sending efficiency.
  • Verify before you send, not after. Addresses that bounce were avoidable before the campaign, and Google asks senders to confirm addresses before subscribing them.
  • Never run a phishing simulation from the sending domain. Google says test phishing campaigns can damage the domain's reputation and get it added to blocklists.
  • Watch affiliates and anyone sending on your behalf. Google notes that association with marketing spam affects your other mail.

The same discipline applies to volume-driven programs. Our email marketing campaigns guide covers the campaign side, where consent and frequency do most of the work.

How to improve email deliverability, step by step

  1. Prove authentication still passes at each provider

    Send to accounts you own at Gmail, Outlook.com and Yahoo, open the raw headers, and confirm SPF, DKIM and DMARC all pass. Fix any failure before you change anything else.

  2. Check the SPF record against the RFC limits

    Count the terms in your record that cause DNS lookups. RFC 7208 caps them at ten and requires a permerror above that, which makes SPF fail for every message you send.

  3. Turn on the feedback the providers offer

    Verify your sending domain in Google Postmaster Tools and enroll your DKIM domain in Yahoo's Complaint Feedback Loop, so complaints arrive as data instead of silence.

  4. Clean the list before the next campaign

    Remove addresses that returned permanent errors, suppress everyone who opted out, and drop contacts you have mailed repeatedly with no reply at all.

  5. Make one-click unsubscribe work, then honor it fast

    Add the List-Unsubscribe and List-Unsubscribe-Post headers described in RFC 8058, keep a visible opt-out in the body, and remove people inside the published windows.

  6. Separate the streams and hold the rate steady

    Send campaigns, replies and notifications from different addresses or domains, keep the daily rate consistent, and avoid bursts after a quiet week.

  7. Read the SMTP codes every week

    Treat 4xx responses as throttling and slow down, treat 5xx responses as a list or policy problem, and record which provider returned what.

  8. Review the numbers monthly and change one thing

    Compare spam rate, bounces, replies and reputation against last month, change one variable at a time, and write down what you changed.

What to track, and what each number tells you

MetricWhat it tells you
Authentication pass rateWhether a tool or DNS change broke SPF, DKIM or DMARC
Spam rate in Postmaster ToolsHow close you are to the 0.3% ceiling and the 0.1% target
Domain reputation ratingThe trend, not the day, and whether it is recovering
Permanent bounce rateWhether the list source is producing valid addresses
Delivery errors by reasonWhich specific requirement or reputation issue is biting
Unsubscribe processing timeWhether you are inside the 48 hour and two day windows
Reply rate per segmentThe only number that proves people wanted the message
CompareThis month against last month, one change at a time

Open rate is missing on purpose. Google states plainly that it does not track open rates, cannot verify third party open reporting, and that a low open rate is not necessarily an accurate indicator of a deliverability problem.

The email deliverability tool categories, without a ranking

This page does not rank vendors or quote their pricing. These are the categories an email deliverability routine uses.

  • Provider dashboards: Google Postmaster Tools, Yahoo Sender Hub and the Outlook.com postmaster services, all free and all first-party.
  • DNS and record checkers: anything that resolves your SPF, DKIM, DMARC, PTR and MX records the way a receiver would.
  • DMARC report processors: aggregate report parsers that turn daily XML into a list of sources sending as your domain.
  • Seed and placement testing: your own accounts at each provider, read by a person, plus any seed list tool you trust.
  • Verification and enrichment: address validation before the send, which overlaps with lead enrichment for outbound lists.
  • Blocklist monitoring: periodic checks of the sending domain and the sending IP against public lists.

Consent, opt-out and the legal floor

Sales email and marketing email are both commercial email. In the United States the CAN-SPAM Act applies to any email whose primary purpose is commercial advertising or promotion, and the Federal Trade Commission's compliance guide states the rules plainly.

  • Accurate headers and subject lines. Sender information may not be false or misleading, and the subject must reflect the content.
  • A valid physical postal address. The message must include one.
  • A working opt-out. The mechanism must be able to process requests for at least 30 days after the message was sent.
  • Ten business days. Opt-out requests must be honored within that window, and you may not charge a fee or require more than an email address.
  • Per message penalties. The FTC states that each separate email in violation is subject to penalties of up to $53,088.

Yahoo points senders to the same act regardless of where they are sending from. Other jurisdictions set a higher consent bar than CAN-SPAM does, so treat this as the floor rather than the standard.

Common email deliverability mistakes

  • Reading the delivery rate in a sending tool as proof of inbox placement.
  • Treating email deliverability as a setup task that was finished last year.
  • Adding a new sending tool to the SPF record without recounting DNS lookups.
  • Publishing DMARC at p=none and never reading a single aggregate report.
  • Sending the week's volume on Monday morning after a quiet week.
  • Running campaigns, replies and notifications from the same address.
  • Retrying 5xx bounces instead of suppressing the address permanently.
  • Treating an unsubscribe as a lost contact and delaying the removal.
  • Buying a list, then blaming the message when complaints arrive.
  • Responding to a reputation drop by sending more, or by buying a new domain.
  • Judging a change after two days, when the compliance dashboard can take seven.

The email that lowers complaints instead of raising them

When a segment of subscribers has stopped replying, the safest next email is the one that offers to stop. It reduces the pool of people likely to report you, and it produces a routing answer often enough to be worth sending. This example was written for this page.

Permission check to a segment that stopped replying
Subject: Should I stop emailing you about {{topic}}?

Hi {{firstName}},

I have written to you a few times about {{topic}} and heard nothing back, which usually means one of two things: wrong person, or wrong time.

If it is the wrong person, who owns {{area}} at {{company}} now?

If it is the wrong time, reply with "later" and I will close the thread and stop sending.

No reply is fine too. I will take you off my list this week either way.

{{senderName}}
Backfires when

The contact never opted in and never engaged, and this email is the fourth unwanted message rather than the last one. Then it raises complaints instead of lowering them.

Send it once, to people you actually contacted before, and then keep the promise in the last line.

Frequently asked questions

How do you improve email deliverability?

Keep SPF, DKIM and DMARC passing on every message, send only to people who expect you, keep the spam complaint rate below the published thresholds, remove bounces and opt-outs quickly, hold volume steady, and read Postmaster Tools and your SMTP codes every month.

What are email deliverability best practices for a B2B sales team?

Authenticate every stream, separate campaign mail from replies and notifications, keep lists small and researched, write plain text with few links, offer a real way out, honor it fast, and review spam rate, bounces and reputation on a schedule.

What is a good spam complaint rate?

Google's sender guidelines say keep the rate reported in Postmaster Tools below 0.3%, and the FAQ says keep it below 0.1% and never let it reach 0.3%. Yahoo publishes the same 0.3% ceiling for bulk senders.

Do I need SPF, DKIM and DMARC for cold email?

Google and Yahoo require SPF or DKIM from every sender and all three from bulk senders. Microsoft requires SPF, DKIM and DMARC from domains sending more than 5,000 messages a day to Outlook.com. Publish all three whatever your volume.

What DMARC policy should a B2B sender use?

RFC 9989, which replaced RFC 7489 in May 2026, defines none, quarantine and reject. Google, Yahoo and Microsoft all accept p=none as the minimum. Microsoft advises moving gradually from none to quarantine to reject once your legitimate sources are aligned, to avoid losing real mail.

Why does my SPF record fail with a permerror?

RFC 7208 limits the terms that trigger DNS lookups, include, a, mx, ptr, exists and redirect, to ten. Above that, implementations must return permerror, so SPF fails for every message. Each extra vendor include adds lookups.

What is sender reputation and how is it measured?

It is the rolling judgment a provider makes about your domain and your sending IP. Google Postmaster Tools shows it as Bad, Low, Medium or High, based on spam history, authentication and compliance with the sender guidelines.

How do I check my sender reputation?

Verify your DKIM or SPF domain in Google Postmaster Tools and read the reputation, spam rate, authentication and delivery error dashboards. Google withholds data on low volume days to protect user privacy, so small senders may see empty charts.

How often should I clean my email list?

Microsoft's guidance for high volume senders is to remove inactive or invalid addresses regularly, monthly or quarterly. Remove any address that returned a permanent error immediately, since Yahoo treats repeated unknown recipients as a sending problem.

Does email content affect deliverability?

Yes. Google's guidelines require accurate headers and display names, ban hidden content in HTML or CSS, ask that links be visible and understandable, and warn against mixing promotional content into transactional mail.

How long does it take to recover after a reputation drop?

Google publishes one concrete rule: bulk senders become eligible for mitigation again when the user-reported spam rate stays below 0.3% for seven consecutive days. Compliance dashboard changes can also take up to seven days to appear.

What should I do when emails start bouncing or deferring?

Slow down. Google describes temporary failures as a throttling tool and recommends stopping completely for a short period, then resuming at a lower rate with exponential backoff. Permanent failures mean fixing the list or the policy problem first.

Is a dedicated IP better for email deliverability?

It depends on volume and consistency. Google notes that the reputation of a shared IP is affected by everyone using it, and that IP quotas are shared, while domain quotas follow your domain. Yahoo advises separating mail types by IP or DKIM domain.

Does email warm up fix deliverability problems?

No. Warm up prepares a new domain before the first campaign. Ongoing deliverability depends on authentication, list quality, complaints and consistency, and none of those improve because a tool exchanges mail on your behalf.

Sources and reading
  1. Google, Email sender guidelines, for the authentication, PTR, TLS, RFC 5322 and spam rate requirements, the display name and formatting rules, and the guidance on volume increases and 4.7.28, checked Sep 23, 2026.
  2. Google, Email sender guidelines FAQ, for the 5,000 message bulk threshold, the 0.1% and 0.3% spam rate wording, the seven consecutive day mitigation rule, the enforcement table and the error codes, checked Sep 23, 2026.
  3. Google, Postmaster Tools dashboards, for the dashboard list, the compliance states, the reputation rating definitions and the delivery error actions, checked Sep 23, 2026.
  4. Google, Set up Postmaster Tools, for domain verification and the low volume data limitation, checked Sep 23, 2026.
  5. Google, Report delivery issues in Postmaster Tools, for who may file a delivery issue report, checked Sep 23, 2026.
  6. Yahoo, Sender Requirements and Recommendations, for authentication, the 0.3% spam rate, the two day unsubscribe window, PTR records and stream separation, checked Sep 23, 2026.
  7. Yahoo, Sender FAQs, for the bulk sender definition, the Complaint Feedback Loop and the unsubscribe answers, checked Sep 23, 2026.
  8. Yahoo, SMTP Error Codes, for the 4xx and 5xx behavior, complaint and unknown recipient errors and the 48 hour guidance, checked Sep 23, 2026.
  9. Microsoft, Strengthening Email Ecosystem: Outlook's New Requirements for High Volume Senders, for the Outlook.com requirements, the 550 5.7.515 rejection, the SPF lookup answer and the hygiene recommendations, checked Sep 23, 2026.
  10. Microsoft, Email authentication in Microsoft 365, for how forwarding breaks SPF, why DKIM survives it and what ARC does, checked Sep 23, 2026.
  11. IETF, RFC 7208, Sender Policy Framework, for the ten DNS lookup limit, permerror and the void lookup limit, checked Sep 23, 2026.
  12. IETF, RFC 6376, DomainKeys Identified Mail, for what a DKIM signature asserts and the minimum key length, checked Sep 23, 2026.
  13. IETF, RFC 9989, DMARC, for its May 2026 replacement of RFC 7489, the policy values, alignment, the rua tag and monitoring mode, the removal of the pct tag, the t tag and the note that a DMARC pass does not guarantee inbox delivery, checked Oct 1, 2026.
  14. IETF, RFC 8058, one-click unsubscribe, for the header pair, the HTTPS requirement and the DKIM coverage rule, checked Sep 23, 2026.
  15. IETF, RFC 5321, SMTP, for the meaning of 4yz and 5yz reply codes, checked Sep 23, 2026.
  16. Federal Trade Commission, CAN-SPAM Act: A Compliance Guide for Business, for the opt-out windows, the postal address rule and the per message penalty, checked Sep 23, 2026.
  17. Microsoft also runs Outlook.com postmaster services, Smart Network Data Services and the Junk Email Reporting Program. That site blocked both curl and automated fetching on the day this page was checked, so nothing on this page is sourced from it.
  18. Jeluvi entries this guide builds on: email warm up, cold email, MX records, sales cadence.
  19. The template and the review routine were written for this page. No inbox placement, open rate or reply rate figures are quoted.
Take the sequence with you

The 10-day cadence, five templates, one email.

Five touches across email, LinkedIn and phone, five templates with placeholders marked, and the first-30-days checklist. One email.

Build a LinkedIn or outreach tool? Jeluvi is read by the people who use them. See how partners appear on Jeluvi.