An email platform can report a successful send while the commercial message never reaches a useful inbox position.

The receiving server may accept it and place it in spam. It may defer or reject it. It may arrive in a category that the recipient rarely reviews. It may reach a valid inbox but be ignored because the person did not expect or value it.

That is why deliverability is not an isolated technical percentage.

Deliverability is the organisation’s ability to send legitimate, expected email through trusted infrastructure in a way that mailbox providers accept and recipients continue to value.

Marketing shapes content and cadence. IT or DNS owners shape authentication. Data teams shape sources and suppression. Privacy and legal owners shape permission. Customer service shapes complaints. Leadership shapes volume pressure and incentives.

The short answer

Email deliverability depends on seven connected layers:

  1. Permission and recipient expectations
  2. List acquisition and hygiene
  3. Sender identity and authentication
  4. Infrastructure and routing
  5. Sending volume, consistency and segmentation
  6. Message content, links and user experience
  7. Recipient feedback and reputation

Authentication is essential, but it does not create permission or guarantee placement. Attractive design cannot repair a purchased list. A clean list cannot compensate for a spoofable domain. Every layer needs an owner.

Seven-layer email deliverability system from permission and authentication through recipient response.

Deliverability depends on identity, practice, infrastructure and recipient response.

Sent, delivered, placed and engaged are different

Sent

The platform attempted to send the message.

Delivered

The receiving server accepted it rather than returning a tracked bounce. "Delivered" normally does not prove primary-inbox placement or human attention.

Placed

The mailbox provider classified the accepted message into an inbox, category, junk folder or another destination. Placement can vary by recipient and provider.

Engaged

The person performed a meaningful action such as reading, clicking, replying, completing a service task or purchasing. Open tracking is an imperfect proxy and increasingly affected by privacy features.

Report each layer accurately. A 98 per cent delivery rate, for example, would still say nothing on its own about inbox placement, consent, click quality or revenue. This article intentionally avoids a benchmark because suitability depends on the programme and measurement method.

Sender identity: SPF, DKIM and DMARC

Authentication allows receiving systems to evaluate whether messages are authorised for the domain they claim to represent.

SPF

Sender Policy Framework publishes which servers are authorised to send for a domain used in the message’s envelope path. Records must include all legitimate senders without exceeding technical limits.

DKIM

DomainKeys Identified Mail adds a cryptographic signature. The receiving server can verify that an authorised domain signed the message and that signed parts were not altered in transit.

DMARC

Domain-based Message Authentication, Reporting and Conformance connects domain alignment with a policy and reporting. It helps the domain owner monitor legitimate and unauthorised use and instruct receiving systems how to treat messages that fail aligned authentication.

Authentication records should be designed by a competent owner. Common risks include:

  • A new email provider is not included correctly
  • Several SPF records are published when one valid record is required
  • DKIM is not enabled for a sending domain
  • The visible From domain does not align as required
  • DMARC is moved to an enforcement policy without understanding all legitimate senders
  • Old platforms remain authorised after exit
  • Transactional, corporate and marketing streams share unclear ownership

Google’s current email sender guidelines require all senders to personal Gmail accounts to use SPF or DKIM, valid forward and reverse DNS and TLS, among other requirements. Senders of more than 5,000 messages per day to personal Gmail accounts must use SPF, DKIM and DMARC, meet alignment requirements and support one-click unsubscribe for marketing and subscribed messages.

Meeting these requirements reduces avoidable rejection risk. Google expressly says that it cannot guarantee messages sent by an email provider will pass Gmail’s spam filters.

Permission and expectations are reputation controls

People are less likely to complain when they asked for the message, recognise the sender and receive the expected value and frequency.

High-risk acquisition practices include:

  • Purchasing or renting email addresses
  • Scraping public addresses
  • Adding one-off enquirers or purchasers without establishing consent
  • Hiding marketing permission in unrelated terms
  • Importing old lists with uncertain sources
  • Combining brands or countries without checking scope
  • Continuing after unsubscribe or complaint

Google advises senders not to purchase addresses or send to people who did not sign up. ACMA states that Australian commercial electronic messages generally require consent, sender identification and an unsubscribe facility. Both legal compliance and provider reputation matter; one does not replace the other.

Set expectations at collection. Tell people what they will receive, from whom and how often where practical. Keep source, wording, time and scope records.

List quality is more than removing hard bounces

An address can be technically valid but commercially harmful if the owner did not consent, has no relationship with the brand or has been inactive for a long period.

Maintain processes for:

  • Hard-bounce suppression
  • Repeated soft-bounce and deferral review
  • Complaint suppression
  • Unsubscribe propagation across campaigns and flows
  • Duplicate and malformed address handling
  • Role or disposable address policy where relevant
  • Inactivity and sunset rules suited to the programme
  • Consent-source auditing
  • Removing invalid test and internal records

Do not use an open event as the only engagement measure. Apple Mail Privacy Protection can prevent senders from seeing whether a recipient opened the message. Google states that it does not track open rates and cannot verify third-party open-rate accuracy.

Clicks, replies, purchases, service actions and recent customer activity can provide stronger evidence, but automated link checking and other system behaviour can also affect reporting. Use several signals.

Sending patterns can create risk

Mailbox providers observe sending behaviour over time.

Risk can increase when the organisation:

  • Moves from small sends to a very large audience without a history
  • Sends in irregular bursts
  • Reactivates an old database all at once
  • Moves to new domains or infrastructure without a controlled transition
  • Mixes promotional and transactional content
  • Sends every message to the full list regardless of relevance
  • Continues during high complaints or deferrals

Google advises large-volume senders to increase volume slowly, begin with engaged users, send at a consistent rate and monitor responses, spam rate and reputation. It also warns that sudden volume spikes can cause rate limiting or reputation drops.

Warming is not a ritual that overrides recipient behaviour. If the underlying list is poor or permission is unclear, gradually sending to it does not make it safe.

Content and links influence trust

Mailbox systems and recipients evaluate the complete message.

Check:

  • A clear and consistent sender name
  • Accurate From, subject and message information
  • A subject that does not imitate a reply or create a deceptive impression
  • Balanced, accessible HTML and a useful plain-text alternative where the platform supports it
  • Links that point to reputable, secure and expected destinations
  • No hidden content or manipulative formatting
  • A visible unsubscribe route
  • Mobile readability and image alternatives
  • Correct brand, address and contact information

Google’s guidelines say headers and content should be accurate and not misleading. Australian Consumer Law also prohibits false or misleading claims. Deliverability tactics should never weaken the truthfulness of the communication.

Avoid folklore such as one forbidden word automatically causing spam placement. Context, sender reputation, permission, formatting, links and recipient response interact.

Unsubscribe is a safety valve, not a failure

If recipients cannot leave easily, some will complain or ignore every future message.

ACMA’s current guidance requires Australian commercial messages to include an unsubscribe option that is clear, functional for at least 30 days after sending, does not require extra personal information or login, and is honoured within five working days.

Gmail requires one-click unsubscribe headers plus a visible unsubscribe link for marketing and subscribed messages from senders exceeding its high-volume threshold. One-click is a technical header process; the visible body link remains necessary under Gmail’s requirement.

Keep global and list-level preferences clear. A preference centre can offer choices, but it must not obstruct a complete opt-out.

Diagnose from evidence, not inbox anecdotes

One executive finding a message in junk is useful evidence, but it does not establish the full pattern.

Segment the investigation by:

  • Recipient provider and domain
  • Sending domain, IP and stream
  • Campaign versus automated journey
  • Time and volume change
  • Recipient source and engagement group
  • Message template and linked domains
  • Authentication result
  • SMTP response or bounce class

Use available evidence such as:

  • Platform delivery and bounce logs
  • Gmail Postmaster Tools where data is available
  • DMARC aggregate reports
  • Provider-specific postmaster or complaint tools
  • Seed testing as one diagnostic, not perfect proof
  • Internal test accounts across providers
  • Consent and list-source records
  • DNS and authentication checks
  • Commerce, CRM and website outcomes

Email deliverability diagnosis matrix connecting symptoms with checks, possible causes and evidence.

Different symptoms require different evidence and owners.

A controlled recovery process

1. Stop the harmful behaviour

Pause or reduce the affected stream when continued sending could increase complaints, deferrals or rejection. Preserve essential service communication through the correct, separately governed route.

2. Preserve evidence

Export errors, authentication results, campaign settings, audience source, changes and provider splits before overwriting the configuration.

3. Localise the issue

Determine whether it affects one provider, domain, IP, message stream, template, list source or the whole programme.

4. Correct the root cause

Repair authentication, remove invalid or non-permitted sources, correct content or links, separate streams, fix suppression and update the operating process.

5. Resume with the strongest eligible audience

Begin with recent, clearly eligible and genuinely engaged recipients. Keep volume consistent and monitor responses.

6. Increase only while evidence supports it

Watch complaints, bounces, deferrals, provider-specific outcomes and reputation. A fixed recovery timetable is not credible because severity and provider response vary.

Email deliverability recovery loop from stopping harmful sends through controlled resumption and monitoring.

Protect reputation first, then resume only as evidence supports it.

Assign ownership before an incident

Responsibility Likely owner Required collaborators
Consent and privacy position Client privacy or legal owner Marketing, data, platform provider
DNS and authentication Client IT or nominated technical owner Email provider, agency
Audience source and suppression Marketing or CRM owner Privacy, sales, customer service
Content and template QA Marketing and email delivery team Brand, legal, design, development
Sending plan Marketing owner Sales, operations, email specialist
Monitoring and incident triage Named email programme owner IT, provider, agency
Commercial outcomes Business owner Finance, sales, analytics

Exact accountability should be documented. "The email platform handles it" is not sufficient.

Migration and major-change safeguards

Changing email platforms, domains, dedicated IPs, authentication or volume patterns needs a release plan.

Inventory:

  • Every legitimate sending system
  • Current SPF, DKIM and DMARC state
  • Marketing and transactional streams
  • Suppression and consent records
  • Templates, links and tracking domains
  • Automation journeys
  • Historical engagement and complaint groups
  • DNS access and rollback

Test authentication, suppression, forms, preference updates and transactional messages before cutover. Do not import unsubscribed contacts as active. Monitor provider-specific responses closely after release.

Metrics that belong in an email health view

Use a set rather than one score:

  • Accepted, rejected and deferred messages
  • Hard and soft bounce patterns
  • Complaint and unsubscribe rates
  • Authentication pass and alignment
  • Domain or IP reputation where providers expose it
  • Eligible engaged audience size
  • Click, reply and meaningful action trends
  • Provider-level splits
  • Journey and campaign conflicts
  • Qualified leads, purchases, retention or service outcomes

Interpret metrics with volume and context. Google advises keeping spam rates reported in Postmaster Tools below 0.10 per cent and avoiding 0.30 per cent or higher. That is a Gmail provider threshold and aspiration, not a universal legal or commercial benchmark.

Separate email streams deliberately

Corporate correspondence, password or order messages and marketing campaigns can have different risk, urgency, volume and operating owners. Design the sending architecture so those differences are visible and governable.

Possible controls include distinct sending services, subdomains, From identities, authentication records, suppression logic and monitoring views. The correct design depends on volume, providers, customer experience, technical capability and incident consequence.

Separation is not a way to hide poor acquisition or protect marketing from complaints it has earned. Related domains can still affect trust, and mailbox providers use signals that businesses do not fully control. Every stream needs legitimate recipients, accurate identity, suitable security and responsible sending practice.

Document the purpose and owner of each stream. An account alert should not silently become a promotion. A sales sequence should not bypass the central unsubscribe and suppression policy. A new business unit should not begin sending from a lookalike domain without security, brand and deliverability review.

Apply change control before major sends

Require a deliverability check when the business changes domain, email provider, DNS service, website forms, CRM integration, list source, sending volume, frequency or authentication. The same applies before a large seasonal launch or acquisition-driven list expansion.

The review should confirm identity, permissions, list transfer, suppression, warm-up or ramp plan where relevant, monitoring, escalation and rollback. Preserve the previous configuration and test evidence. A known change point makes later diagnosis far faster than reconstructing the migration after a problem appears.

Common mistakes

  • Assuming delivered means primary inbox
  • Treating SPF alone as complete authentication
  • Buying a list and attempting to "warm" it
  • Mixing transactional and promotional content carelessly
  • Sending to everyone to improve short-term revenue
  • Making unsubscribe difficult to protect list size
  • Using open rate as the only health measure
  • Changing domains or platforms without an inventory and release plan
  • Ignoring one-provider failures because the account average looks acceptable
  • Promising a fixed deliverability recovery period

Maintain an email incident playbook

Define who investigates authentication, provider, list, content and destination-link failures; what evidence is preserved; when sending pauses; and how recovery is tested. Deliverability recovery should not begin with sending more volume.

Related Emote guidance: Email Marketing, Klaviyo Partner and Lifecycle email marketing.

Frequently asked questions

Can an email platform guarantee inbox placement?

No. Providers can supply infrastructure and tools, but recipient mailbox systems evaluate authentication, reputation, content, behaviour and other signals.

Does DMARC improve deliverability?

DMARC supports domain authentication, alignment, reporting and anti-spoofing controls. It is important, but it does not create permission or guarantee placement.

Should a business use a dedicated IP?

It depends on volume, consistency, programme maturity, provider architecture and the ability to manage reputation. A dedicated IP gives more direct responsibility, not automatic quality.

Are open rates still useful?

They can be a directional platform metric with substantial limitations. Apple Mail Privacy Protection and other system behaviour reduce confidence. Use clicks, replies, outcomes and provider evidence as well.

How long does deliverability recovery take?

There is no universal period. It depends on the cause, severity, provider, domain history, corrective action and recipient response.

Should unengaged contacts be deleted?

The correct action may be suppression, retention for a justified non-marketing purpose, deletion or another treatment. Decide from consent, privacy, business, legal and platform requirements rather than one generic rule.

How Emote can help

Deliverability begins long before the campaign is scheduled.

It begins when the organisation explains the relationship, collects an address, configures its domain, chooses its providers, defines suppression and decides whether the next message is genuinely useful.

If your organisation needs an email programme that connects strategy, creative, data, consent, authentication and measurement, book an initial meeting with Emote. Emote can clarify the current position and coordinate with your nominated IT, privacy, legal and platform owners before an appropriate scope is agreed.

Up next: Email marketing beyond newsletters: lifecycle programmes that nurture, retain and reactivate customers

Read More