Technical9 min read

Why Your Emails Land in Spam (and How to Fix It)

The real reasons your emails go to spam, and a step-by-step fix for authentication, reputation, content, and list hygiene.

Farhad, founder of GHL Spark
Farhad · Founder, GHL Spark
Cover illustration — a bright teal grid with a highlighted square on a dark green background, marked GHL Spark, Technical

In short

Emails go to spam for one of five reasons, and they are almost always fixable. The first is authentication — if SPF, DKIM and DMARC are not set up, mailbox providers cannot confirm you are who you claim to be, and Gmail and Yahoo now reject or filter unauthenticated bulk mail outright. The second is sender reputation, built slowly from how recipients react to you. The third is content that trips spam filters. The fourth is a dirty list full of dead and unengaged addresses. The fifth is sending too much, too fast, from a cold domain. Fix authentication first, then reputation, and most inbox problems disappear.

Key takeaways

  • Authentication comes first — without SPF, DKIM and DMARC, Gmail and Yahoo now filter or reject bulk mail no matter how good your content is.
  • Sender reputation is earned from recipient behaviour — opens, replies, deletes and spam complaints — not from anything you can declare about yourself.
  • Content triggers matter less than people think, but a bad text-to-image ratio, spammy phrasing and broken links still push borderline mail over the edge.
  • A dirty list is the fastest way to wreck deliverability — dead addresses, spam traps and unengaged contacts all tell providers your mail is unwanted.
  • New domains and dedicated IPs must be warmed up gradually — a cold domain blasting thousands of emails on day one looks exactly like a spammer.

You wrote a genuinely useful email. You hit send. And it landed in the spam folder, or vanished entirely, and almost nobody opened it. If you are asking why your emails are going to spam, the frustrating truth is that it is rarely about the words you wrote. It is about whether the mailbox provider trusts you.

Here is the short version. Emails go to spam for one of five reasons: your domain is not authenticated, your sender reputation is poor, your content trips filters, your list is dirty, or you are sending too much too fast from a cold domain. Fix them roughly in that order — authentication first, because since 2024 it is the gate you cannot get past — and most of your inbox problems disappear. This guide walks through each one and exactly what to do.

Why do emails go to spam in the first place?

Every message you send is judged in a fraction of a second by the receiving mailbox provider — Gmail, Outlook, Yahoo, Apple Mail. Their filters ask a series of blunt questions. Can we confirm this sender is who they claim to be? Do people who get mail from this sender want it? Does this message look like the millions of spam samples we have seen? Is this domain behaving normally, or suddenly firing off huge volumes?

If enough of those answers come back wrong, your email is quarantined in spam or dropped silently. The filters are not reading your prose for quality. They are running a risk assessment on you as a sender. That reframing matters, because it tells you where to spend your effort — not on rewording the offer, but on the technical and behavioural signals that decide whether you are trusted at all.

The five levers below are, in practice, everything. Get them right and good email reaches the inbox. Get them wrong and even a perfect message gets buried. It also helps to know that deliverability is a moving target — providers tighten their rules every year, and a setup that worked in 2022 may quietly fail today. The upside is that the fixes are durable: once your authentication is in place and your list is clean, you are ahead of the majority of senders who never touch either.

Set up SPF, DKIM and DMARC — authentication comes first

Authentication is the single highest-leverage fix, and it is where you should always start. These three DNS records are how you prove to mailbox providers that you are genuinely allowed to send from your domain. Without them, you look indistinguishable from a spammer forging your address.

SPF (Sender Policy Framework) is a DNS record listing which mail servers may send on behalf of your domain. The receiver checks the sending server against your list; if it is not there, the message fails.

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message. The receiver uses a public key published in your DNS to confirm the message genuinely came from you and was not tampered with in transit.

DMARC (Domain-based Message Authentication, Reporting and Conformance) sits on top of both. It tells receivers what to do when a message fails SPF and DKIM, and it sends you reports on who is sending mail under your name. Start with a policy of p=none to monitor without disrupting delivery, confirm your real mail passes, then tighten to p=quarantine and finally p=reject.

This is no longer optional. In February 2024, Gmail and Yahoo began enforcing hard rules on bulk senders — anyone sending more than 5,000 messages a day. Valid SPF and DKIM, a published DMARC record, a one-click unsubscribe, and a spam-complaint rate under 0.3 percent are now the price of entry. Miss them and your mail is filtered or rejected before content ever enters the picture.

If you only do one thing after reading this, log into your DNS and confirm all three records exist and pass. Most reputable email platforms give you the exact records to paste in. Once they are live, send a test message to yourself and inspect the headers to confirm each check reads "pass."

What is sender reputation, and how do you build it?

Once you are authenticated, providers start scoring you on behaviour. Sender reputation is a running tally of how recipients react to your mail, tracked against both your domain and your sending IP. You cannot declare it or buy it — you earn it, one send at a time.

Positive signals build it up. People open your emails, reply to them, click links, move them out of spam, and add you to their contacts. Negative signals tear it down fast. People delete without opening, ignore you for months, or — worst of all — hit the spam button. A complaint rate above 0.3 percent is enough to get you throttled by Gmail.

The practical way to protect reputation is to mail people who actually want to hear from you, and to stop mailing people who clearly do not. Send relevant content on a predictable schedule. Make the first few emails after signup count, because early engagement teaches providers you are wanted. And watch your metrics — a sudden dip in opens or a rise in complaints is an early warning that your reputation is slipping before it collapses. If you are just getting started, our guide on email marketing for small business covers how to build engaged sending habits from day one.

Which content triggers actually push you to spam?

Content matters less than most people fear, but it is still the tiebreaker on borderline mail. Filters have moved well past simple word-matching, so a single mention of "free" will not doom you. What hurts is stacking signals that, taken together, look promotional and low-trust.

Watch for these:

  • A bad text-to-image ratio. An email that is one giant image with almost no live text is a classic spam pattern, because it hides words the filter cannot read. Keep real, selectable text in the message and add alt text to every image.
  • Spammy phrasing piled on. ALL CAPS subject lines, rows of exclamation marks, and phrases like "act now," "risk-free" and "you have been selected" add up quickly.
  • Broken, cloaked or mismatched links. A link whose visible text says one thing while it points somewhere else is a strong spam signal. So are URL shorteners and links to domains with poor reputations.
  • No plain-text version. A well-formed email includes both an HTML and a plain-text part. Missing the plain-text alternative looks sloppy to filters.
  • Misleading subject lines. A subject that does not match the body erodes trust and drives complaints.

The reliable test is simple: write as if you were emailing one real customer, not broadcasting to a crowd. That instinct clears almost every content filter without you memorising a single trigger word.

How does list hygiene affect the spam folder?

A dirty list is one of the fastest ways to wreck deliverability, and it is the reason many senders with perfect authentication still struggle. Every dead address, every spam trap, and every contact who has ignored you for a year sends the same message to providers: this mail is unwanted.

Clean your list on a schedule. Remove hard bounces immediately — an address that does not exist should never be mailed twice. Prune contacts who have not opened or clicked in six to twelve months, or move them to a low-frequency re-engagement track before dropping them. Validate new addresses at the point of signup to catch typos and fakes before they ever enter your list.

And never, ever buy a list. Purchased and scraped lists are seeded with spam traps — addresses planted specifically to catch senders who mail without consent — and hitting even a few can get your domain blacklisted, poisoning delivery for the contacts who genuinely opted in. Grow your list from real opt-ins, even if it grows more slowly. A smaller engaged list outperforms a big cold one every time. If you are choosing a platform, our roundup of the best email marketing software compares the tools that make list cleaning and validation straightforward.

What is domain warm-up, and when do you need it?

If you are sending from a brand-new domain, a new subdomain, or a fresh dedicated IP, you need to warm it up. Warm-up means increasing your sending volume gradually so mailbox providers build trust in you over time instead of seeing a sudden, suspicious flood.

Think about how it looks from the provider's side. A domain with no sending history that suddenly pushes ten thousand emails on its first day is behaving exactly like a spammer who just registered a throwaway domain. Even with flawless authentication, that pattern gets you filtered.

Warm up by starting small and engaged. Send to your most active contacts first — the people most likely to open and reply — because their positive engagement teaches providers your mail is wanted. Increase volume steadily over two to six weeks, roughly doubling every few days while watching your bounce and complaint rates. If either spikes, slow down. A dedicated sending subdomain, kept separate from your main corporate email, also protects your primary domain if a campaign goes wrong.

The email deliverability checklist

Here is everything above condensed into a working checklist. Run down it before any significant send.

FactorWhat to do
SPFPublish a DNS record listing every server allowed to send for your domain; confirm it passes in the headers.
DKIMEnable signing in your platform and publish the public key in DNS; verify the signature passes.
DMARCPublish a record starting at p=none, confirm legitimate mail passes, then tighten to quarantine or reject.
Sending domainUse your own authenticated domain, never a free @gmail.com or @yahoo.com address, for bulk mail.
Sender reputationMail engaged contacts on a predictable schedule; keep spam complaints under 0.3 percent.
ContentBalance text and images, add alt text, avoid caps and spammy phrasing, include a plain-text version.
UnsubscribeAdd a working one-click unsubscribe to every bulk email; make it easy to find.
List hygieneRemove hard bounces immediately; prune unengaged contacts; never buy or scrape a list.
Bounce rateKeep it under two percent; validate addresses at signup.
Warm-upRamp new domains and IPs gradually over two to six weeks, starting with your best contacts.
TestingRun a seed-inbox test and check headers before every major campaign.

What about the tools — do they handle this for you?

Most of the technical burden here is one-time setup plus ongoing discipline, and the platform you send from does a lot of the heavy lifting. Dedicated email tools and all-in-one marketing platforms — Mailchimp, ActiveCampaign, and all-in-one systems like GoHighLevel among them — will generate your SPF and DKIM records for you to paste into DNS, handle DMARC alignment, add compliant one-click unsubscribe headers automatically, and surface bounce and complaint metrics so you can act on them. That is one option among several, and the right choice depends on what else you need the platform to do.

What no tool does for you is keep your list clean, write mail people want, or resist the temptation to blast a cold domain. Those stay your job. The platform removes the technical friction; the trust is still something you earn.

If email and SMS deliverability is central to how you serve clients, specialist email & SMS marketing agencies build this discipline into their delivery. For more on the wider stack, our hub on web, email & ecommerce collects the related guides in one place.

Fixing the spam problem, in order

You do not have to do everything at once. Work the list in priority order and you will see results fast.

Start with authentication — SPF, DKIM and DMARC — because in 2026 it is the non-negotiable gate. Then protect your sender reputation by mailing only people who want your email and watching your complaint rate. Clean your list so dead and unengaged addresses stop dragging you down. Tidy up content so borderline messages tip the right way. And if your domain is new, warm it up patiently instead of blasting from cold.

Do those five things and the spam folder stops being where your best work goes to die. If you would rather hand the whole thing to a team that does deliverability for a living, take a look at our pricing or book a call and we will get your email landing where it belongs.

Frequently asked questions

What is SPF, and do I really need it?
SPF stands for Sender Policy Framework. It is a DNS record that lists which mail servers are allowed to send email on behalf of your domain. When a mailbox provider receives your message, it checks the sending server against your SPF record. If the server is not listed, the message fails SPF and looks like a forgery. You absolutely need it. Missing or broken SPF is one of the most common reasons legitimate business email lands in spam, and it is a five-minute fix through your domain's DNS settings.
What is DKIM, and how is it different from SPF?
DKIM stands for DomainKeys Identified Mail. Where SPF checks which server sent the message, DKIM cryptographically signs the message itself so the receiver can confirm it was not altered in transit and genuinely came from your domain. You publish a public key in DNS, and your sending platform signs each message with the matching private key. SPF and DKIM are complementary, not alternatives — you want both. Together they prove both the sending server and the message content are legitimate.
What is DMARC, and what should my policy be set to?
DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It ties SPF and DKIM together and tells receiving servers what to do when a message fails both — do nothing, quarantine it, or reject it. Start with a monitoring policy of p=none so you can collect reports without affecting delivery, confirm your legitimate mail is passing, then tighten to p=quarantine and eventually p=reject. Gmail and Yahoo now require at least a published DMARC record for bulk senders, so p=none is the minimum, not optional.
Why does Gmail keep flagging my emails specifically?
Gmail leans heavily on engagement and authentication. If your messages are unauthenticated, or if Gmail users routinely ignore, delete or report your mail, Gmail learns that your email is unwanted and routes it to spam or Promotions. Since February 2024, Gmail also enforces hard requirements on bulk senders — valid SPF and DKIM, a DMARC record, a one-click unsubscribe, and a spam-complaint rate kept below 0.3 percent. Fail those and Gmail filters you regardless of what you are sending.
Which spam trigger words should I actually avoid?
Modern filters weigh patterns far more than any single word, so no list is a magic bullet. That said, stacking classic promotional phrases still hurts — free, act now, limited time, risk-free, guaranteed, congratulations, you have been selected, and anything about getting rich or losing weight. The bigger risks are ALL CAPS subject lines, excessive exclamation marks, hidden text, and mismatched or cloaked links. Write the way you would to one real person and you will clear the bar without memorising a word list.
Does buying an email list hurt deliverability?
Badly, and often permanently. Purchased and scraped lists are full of spam traps — real addresses planted specifically to catch senders who did not get consent. Hit a few and mailbox providers flag your domain as a spammer, tanking delivery for everyone you mail, including people who genuinely signed up. Bought lists also generate high bounce and complaint rates from the first send. Never buy a list. Grow one from people who opted in, even if it grows more slowly.
What is domain warm-up, and how long does it take?
Warm-up is the practice of gradually increasing your sending volume from a new domain or dedicated IP so mailbox providers build trust incrementally rather than seeing a sudden flood. A brand-new domain blasting ten thousand emails on day one looks identical to a spammer. Start with small volumes to your most engaged contacts, then increase steadily over two to six weeks, watching bounce and complaint rates as you scale. Skipping warm-up is one of the fastest ways to burn a fresh domain's reputation.
Can I send marketing email from a free Gmail or Yahoo address?
Not for anything at scale. Since 2024 you cannot reliably pass DMARC when sending bulk mail from an @gmail.com or @yahoo.com address, because those providers publish strict DMARC policies you are not authorised to send under. Your mail gets rejected or filtered. Send from your own domain — for example [email protected] — which you can authenticate with SPF, DKIM and DMARC. A free address also looks unprofessional and undermines trust with recipients.
What is the right image-to-text ratio for emails?
There is no exact magic number, but an email that is one giant image with almost no live text is a classic spam signal, because it is the oldest trick for hiding words filters cannot read. Aim for a healthy balance — roughly a 60-to-40 split of text to images is a safe rule of thumb — and always include real, selectable text alongside any graphics. Add alt text to every image so the message still makes sense when images are blocked, which many clients do by default.
Do I really need an unsubscribe link in every email?
Yes, and for bulk senders it now needs to be one-click. It is a legal requirement under laws such as CAN-SPAM and GDPR, and as of 2024 Gmail and Yahoo require a functioning one-click unsubscribe header on bulk mail. Beyond compliance, an easy unsubscribe protects your reputation — a reader who cannot find the unsubscribe link will hit the spam button instead, and a spam complaint damages you far more than a quiet opt-out ever could.
How do I test my email deliverability before a big send?
Use a seed-testing or inbox-placement tool that sends your email to a spread of addresses across Gmail, Outlook, Yahoo and others, then reports where each landed. Free tools like Mail-Tester score your message and flag authentication, content and reputation problems before you hit send. Also check that SPF, DKIM and DMARC pass by inspecting the headers of a test email you send to yourself. Test after any change to your domain, platform or template.
What bounce rate is too high, and what causes bounces?
Keep your bounce rate under roughly two percent — above that, mailbox providers read it as a sign you are mailing a stale or purchased list, and your reputation suffers. Hard bounces come from invalid or non-existent addresses and should be removed immediately and permanently. Soft bounces are temporary — a full mailbox or a server that is briefly down. Validate new addresses at signup, remove hard bounces after every campaign, and never keep mailing an address that has bounced hard.

About the author

Farhad, founder of GHL Spark

Farhad

Founder, GHL Spark

Farhad is the founder of GHL Spark, where he builds and white-labels GoHighLevel SaaS platforms for agencies and SaaS operators. He writes about the parts of GoHighLevel that actually break in production — A2P registration, onboarding, support load and automation.

More from Farhad

Want this handled for you?

We set up, configure and white-label your GoHighLevel SaaS — so you can sell it instead of building it.

Fixed quote · No lock-in · Launch-ready in ~7 days