Deliverability

Email deliverability: how to reach the inbox

Getting an email accepted is the easy part. Getting it into the inbox depends on five things you control: authentication, list quality, engagement, content and your sending setup. This guide covers each one, the rules Gmail, Yahoo and Microsoft enforce, and how to monitor the result.

Updated October 9, 2026 · 14 min read

Email deliverability: accepted mail can land in the inbox or the spam folder, and the five levers you control

Email deliverability is the share of your email that reaches the inbox, as opposed to bouncing or landing in spam. It is decided by the receiving mailbox provider, message by message, based on who you are (authentication), who you send to (list quality), how those people react (engagement), what you send (content) and how you send it (infrastructure). You control all five.

Gmail, Yahoo and Microsoft have turned part of this into hard rules: since 2024 and 2025, high-volume senders that skip authentication get their mail filtered or rejected, and Gmail and Yahoo also require one-click unsubscribe in bulk marketing mail. The sections below go lever by lever, then cover the provider rules, monitoring and testing, and end with a checklist you can work through for an email deliverability audit.

Deliverability vs. delivery rate

The two terms sound alike but measure different things:

Delivery rateDeliverability (inbox placement)
QuestionDid the receiving server accept the message?Did the message reach the inbox?
How it failsBounces: the server answers with a 4xx or 5xx codeThe server accepted the message and filed it as spam
Who reports itYour email service, from the SMTP repliesNobody directly: you infer it from opens, clicks and provider dashboards
Formula(sent − bounced) ÷ sentNot measurable from the sender’s side alone

A 99% delivery rate can hide a deliverability problem: the receiving server said 250 OK and then filed the message as spam. That is why bounce reports alone don’t tell you whether a campaign worked. Watch opens and clicks per mailbox provider (a sudden drop at one provider points to filtering there) and use the provider dashboards described under monitoring.

There is no published industry standard for a “good” inbox rate. What the big providers do publish is a spam complaint threshold (Gmail and Yahoo: below 0.3%) and their sender requirements, so those are the numbers to hold yourself to.

How to improve email deliverability: the five levers

LeverWhat receivers look atWhere to start
AuthenticationSPF, DKIM and DMARC pass and align with the From domainAuthentication checklist
List qualityUnknown recipients, bounces, spam trapsList quality
EngagementSpam complaints, opens, replies, deletions without readingSend only to people who asked; remove long-inactive contacts
ContentLinks, formatting, spam-filter rules, a working unsubscribeTest before you send
InfrastructureReverse DNS, TLS, IP and domain reputation, volume patternsValid PTR record, consistent volume, separate streams

Authentication proves the mail is really from your domain. Without it, receivers can’t tell your mail from forgeries or tie a reputation to your domain, and Gmail, Yahoo and Outlook.com now require it from bulk senders.

List quality is the lever most often left to chance. Every message to an address that doesn’t exist produces a bounce, and providers expect you to act on them: Yahoo asks senders to monitor bounces and remove invalid addresses promptly, and Microsoft’s Outlook.com policy says not to retransmit to a recipient after a permanent (5xx) failure. Old lists also contain recycled spam traps.

Engagement is what recipients do with your mail: open, reply, ignore, or report it as spam. The one engagement number you can see directly is the spam complaint rate in Google Postmaster Tools. Yahoo’s sender guidance is blunt about the basics: send only to users who requested mail, use opt-in confirmation, and don’t buy lists (Yahoo Sender Hub best practices, checked October 9, 2026).

Content is what a filter can read in the message itself: headers, links, formatting and wording. Open-source filters such as SpamAssassin score each message against a large rule set, and the same problems hurt with the big providers’ own filters. A missing or broken unsubscribe link is also a content problem, and for bulk senders a rule violation.

Infrastructure covers the plumbing: a sending IP with a valid PTR record (reverse DNS) that matches its forward DNS, TLS on the connection, and steady volumes. Gmail and Yahoo both require valid forward and reverse DNS for sending IPs. Yahoo also asks senders not to send bulk or marketing mail from the IPs used for user, transactional or alert mail.

Authentication checklist: SPF, DKIM, DMARC, BIMI

RecordWhat it provesLearnCheckCreate
SPFThe sending server is allowed to send for the domain in the envelope senderSPF recordSPF checkerSPF record generator
DKIMThe message was signed by the domain and not changed in transitDKIM recordDKIM checkerDKIM generator
DMARCSPF or DKIM passes for the domain in the From header, and what receivers should do if notWhat is a DMARC recordDMARC checkerDMARC generator
BIMIShows your logo in supporting inboxesBIMI Group––

Work through them in that order:

  1. SPF: one TXT record on each domain used as the envelope sender (Return-Path), listing every service that sends with it. Stay within the 10 DNS lookups SPF allows.
  2. DKIM: turn on domain authentication at every email service you use (newsletter tool, CRM, help desk, your own app). Each one publishes its own selector under _domainkey. Google asks for keys of at least 1,024 bits and recommends 2,048 (Gmail sender guidelines).
  3. DMARC: start with a monitoring policy and a report address, read the reports for a few weeks, then move to quarantine and reject once every legitimate source passes:
_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
  1. Alignment: DMARC passes only when the domain that passes SPF or DKIM matches the domain in the From header. A newsletter tool that signs with its own domain passes DKIM but fails alignment, so set up its custom-domain DKIM.
  2. BIMI (optional): a logo next to your messages in supporting mailbox providers. BIMI does not change delivery; it requires DMARC at enforcement (p=quarantine or p=reject), and some providers, such as Gmail and Apple, also require a certificate (VMC or CMC) proving your rights to the logo, according to the BIMI Group.

List quality: verification, bounces and spam traps

Most deliverability problems that look mysterious start with the list. Four habits keep it clean:

To check a single address by hand, use the email validator; how to check if an email exists shows what happens during the check.

Three kinds of address need separate handling:

Gmail, Yahoo and Microsoft bulk-sender rules

The three largest consumer mailbox providers now publish requirements for senders above a volume threshold. Below is a summary, checked against each provider’s own page on October 9, 2026. The Gmail and Yahoo sender requirements guide has the full checklist with fixes.

GmailYahooOutlook.com (Microsoft)
In force sinceFebruary 1, 2024February 2024May 5, 2025
Who countsClose to 5,000 or more messages a day to personal Gmail accounts; once reached, the status is permanentBulk senders; no exact number publishedDomains sending more than 5,000 emails a day to Outlook.com accounts
AuthenticationSPF and DKIM, DMARC at least p=none, From domain aligned with SPF or DKIMSPF and DKIM, DMARC at least p=none that passes, relaxed alignment acceptedSPF, DKIM and DMARC (at least p=none, aligned with SPF or DKIM)
UnsubscribeOne-click (RFC 8058) for marketing and subscribed mail, plus a visible link; honor within 48 hoursOne-click List-Unsubscribe plus a visible link; honor within 2 daysA clearly documented, easy-to-use unsubscribe mechanism
Spam complaintsBelow 0.3%, ideally below 0.1%Below 0.3%Not specified
Also requiredValid forward and reverse DNS, TLS, RFC 5322 formattingValid forward and reverse DNS, RFC 5321 and 5322 complianceValid reverse DNS
If you failTemporary or permanent rejections, or spam placementNot specified; enforcement rolled out gradually from February 2024Junk folder, then possibly rejection

What each provider adds:

If you send less than these thresholds, the rules for all senders still apply at Gmail and Yahoo: SPF or DKIM, valid reverse DNS, a spam rate below 0.3%, and properly formatted messages. In practice, set up all of it regardless of volume; it costs a few DNS records.

Monitoring: Postmaster Tools, SNDS and blocklists

You can’t see inbox placement directly, but each large provider shows you part of the picture.

Google Postmaster Tools reports on mail sent to personal Gmail accounts (@gmail.com and @googlemail.com) once you verify your domain with a DNS record. Its dashboards cover spam rate, message authentication and delivery errors; the newer interface adds a Compliance dashboard that tracks the sender requirements. Google says it is retiring the old Domain and IP Reputation dashboards, and that days with too little mail show no data (Postmaster Tools help, interface changes). The spam rate there is the number Gmail’s 0.1% and 0.3% thresholds refer to.

Microsoft SNDS (Smart Network Data Services) gives the owners of sending IPs data about those IPs at Outlook.com, and includes the Junk Email Reporting Program, which reports messages users mark as junk. You request access for the IPs you are responsible for and have to re-attest ownership: network access expires 10 months after approval (SNDS). It is useful if you send from your own IPs; on a shared IP at an email service, ask the service what it monitors and how it reports problems to you.

Yahoo’s Complaint Feedback Loop sends you reports of messages Yahoo users marked as spam, per DKIM domain. Yahoo expects an active one for all your DKIM domains.

Blocklists (DNSBLs) are lists of IP addresses or domains that receiving servers query before accepting mail. The Spamhaus Blocklist (SBL), for example, lists IPs it observes sending spam, and receivers using it refuse their mail. Which lists matter for you depends on which ones your recipients’ servers use, so treat a listing as a signal to investigate, not as an automatic catastrophe. To check:

Your own bounce logs are the cheapest monitor of all. A rising share of 5.1.1 “user unknown” bounces means list decay; a rising share of 5.7.x policy blocks means a reputation or authentication problem. The SMTP error codes reference explains each code, and Mail Delivery Subsystem, MAILER-DAEMON and Delivery Status Notification (Failure) show how to read the bounce messages themselves.

Test before you send

A test shows problems before your recipients’ filters do:

  1. Send the real campaign to the email spam checker. It returns the SpamAssassin score and checks SPF, DKIM, DMARC, reverse DNS, blocklists and the List-Unsubscribe header for the message as it was actually sent.
  2. Check a received message’s headers with the email header analyzer to see the Authentication-Results a real mailbox provider recorded and every server the message passed through.
  3. Verify the list (or at least the segment you’re about to mail) if it hasn’t been mailed recently.
  4. Send to a small segment first when you change something big: a new domain, a new email service, a list you haven’t mailed in months. Check bounces and complaints before sending the rest.

No test guarantees inbox placement, because the receiver also weighs your reputation and how recipients react. But a test catches the causes that are entirely in your hands.

Cold email deliverability

Outreach to people who haven’t signed up plays by the same rules with less margin: there’s no prior engagement to build on, every complaint counts against a small volume, and business lists contain many catch-all domains and role addresses. What helps:

Email deliverability checklist

Use this as an email deliverability audit, top to bottom. Where a free tool can check an item, it’s linked.

Authentication

Infrastructure

List

Messages

Monitoring

Sources

Checked October 9, 2026: Gmail email sender guidelines and FAQ; Yahoo Sender Hub best practices; Outlook.com policies, practices and guidelines; Google Postmaster Tools help; Microsoft SNDS; Spamhaus Blocklist (SBL); BIMI Group FAQ; M3AAWG: Help! I Hit a Spam Trap!.

Stop bounces before they happen

Most hard bounces come from addresses that don't exist. An email verification asks the receiving server about the mailbox without sending anything, so you can remove bad addresses before your next send.

Frequently asked questions

What is email deliverability?

Email deliverability is the ability of your email to reach the recipient's inbox rather than bounce or land in the spam folder. It depends on your domain's authentication (SPF, DKIM, DMARC), the quality of your list, how recipients engage with your mail, your content and your sending infrastructure.

How do I improve email deliverability?

Authenticate your domain with SPF, DKIM and DMARC; send only to people who opted in; verify addresses at sign-up and before campaigns; remove hard bounces and long-inactive contacts; make unsubscribing easy; and keep your spam complaint rate below 0.1% in Google Postmaster Tools. Then test each campaign before you send it.

What is a good deliverability rate?

Mailbox providers don't publish a target inbox rate, and your email service can only report what was accepted, not where it landed. Track the numbers you can measure: hard bounces, the spam rate in Google Postmaster Tools (below 0.1%, never 0.3% or more, per Google), and opens and clicks by mailbox provider over time.

Why are my emails going to spam?

The usual causes are missing or failing authentication (SPF, DKIM, DMARC), a high complaint rate, sending to old or bought lists with many invalid addresses or spam traps, a listed sending IP, or content that looks like spam. Send a test to the email spam checker to see which applies to you.

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Keep reading

Start using our email validation software today!

Get 100 validations per month for free