Introduction
Successfully sending to the provider does not mean the email has entered the inbox. Deliverability is a coordination problem between email authentication infrastructure, recipient list quality, email content and reputation accumulated over time.
This article focuses on the most important parts for a large sending system to maintain stable inbox placement.
1. Deliverability is actually determined by what?
Four pillars
| Pillar | Questions to answer |
|---|---|
| Authentication | Is this email really authorized to be sent by a valid domain? |
| Reputation | Does this domain/IP have a good or bad history? |
| List quality | Does the recipient exist, interact, and opt-in? |
| Content quality | Does the content show signs of spam, misleading or violating policy? |
Common misunderstandings
- Correct DKIM does not automatically guarantee access to the inbox.
- Buying dedicated IP does not fix dirty lists.
- Adding too many tracking pixels can be counterproductive.
- New domain but sending old volume from day one will almost certainly be throttling.
2. SPF: who is allowed to send your domain instead?
SPF is a DNS record that declares which mail servers or providers are allowed to send mail to the domain.
Example SPF record
example.com. IN TXT "v=spf1 include:amazonses.com include:sendgrid.net -all"
Meaning
v=spf1: SPF version.include:amazonses.com:allow SES.include:sendgrid.net: enable SendGrid.-all: all other sources fail hard.
Practical note
- Shouldn't be too much
includebecause SPF lookup is limited. - SPF checks envelope sender, not always
From:user sees. - If using multiple ESPs, carefully control alignment with DMARC.
3. DKIM: sign content to prove integrity
DKIM adds a digital signature to the email header. Mail receivers use the public key in DNS to verify that the email content has not been modified along the way.
Example DKIM record
ses2026._domainkey.example.com. IN TXT (
"v=DKIM1; k=rsa; "
"p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw..."
)
Best practices
- Use an explicit selector by provider or by year/quarter to rotate the key.
- Key length must be at least 1024, preferably 2048 bits if the provider supports it.
- Rotate DKIM keys periodically but without interrupting old email verification.
4. DMARC: policy and alignment
DMARC allows the domain owner to declare how to handle SPF/DKIM failed emails, and receive aggregate reports.
Example DMARC record
_dmarc.example.com. IN TXT "v=DMARC1; p=quarantine; pct=100; rua=mailto:[email protected]; ruf=mailto:[email protected]; adkim=s; aspf=s"
Frequently used modes
| Policy | Meaning | When using |
|---|---|---|
p=none | monitor only | initial phase of implementation |
p=quarantine | push failed mail to spam/quarantine | After alignment is stable |
p=reject | absolutely refuse | when the domain is well controlled |
Safe implementation roadmap
- Start with
p=none. - Collect DMARC reports for at least several weeks.
- Handle all valid email sources that are not aligned.
- Increase
quarantinethenreject.
5. Domain/IP warm-up and reputation management
Why is reputation important?
Mailbox providers such as Gmail, Outlook, Yahoo evaluate mail sending behavior over time. They care about:
- Hard bounce rate.
- Complaint rate.
- Rate of engaged opens/clicks.
- Is there a natural increase in sending frequency?
- Rate of sending to inactive addresses for a long time.
Warm-up plan for new domain
| Week | Segments | Volume |
|---|---|---|
| 1 | Users opened mail in the last 7 days | low |
| 2 | Users engaged 30 days | slight increase |
| 3 | Expand to 60-90 days | controlled increase |
| 4+ | The entire list is clean | according to actual metrics |
Shouldn't do it
- Send both transactional and marketing simultaneously from the same new domain/IP.
- Using shared list without clear consent.
- Scale 10 times the volume just because the system has excess capacity.
6. List hygiene and complaint handling
No matter how good the infrastructure is, it cannot save a dirty recipient list.
Address types that should be removed
| Type | Action |
|---|---|
| Hard bounce | suppress now |
| Complained users | suppress permanently or according to policy |
| High-risk role accounts | consider removing |
| Perennial Inactive | put in re-engagement before |
| Disposable emails | block from the beginning |
Internal Suppression list
CREATE TABLE suppression_list (
email TEXT PRIMARY KEY,
reason TEXT NOT NULL,
source TEXT NOT NULL,
created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
expires_at TIMESTAMPTZ
);
Complaint handling flow
- Receive webhook complaint from provider.
- Map back
recipientandmessage_idinternal. - Add recipients to the suppression list.
- Reduce send rate if complaint rate increases by domain/campaign.
- Warn the marketing team if the campaign has poor quality content.
7. Email content and spam signals
Common bad signals
- Subject is too excited like "FREE!!! LIMITED OFFER!!!".
- Heavy HTML, many images but little text.
- Strange domain tracking link, inconsistent brand.
- Missing unsubscribe link.
- From name/domain is not consistent with the brand.
Checklist of healthy content
- Subject is clear, no excessive clickbait.
- Has plain-text fallback.
- Have appropriate address and contact information.
- There is an easily visible unsubscribe link.
- Tracking domains using brand subdomains if possible.
8. Monitoring deliverability
Metrics to track
| Metrics | Reference warning level |
|---|---|
| Hard bounce rate | > 2% |
| Complaint rate | > 0.1% |
| Delivery rate | Strong decrease compared to baseline |
| Open rate | Abnormal drop by domain |
| Spam placement | Continuously increase many campaigns |
Useful tool
- Gmail Postmaster Tools
- Microsoft SNDS
- DMARC aggregate report analyzers
- Provider dashboards of SES/SendGrid/Mailgun
What is BIMI?
BIMI allows the display of brand logos in the inboxes of some mailbox providers, but usually requires good DMARC enforcement and sometimes a brand authentication certificate. It does not replace SPF/DKIM/DMARC but builds on it.
Summary
Deliverability is a long-term game. You cannot fix it with a script or a single DNS record. You need to simultaneously do proper authentication, warm-up carefully, keep the list clean, and monitor reputation signals every day.
Next article: We will build monitoring, metrics and alerting to look at the notification system like a real production system.