Chuyển đến nội dung chính

Lesson 13: Email Deliverability — SPF, DKIM, DMARC

Email authentication with SPF, DKIM, DMARC. IP reputation, domain warm-up, spam score optimization, list hygiene, complaint processing, blacklist monitoring and BIMI.

🏗️ Architecture — Lesson 13 Lesson 13: Email Deliverability — SPF, DKIM, DMARC

Design a Notification System to send millions of Emails

Part 5: Deliverability, Monitoring & Production

xdev.asia

Introduction

Successfully sending to the provider does not mean the email has entered the inbox. Deliverability is a coordination problem between email authentication infrastructure, recipient list quality, email content and reputation accumulated over time.

This article focuses on the most important parts for a large sending system to maintain stable inbox placement.


1. Deliverability is actually determined by what?

Four pillars

PillarQuestions to answer
AuthenticationIs this email really authorized to be sent by a valid domain?
ReputationDoes this domain/IP have a good or bad history?
List qualityDoes the recipient exist, interact, and opt-in?
Content qualityDoes the content show signs of spam, misleading or violating policy?

Common misunderstandings

  • Correct DKIM does not automatically guarantee access to the inbox.
  • Buying dedicated IP does not fix dirty lists.
  • Adding too many tracking pixels can be counterproductive.
  • New domain but sending old volume from day one will almost certainly be throttling.

2. SPF: who is allowed to send your domain instead?

SPF is a DNS record that declares which mail servers or providers are allowed to send mail to the domain.

Example SPF record

example.com. IN TXT "v=spf1 include:amazonses.com include:sendgrid.net -all"

Meaning

  • v=spf1: SPF version.
  • include:amazonses.com:allow SES.
  • include:sendgrid.net: enable SendGrid.
  • -all: all other sources fail hard.

Practical note

  • Shouldn't be too much include because SPF lookup is limited.
  • SPF checks envelope sender, not always From: user sees.
  • If using multiple ESPs, carefully control alignment with DMARC.

3. DKIM: sign content to prove integrity

DKIM adds a digital signature to the email header. Mail receivers use the public key in DNS to verify that the email content has not been modified along the way.

Example DKIM record

ses2026._domainkey.example.com. IN TXT (
  "v=DKIM1; k=rsa; "
  "p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw..."
)

Best practices

  • Use an explicit selector by provider or by year/quarter to rotate the key.
  • Key length must be at least 1024, preferably 2048 bits if the provider supports it.
  • Rotate DKIM keys periodically but without interrupting old email verification.

4. DMARC: policy and alignment

DMARC allows the domain owner to declare how to handle SPF/DKIM failed emails, and receive aggregate reports.

Example DMARC record

_dmarc.example.com. IN TXT "v=DMARC1; p=quarantine; pct=100; rua=mailto:[email protected]; ruf=mailto:[email protected]; adkim=s; aspf=s"

Frequently used modes

PolicyMeaningWhen using
p=nonemonitor onlyinitial phase of implementation
p=quarantinepush failed mail to spam/quarantineAfter alignment is stable
p=rejectabsolutely refusewhen the domain is well controlled

Safe implementation roadmap

  1. Start with p=none.
  2. Collect DMARC reports for at least several weeks.
  3. Handle all valid email sources that are not aligned.
  4. Increase quarantine then reject.

5. Domain/IP warm-up and reputation management

Why is reputation important?

Mailbox providers such as Gmail, Outlook, Yahoo evaluate mail sending behavior over time. They care about:

  • Hard bounce rate.
  • Complaint rate.
  • Rate of engaged opens/clicks.
  • Is there a natural increase in sending frequency?
  • Rate of sending to inactive addresses for a long time.

Warm-up plan for new domain

WeekSegmentsVolume
1Users opened mail in the last 7 dayslow
2Users engaged 30 daysslight increase
3Expand to 60-90 dayscontrolled increase
4+The entire list is cleanaccording to actual metrics

Shouldn't do it

  • Send both transactional and marketing simultaneously from the same new domain/IP.
  • Using shared list without clear consent.
  • Scale 10 times the volume just because the system has excess capacity.

6. List hygiene and complaint handling

No matter how good the infrastructure is, it cannot save a dirty recipient list.

Address types that should be removed

TypeAction
Hard bouncesuppress now
Complained userssuppress permanently or according to policy
High-risk role accountsconsider removing
Perennial Inactiveput in re-engagement before
Disposable emailsblock from the beginning

Internal Suppression list

CREATE TABLE suppression_list (
  email TEXT PRIMARY KEY,
  reason TEXT NOT NULL,
  source TEXT NOT NULL,
  created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
  expires_at TIMESTAMPTZ
);

Complaint handling flow

  1. Receive webhook complaint from provider.
  2. Map back recipient and message_id internal.
  3. Add recipients to the suppression list.
  4. Reduce send rate if complaint rate increases by domain/campaign.
  5. Warn the marketing team if the campaign has poor quality content.

7. Email content and spam signals

Common bad signals

  • Subject is too excited like "FREE!!! LIMITED OFFER!!!".
  • Heavy HTML, many images but little text.
  • Strange domain tracking link, inconsistent brand.
  • Missing unsubscribe link.
  • From name/domain is not consistent with the brand.

Checklist of healthy content

  • Subject is clear, no excessive clickbait.
  • Has plain-text fallback.
  • Have appropriate address and contact information.
  • There is an easily visible unsubscribe link.
  • Tracking domains using brand subdomains if possible.

8. Monitoring deliverability

Metrics to track

MetricsReference warning level
Hard bounce rate> 2%
Complaint rate> 0.1%
Delivery rateStrong decrease compared to baseline
Open rateAbnormal drop by domain
Spam placementContinuously increase many campaigns

Useful tool

  • Gmail Postmaster Tools
  • Microsoft SNDS
  • DMARC aggregate report analyzers
  • Provider dashboards of SES/SendGrid/Mailgun

What is BIMI?

BIMI allows the display of brand logos in the inboxes of some mailbox providers, but usually requires good DMARC enforcement and sometimes a brand authentication certificate. It does not replace SPF/DKIM/DMARC but builds on it.


Summary

Deliverability is a long-term game. You cannot fix it with a script or a single DNS record. You need to simultaneously do proper authentication, warm-up carefully, keep the list clean, and monitor reputation signals every day.

Next article: We will build monitoring, metrics and alerting to look at the notification system like a real production system.