Stop email going to spam troubleshoot — complete fix guide: Practical Guide
Complete troubleshooting guide to stop emails going to spam. Fix DNS records, authentication, reputation, and content issues with tested steps.

On this page
TL;DR — Key takeaways
- Emails land in spam primarily due to missing or incorrect SPF, DKIM, and DMARC records, which you can verify using DNS lookup tools and fix through your DNS provider.
- Poor sender reputation from high bounce rates, spam complaints, or shared IP history requires immediate list hygiene, authentication fixes, and gradual sending volume increases.
- Content triggers like excessive capitalization, spam keywords, broken HTML, or missing unsubscribe links cause filtering even with perfect authentication.
- Testing deliverability with mail-tester.com or GlockApps before sending campaigns identifies fixable issues and provides actionable scores.
- Shared hosting environments require verification that your domain's DNS records are separate from server-wide records and properly configured for your sending domain.
When your emails consistently land in spam folders, legitimate business communication fails. Recipients miss invoices, password resets, order confirmations, and support responses. Email going to spam troubleshoot work requires systematic diagnosis across authentication, reputation, content, and infrastructure layers.
This guide provides a step-by-step troubleshooting framework for website owners, hosting customers, and support engineers. Each section addresses a specific failure point with verification commands, safe fixes, and rollback procedures. Follow the diagnostic sequence to identify and resolve the root cause efficiently.
Understanding why emails go to spam
Email spam filters operate as multi-layered defense systems. They evaluate sender authentication, domain reputation, IP reputation, content patterns, recipient engagement, and infrastructure signals. A failure in any layer triggers filtering.
Authentication failures occur when SPF, DKIM, or DMARC records are missing, misconfigured, or misaligned with your sending domain. Filters treat unauthenticated mail as suspicious by default.
Reputation signals include sender domain age, historical spam complaints, bounce rates, blacklist presence, and sending patterns. Shared hosting environments inherit reputation from other accounts on the same IP address.
Content triggers activate when your message contains spam keywords, excessive capitalization, misleading subject lines, broken HTML, suspicious links, or missing unsubscribe mechanisms.
Infrastructure issues like reverse DNS mismatches, missing PTR records, or sending from residential IP ranges raise immediate red flags for recipient mail servers.
Verify email authentication records
Start by checking your domain's SPF, DKIM, and DMARC records. These DNS records prove your mail server is authorized to send email for your domain.
SPF (Sender Policy Framework) lists which IP addresses or mail servers can send email for your domain. Use a DNS lookup tool or command-line query to verify your record exists and includes your sending server.
Check SPF with: dig TXT yourdomain.com +short | grep spf
A valid SPF record looks like: v=spf1 include:_spf.yourmailprovider.com ~all
The ~all qualifier sets a soft fail policy. Use -all only after thorough testing, as it instructs recipients to reject unauthorized mail outright.
DKIM (DomainKeys Identified Mail) cryptographically signs your outgoing messages. Your mail server adds a signature header, and recipients verify it against a public key published in your DNS.
DKIM records appear as TXT records with a selector prefix, such as: default._domainkey.yourdomain.com
Check DKIM with: dig TXT default._domainkey.yourdomain.com +short
If DKIM is missing, generate keys through your mail server control panel or hosting provider. Most platforms provide automatic key generation and DNS record suggestions.
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells recipient servers what to do when SPF or DKIM checks fail. It also provides reporting for visibility into authentication failures.
A basic DMARC record looks like: v=DMARC1; p=none; rua=mailto:[email protected]
Start with p=none to monitor without blocking. After confirming legitimate mail passes authentication, gradually move to p=quarantine then p=reject.
Use online validators like MXToolbox or DMARCian to verify all three records are syntactically correct and aligned with your domain.
- Back up existing DNS records before making changes
- Test new SPF records with mail-tester.com before full deployment
- Allow 24-48 hours for DNS propagation after record updates
- Monitor DMARC reports for authentication failures before enforcing strict policies
- Verify your sending domain matches the domain in your SPF and DKIM records
Check and repair sender reputation
Sender reputation accumulates over time based on recipient behavior, complaint rates, bounce handling, and engagement metrics. Poor reputation overrides perfect authentication.
Check your sending IP and domain against major blacklists using MXToolbox Blacklist Check or MultiRBL. If listed, follow each blacklist's removal process. Removal requires fixing the underlying issue first.
High bounce rates damage reputation quickly. Bounces fall into two categories: hard bounces (permanent failures like invalid addresses) and soft bounces (temporary issues like full mailboxes).
Clean your email list immediately. Remove hard bounces after the first failure. Remove soft bounces after three consecutive failures. Use double opt-in for new subscriptions to prevent invalid addresses from entering your list.
Spam complaint rates above 0.1% trigger filtering. Even a few complaints per thousand sends signal problems. Review your content, ensure clear unsubscribe links, and honor unsubscribe requests within 24 hours.
Shared hosting customers inherit reputation from other accounts on the same IP. If your authentication is correct but mail still goes to spam, request your hosting provider check for IP blacklisting or consider a dedicated IP address.
New domains and IPs lack reputation entirely. Mailbox providers treat them cautiously. Warm up your sending by starting with small volumes to engaged recipients, then gradually increasing over 2-4 weeks.
Monitor your sender score using tools like Sender Score or Google Postmaster Tools. These services provide reputation metrics and identify specific issues affecting deliverability.
- Implement double opt-in to prevent invalid addresses
- Remove unengaged recipients who haven't opened emails in 6+ months
- Start with 50-100 emails per day when warming up a new domain or IP
- Increase sending volume by 50-100% every 3-5 days during warmup
- Segment lists to send to most engaged recipients first
Fix content and formatting issues
Email content triggers spam filters through pattern matching, keyword analysis, HTML structure evaluation, and link inspection. Even authenticated mail gets filtered when content raises flags.
Avoid spam trigger words in subject lines and body text. Common triggers include: free, guarantee, click here, act now, limited time, earn money, no obligation, risk-free, and excessive punctuation like multiple exclamation marks.
Maintain a healthy text-to-image ratio. Messages with only images and no text appear suspicious. Include at least 500 characters of readable text. Use alt text for images so the message remains understandable if images are blocked.
Write subject lines that accurately describe your message. Misleading subjects trigger spam filters and damage reputation through recipient complaints. Keep subjects under 50 characters for optimal mobile display.
Check HTML structure. Use clean, valid HTML without excessive styling, hidden text, or obfuscated content. Test rendering across email clients using tools like Litmus or Email on Acid.
Include a physical mailing address in your footer. This requirement comes from anti-spam regulations like CAN-SPAM and builds trust with recipients and filters.
Provide a clear, functional unsubscribe link in every promotional email. Make it easy to find — typically in the footer. Test the unsubscribe process regularly to ensure it works correctly.
Limit link density. Messages with excessive links or suspicious domains trigger filtering. Use your own domain for tracking links rather than generic shorteners. Verify all links are functional before sending.
Avoid all-caps text, excessive punctuation, colored fonts that obscure text, or background colors that reduce readability. These formatting choices signal spam to both filters and human recipients.
- Test messages with mail-tester.com before sending to large lists
- Keep subject lines under 50 characters
- Include at least 500 characters of readable text
- Use your domain for all links instead of generic shorteners
- Test the unsubscribe link before each campaign
Verify mail server configuration
Mail server infrastructure problems cause immediate deliverability failures even when authentication and content are perfect.
Verify reverse DNS (PTR record) matches your sending domain or mail server hostname. Recipient servers check that your IP address resolves to a legitimate hostname, and that hostname resolves back to the same IP.
Check PTR record with: dig -x YOUR_IP_ADDRESS +short
The result should match your mail server's hostname. If it shows your hosting provider's generic hostname instead, request a custom PTR record through your provider.
Ensure your mail server uses port 587 for authenticated submission with STARTTLS encryption. Port 25 is for server-to-server transfer and increasingly blocked by ISPs. Port 465 is deprecated in favor of 587.
Verify TLS certificates are valid and not expired. Use: openssl s_client -connect mail.yourdomain.com:587 -starttls smtp
The certificate should match your mail server hostname and show a valid chain to a trusted certificate authority.
Check that your server's hostname is not a residential or dynamic IP range. Use WHOIS lookup on your IP address. ISP-assigned residential ranges are immediately flagged by spam filters.
Review mail server logs for authentication failures, connection rejections, or TLS errors. Log entries provide specific rejection reasons from recipient servers, guiding your troubleshooting.
For shared hosting, verify your domain's MX records point to your intended mail server. Incorrect MX records send mail to the wrong server, bypassing your authentication configuration.
Check MX records with: dig MX yourdomain.com +short
- Back up mail server configuration before making changes
- Test SMTP authentication with a mail client before sending production mail
- Verify TLS certificates have at least 30 days until expiration
- Document your PTR, MX, and authentication record values for quick reference
- Keep mail server software updated with security patches
Test and monitor deliverability
Systematic testing identifies issues before they affect production email. Regular monitoring catches reputation problems early.
Use mail-tester.com for comprehensive pre-send testing. Send a test message to the provided address and receive a detailed score with specific issues to fix. Aim for a score above 8/10.
GlockApps and 250ok provide inbox placement testing across major mailbox providers. These services show whether your mail reaches the inbox, spam folder, or gets blocked entirely at Gmail, Outlook, Yahoo, and others.
Set up seed lists with test accounts at major providers. Send every campaign to these accounts first and verify inbox placement before sending to your full list.
Enable Google Postmaster Tools for domains sending to Gmail addresses. This free service provides reputation data, spam rates, authentication status, and delivery errors specific to Gmail.
Monitor bounce rates, complaint rates, and unsubscribe rates after each send. Sudden increases indicate problems requiring immediate investigation.
Implement feedback loops with major ISPs. These services notify you when recipients mark your mail as spam, allowing you to remove complainers from your list immediately.
Review DMARC reports weekly. These XML reports detail authentication failures, sources of unauthorized mail, and policy enforcement results. Parse reports using DMARC analyzers like Postmark's DMARC Digests.
Document your baseline metrics when deliverability is good. This baseline helps you quickly identify when metrics degrade and deliverability issues begin.
Schedule monthly reviews of your email authentication records, blacklist status, and deliverability scores. Proactive monitoring prevents small issues from becoming major problems.
- Test every campaign with mail-tester.com before full send
- Maintain seed accounts at Gmail, Outlook, Yahoo, and iCloud
- Set up alerts for bounce rates above 2% or complaint rates above 0.1%
- Review DMARC reports weekly during the first month after setup
- Document changes to email infrastructure and correlate with deliverability shifts
Quick troubleshooting checklist
- Verify SPF record exists and includes your mail server IP or provider
- Confirm DKIM is enabled and public key is published in DNS
- Set up DMARC record starting with p=none for monitoring
- Check sending IP and domain against major blacklists
- Clean email list removing hard bounces and inactive recipients
- Review recent email content for spam trigger words and formatting issues
- Verify reverse DNS PTR record matches mail server hostname
- Test SMTP connection uses port 587 with STARTTLS encryption
- Confirm MX records point to correct mail server
- Run test email through mail-tester.com and achieve 8+ score
- Set up Google Postmaster Tools for Gmail deliverability monitoring
- Enable DMARC reporting and review first report
- Document baseline deliverability metrics for future comparison
- Create seed list with test accounts at major providers
FAQ
Why do my emails go to spam even though I'm not sending spam?
Emails go to spam due to missing authentication records (SPF, DKIM, DMARC), poor sender reputation from high bounce rates or complaints, content triggers like spam keywords, or infrastructure issues like missing reverse DNS. Spam filters evaluate multiple signals beyond just content. Even legitimate mail fails deliverability when authentication is incomplete or reputation is damaged from past sending practices.
How long does it take to fix email deliverability after adding SPF and DKIM?
DNS record propagation takes 24-48 hours after adding SPF, DKIM, and DMARC records. However, reputation repair takes 2-4 weeks of consistent good sending practices. Start with small volumes to engaged recipients, maintain low bounce and complaint rates, and gradually increase sending. Mailbox providers need time to observe your improved authentication and sending behavior before granting better inbox placement.
What is a good sender score and how do I check it?
Sender scores range from 0-100, with scores above 80 considered good for consistent inbox delivery. Check your score using Sender Score by Validity, Google Postmaster Tools, or Microsoft SNDS. Scores below 70 indicate reputation problems requiring immediate attention to authentication, list hygiene, and sending practices. Your score updates based on complaint rates, bounce rates, spam trap hits, and recipient engagement over rolling 30-day periods.
Should I use a dedicated IP address or shared IP for sending email?
Shared IPs work well for low-volume senders (under 100,000 emails per month) because you benefit from the provider's established reputation. Dedicated IPs require consistent sending volume to maintain reputation and need 2-4 weeks of warmup. Choose dedicated IPs only if you send high volumes regularly, need complete control over reputation, or share hosting environments are causing deliverability problems. Switching to dedicated IP without proper warmup makes deliverability worse temporarily.
How do I remove my domain from a blacklist?
First, identify why you were blacklisted by checking the blacklist's website for specific removal criteria. Fix the underlying issue causing the listing such as compromised accounts, authentication failures, or list hygiene problems. Then submit a delisting request through the blacklist's official removal process. Most blacklists automatically remove domains after 1-2 weeks of clean sending, but manual requests can accelerate removal. Maintain fixed authentication and clean sending practices to prevent re-listing.
Related articles
- Hosting OperationsSelf-Hosted App Deployment Fails? Check DNS, SSL, Reverse Proxy, and Logs FirstTroubleshoot failed self-hosted app deployments by checking DNS, SSL, reverse proxy routing, container status, logs, and ports.
- Hosting OperationsSelf-Hosted PaaS on a VPS: What to Check Before Installing Coolify, Dokploy, or CapRoverA hosting support checklist for preparing a VPS before installing self-hosted PaaS tools like Coolify, Dokploy, or CapRover.
- Hosting OperationsLinux Server Security Lessons from the Arch Linux Malware Package IncidentPractical Linux server security checklist for VPS admins after package malware concerns, with safe checks, rollback steps, and support guidance.
- Hosting OperationsAWS Lightsail Hong Kong VPS Latency: Practical Hosting Guide for IndonesiaLearn how to test AWS Lightsail Hong Kong VPS latency, compare regions, migrate safely, and troubleshoot hosting performance.
- Hosting OperationsCloudflare Tomorrow Watchlist: A Practical Hosting Operations GuidePractical Cloudflare troubleshooting checklist for DNS, SSL, caching, WAF, origin health, safe testing, and rollback planning.
- Hosting OperationsNetwork Safety Checklist for AI Agent Skills in Hosting OperationsAudit AI agent skills safely with network checks, secret protection, sandbox testing, rollback steps, and hosting support troubleshooting guidance.