Tagged “deliverability”
33 articles
The Google and Yahoo sender rules, one year on
A year after Google and Yahoo made authentication mandatory for bulk senders, here is what changed, how mail failed, and where enforcement is heading.
Read more
How to reach DMARC p=reject without breaking email
The staged playbook to DMARC enforcement with no email outage: inventory senders, fix SPF and DKIM, ramp p=none to p=reject, and lock down subdomains.
Read more
DMARC and Email Migration: A Step-by-Step Guide to Preserving Deliverability
Email migration can impact deliverability, DMARC helps prevent spoofing by verifying email authenticity
Read more
Protecting parked and no-mail domains
Domains that never send mail are the easiest to secure and the most commonly left wide open. Here is how to lock down parked, legacy and campaign domains with SPF -all, DMARC p=reject and a null MX so they cannot be spoofed, with zero deliverability risk.
Read more
Amazon SES at scale: deliverability and DMARC
Amazon SES is deceptively easy to start with and deceptively hard to run well at volume. Verifying a domain, adding three DNS records and firing your first message takes an afternoon.
Read more
SendGrid dedicated IPs, authentication and reputation
Most teams reach for a SendGrid dedicated IP because someone told them shared IPs are bad, or because a deliverability vendor implied that owning your own IP is the professional thing to do.
Read more
Bounce handling and the return-path
The envelope return-path is where bounces come back to and the domain SPF authenticates. Here is how a custom return-path on your own subdomain fixes SPF alignment under DMARC, and what really happens to a bounce.
Read more
DMARC for Mailchimp users: a deliverability checklist
If you send marketing email through Mailchimp, you sit in an awkward spot. You do not run your own mail servers, you do not control the IP addresses your campaigns go out on, and yet your From: address still says.
Read more
What DMARC reports do and do not tell you
Passing DMARC is permission to be judged on your merits, not a guaranteed seat in the inbox. Here is how to read aggregate reports for exactly what they measure, identity and authentication, without mistaking a perfect pass rate for good deliverability or panicking at failures that do not matter.
Read more
Dedicated vs shared sending IPs
Dedicated and shared sending IPs carry very different reputation trade-offs, and the right choice hinges on sustained volume, not folklore. Here is who should use which, and how the decision changes SPF, DKIM and DMARC alignment, plus what your aggregate reports reveal.
Read more
One-click unsubscribe: the List-Unsubscribe requirement
Google, Yahoo and Microsoft now require working one-click unsubscribe on bulk mail. Here is what the List-Unsubscribe and List-Unsubscribe-Post headers are, how RFC 8058 one-click actually works on the wire, how to implement it correctly, and why it sits alongside SPF, DKIM and DMARC on the same deliverability checklist.
Read more
Double opt-in and why it matters
Confirmed (double) opt-in keeps spam-trap hits, bounces and complaints off your list, the exact reputation signals that decide whether your authenticated mail reaches the inbox and clears the Gmail and Yahoo bulk-sender rules.
Read more
Email authentication for accountants
Accountancy practices are prime impersonation targets: you hold client bank details, your clients act on what you tell them, and the tax calendar is public. This guide covers the four fraud patterns a practice actually faces, exactly where DMARC, SPF and DKIM stop them, and a deadline-aware enforcement plan to reach p=reject without breaking client mail.
Read more
Why Gmail, Yahoo and Microsoft now require DMARC
Gmail, Yahoo and Microsoft now require SPF, DKIM and DMARC from bulk senders. Here is what each demands, what "require" really means, and how to comply.
Read more
The 2024 and 2025 bulk-sender requirements in full
Google, Yahoo and Microsoft turned email authentication into a hard delivery gate. Here are the exact requirements, the numeric thresholds, who counts as a bulk sender, and a line-by-line compliance checklist.
Read more
Keeping your spam complaint rate under 0.3%
The spam complaint rate is the small, unforgiving number mailbox providers trust most. Learn how it is measured per provider, what pushes it past the 0.3% danger line, and the concrete steps that bring it back down.
Read more
Email authentication for e-commerce
Online shops send order, shipping and receipt mail from a dozen different systems at once. Here is how to authenticate every stream, meet the Gmail, Yahoo and Microsoft bulk-sender rules, block order-confirmation phishing, and earn your brand logo in the inbox with BIMI.
Read more
Email authentication for schools and universities
A practical, stage-by-stage path to DMARC enforcement on a sprawling .edu or .ac.uk estate: discovery, fixing SPF under the ten-lookup limit, aligning DKIM across many departmental senders, ramping to p=reject, and the governance traps that stall most rollouts.
Read more
Email authentication for financial services
For banks, insurers and fintechs, DMARC, SPF, DKIM, MTA-STS and BIMI are anti-fraud and brand-protection controls, not deliverability tweaks. How to meet regulatory expectations and reach p=reject across a multi-vendor estate without breaking OTP or statement mail.
Read more
Email authentication for government
Public-sector domains are prime spoofing targets because the state's authority is the most valuable brand a fraudster can wear. Here is why government email is forged, the mandates pushing departments to p=reject, and the engineering realities of getting a sprawling government estate to enforcement without cutting off citizen mail.
Read more
Email authentication for healthcare and HIPAA
HIPAA never names DMARC, but it asks for exactly what SPF, DKIM and DMARC deliver: protection of transmitted PHI, integrity, sender authentication and ongoing risk management. Here is how email authentication maps onto the HIPAA Security Rule, why DMARC reporting need not expose PHI, and the staged path to p=reject that does not break clinical email.
Read more
Email authentication for law firms
How solicitors use SPF, DKIM and DMARC to stop their domain being spoofed, protect client money on completions, and meet their confidentiality duties, with a staged, no-outage path to p=reject.
Read more
Why legitimate email lands in spam
Real, useful email ends up in the junk folder when its signals look untrustworthy to mailbox providers. This guide breaks misfiled mail into its four root causes (authentication, reputation, content and complaints) and shows how to diagnose and fix each with concrete tools and steps, starting with the highest-leverage fix: authentication.
Read more
Email authentication for nonprofits
For charities, DMARC is donor trust and fundraising revenue expressed as DNS records: it stops attackers spoofing your appeals and lifts your own appeals out of the spam folder. Here is how to align every sender, ramp safely to p=reject, and put your logo in the inbox, including via a Common Mark Certificate when your charity logo is not a registered trademark.
Read more
Email authentication for SaaS companies
SaaS companies send several distinct mail streams at once: transactional, product, marketing and customer-generated. This guide shows how to structure SPF, DKIM, DMARC, MTA-STS and BIMI by subdomain so a bad day on one stream never poisons your password resets, and how to reach p=reject across every domain without an outage.
Read more
Feedback loops and complaint handling
A feedback loop (FBL) is how a mailbox provider tells you a user marked your mail as spam. Learn what FBLs are, how Yahoo, Microsoft and Gmail differ, how to enrol against your DKIM signing domain, how to read ARF reports, and how to keep your complaint rate under the 0.3% threshold.
Read more
GDPR and DMARC reporting
DMARC reports can contain personal data: source IPs in aggregate reports, and recipients, subjects and message bodies in forensic reports. Here is which fields the UK and EU GDPR catch, why forensic (ruf) reporting is the real hazard most domains should drop, and the lawful basis, retention and transfer practices that keep aggregate (rua) collection compliant.
Read more
Using Google Postmaster Tools
Google Postmaster Tools shows you how Gmail scores your domain and IP reputation, what share of your mail authenticates, your TLS coverage, and how often Gmail users mark your messages as spam. Here is how to read each dashboard, the spam-rate and reputation thresholds that actually matter, and how to pair it with DMARC aggregate data to find and fix the source of any problem.
Read more
Inbox placement testing
Inbox placement testing tells you where your mail lands (inbox, spam, a tab, or nowhere), which DMARC reports cannot. Here is how seed lists and panel tools actually work, where they mislead you, and how to cross-read their output with DMARC aggregate data so authentication faults and reputation faults stop looking identical.
Read more
IP warming for new sending IPs
A new sending IP starts with zero reputation, so a sudden volume spike reads as spam. Here is a sensible warm-up schedule, when a dedicated IP is even worth it, and how aligned SPF, DKIM and DMARC make the reputation you build stick to your domain instead of a leased IP.
Read more
List hygiene and deliverability
Authentication proves who you are; list hygiene proves you are wanted. Once DMARC enforcement welds reputation to your verified domain, dead addresses, bounces and spam-trap hits stop being diffuse problems and start hitting your signed identity directly. Here is how clean lists protect the reputation your SPF, DKIM and DMARC setup earns.
Read more
Using Microsoft SNDS and JMRP
Microsoft gives self-hosted senders two free feedback channels into Outlook.com filtering: SNDS for IP reputation, complaint bands and spam-trap hits, and JMRP for the individual junk complaints behind them. Here is how to enrol, read the data honestly, instrument your mail so complaints are traceable, and connect it all to your DMARC alignment so an Outlook deliverability dip becomes diagnosable instead of a mystery.
Read more
A subdomain strategy for sending mail
Splitting transactional, marketing and corporate mail across dedicated subdomains isolates reputation and shrinks the DMARC enforcement problem into small, independently controllable streams. Here is how to design the split, the exact SPF, DKIM and DMARC records to publish, and how to migrate without an email outage.
Read more