Your email is going to spam. First, find out why.
Usually it is a broken record you cannot see, and that is fixable in days. Sometimes it is reputation, and that takes weeks. Occasionally it is neither, and no amount of DNS will help. The audit tells you which — every time, before you spend a penny on a fix.
“Our invoices are going to spam”
A customer says they never got the invoice. It was in their junk folder all along. Then a quote goes missing, then a password reset. Nothing changed on your side, so nothing looks broken — and that is exactly what makes this so frustrating to chase.
Most people react by rewriting the email. They remove the word “free”, strip out images, shorten the subject line. It almost never helps, because the message content is rarely what is wrong. The problem is nearly always in DNS, in reputation, or in a rule that changed while nobody was watching.
There are five causes, and they are not equal
They need completely different work, and they carry completely different timelines. Selling a fix before knowing which one you have is guesswork with an invoice attached — so the first thing I do is find out.
- Category A
- A broken SPF record, or two of them. An SPF record over the ten-lookup limit. A DKIM selector that was never published. DMARC that does not align with what you actually send. No reverse DNS on your mail server. Forwarding that quietly breaks SPF on the way. This is the biggest single share of cases, and all of it is deterministic — the records are either right or they are not.
- Category B
- Complaints from recipients. A mailbox that was compromised and spent a weekend sending spam under your name. A volume spike that looked like a list purchase. The cause can be found and stopped quickly. The reputation itself then recovers on the receiving provider’s schedule, which is nobody’s to promise.
- Category C
- Spamhaus SBL, CSS or DBL. SURBL, URIBL, Barracuda, Proofpoint. Delisting is a form and a wait once the thing that caused the listing has actually stopped — and requesting delisting before then just burns the request.
- Category D
- Google, Yahoo and Microsoft all publish bulk-sender requirements now, and all three enforce them. These are rules with written remedies, which makes them among the more satisfying causes to find.
- Category E
- A bought list. A genuinely unwanted campaign. Or one recipient’s IT department blocking you at their own gateway, where no amount of DNS will help. If the audit lands here, I tell you in writing and the engagement ends. You will have paid for a diagnosis and got one.
“It worked fine last month”
It probably did. Then a rule changed. The big providers spent the last two years turning guidance into enforcement, and a domain that was merely untidy became a domain that gets refused.
What the providers now require
- Google and Yahoo, since February 2024. Send over 5,000 messages a day to personal accounts and you need SPF and DKIM and DMARC — not one of the three. Below that volume, you still need at least SPF or DKIM.
- Microsoft, since 5 May 2025. The same three records for consumer
Outlook, Hotmail and Live addresses above 5,000 a day. Microsoft rejects rather
than filters — non-compliant mail comes back as
550 5.7.15 Access deniedand never reaches a junk folder at all. - One-click unsubscribe. Marketing and subscribed mail needs a working
List-Unsubscribeheader on RFC 8058, plus a visible link in the message. - Spam complaints under 0.30%. Google's own guidance is to stay below 0.10% and never reach 0.30% — so 0.3% is the ceiling you are already in trouble at, not the target.
- TLS in transit, and valid forward and reverse DNS on the sending host. A missing PTR record is a surprisingly common single point of failure.
Search your bounce log for 550 5.7.15 before you do anything else. If it is
there, you already know the category and it is one of the fixable ones.
The providers are not equally helpful, and you should know that up front
- Google is the most transparent by a distance. Postmaster Tools reports domain reputation, spam rate, authentication pass rates and delivery errors. It is the best diagnostic that exists, it needs one DNS record to enable, and I set it up on every engagement whether or not Gmail is the problem.
- Yahoo sits in the middle. Sender Hub plus a complaint feedback loop — enough to work with.
- Microsoft is the hard one. SNDS and JMRP give partial visibility, and there is a mitigation form. Responses are often opaque, and a request can be refused with no usable reason given. I price for that and I do not pretend otherwise.
One more thing worth knowing before you worry: not every blocklist matters. A UCEPROTECT level 2 or 3 listing is largely ignored by the major receivers and is effectively pay-to-delist. Seeing your name on one is usually not your problem. A Spamhaus SBL, CSS or DBL listing is a different matter entirely. Telling those two apart is free, and it saves people from paying to fix something that was never affecting them.
It always has an answer
This is the part that makes the whole thing honest. The audit cannot fail to deliver, because naming the cause is the deliverable — including when the answer is one I cannot sell you a fix for.
What you get, in writing
- Which category you are in, of the five above, with the reasoning.
- The evidence. The actual records, headers, bounce codes and blocklist entries that led to the conclusion — not an assertion you have to take on trust.
- What remediation would involve, in order, written against your configuration rather than as generic advice.
- A realistic timeline, separating what is fixable this week from what recovers on a schedule nobody controls.
- What is already correct. A report that only lists problems is a sales document, not a diagnosis.
Start free. The Email Domain Health Check on this site already tests SPF, DKIM and DMARC on your domain and shows you everything it finds. No signup, no email address. If it comes back clean, you are not category A — and you just narrowed it down for nothing.
Run the free checkFour ways in
Everyone starts with the audit. Where you go afterwards depends on what it finds — and if it finds nothing I can fix, you stop there and keep the report.
Deliverability Audit
Everyone starts here. Always deliverable.
- Full authentication and DNS review
- Blocklist and reputation check
- Header and bounce analysis
- Written report with the evidence
- The category, and what it means
Authentication Fix
Category A, which is most cases. Deterministic work.
- SPF rebuilt inside the ten-lookup limit
- DKIM published and verified
- DMARC to
p=none, aligned - Reverse DNS and forwarding corrected
- Postmaster Tools set up
- Send and receive testing
Audit fee credited — you pay the difference, not both.
Full Remediation
Categories A to D together, when it is more than records.
- Everything in the Authentication Fix
- Blocklist delisting requests
- Provider mitigation submissions
- Staged DMARC rollout to
p=quarantine - Report reading across 30 days
- Sender inventory verified before enforcing
Audit fee credited — you pay the difference, not both.
DMARC Monitoring
After the fix, so it stays fixed.
- Aggregate reports received and read
- New or changed senders flagged
- Monthly summary in plain English
- Alignment failures caught early
- Monthly in advance, cancel anytime
These are launch prices for a new practice, not a permanent position — they will go up once there are testimonials behind them. If your situation does not fit any of the four, say so in the form and I will tell you honestly whether it is worth doing at all.
What you have to supply
Listed openly, because it is the fastest part to get wrong and the slowest part to chase. If you cannot grant something below, say so — there is a workaround for nearly all of it.
Access — least privilege, always
- DNS zone editing only. Not your registrar login. If your provider cannot separate the two, I send you a written list of exact record changes and you apply them yourself.
- Temporary mail tenant admin on Google Workspace, Microsoft 365 or Zoho — and only if DKIM keys actually need generating. Revoked the moment the work is done.
- One mailbox on the domain for send and receive testing.
Information — the part everybody skips
- A written inventory of every legitimate sending source. Contact form, CRM, invoicing, marketing platform, helpdesk, e-commerce, anything a previous developer set up and nobody documented. Enforcing DMARC without this blocks your own real mail, which is the most common way a deliverability fix makes things worse.
- Registrar, renewal date, and who holds the account.
- Any previous deliverability work, and your existing SPF records — including the ones somebody added and forgot.
Protecting the work
- The current zone is exported before anything changes. That is the rollback, and it exists before the first edit.
- TTLs lowered 24 to 48 hours in advance, so a mistake is minutes to undo rather than a day.
- Written authorisation naming the domain, the records to be changed and the rollback plan.
- Written sign-off that the sender inventory is complete, before DMARC is
ever moved off
p=none.
What I will not promise you
Inbox placement is decided by the receiving provider and cannot be guaranteed by anyone. This engagement covers diagnosis, correction of authentication and configuration faults, blocklist delisting requests where applicable, and submission of provider mitigation requests.
A finding of category E ends the engagement. If the cause turns out to be a purchased list, genuinely unwanted mail, or one recipient's own IT blocking you, you get that in writing with the reasoning. The audit fee is earned. Nothing further is billed.
Reputation recovery runs on a timeline nobody controls. Typically weeks once the cause has stopped. You are hearing that before you pay, not after.
Saying this out loud costs me some sales. It is still the right way round: no mailbox provider gives anyone a delivery guarantee, so a competitor offering one is either misinformed or counting on you not checking. I would rather tell you what cannot be fixed than take money for pretending otherwise.
How payment works
Plainly, so nothing about it is a surprise later. There is no account to create, no portal to log into and no card stored anywhere.
-
You apply through the form
No payment at this point, and no commitment. Tell me the domain, where you send from and what is happening.
-
I review it and confirm the scope
If it is not worth doing, I say so here and it costs you nothing. If it is, you get the scope in writing before any invoice exists.
-
An invoice arrives, payable within 48 hours
It carries an invoice number and a due date. Unpaid past 48 hours, the application lapses and the slot is released to somebody else.
-
Work begins once payment is received
Not before. For one-off work there is nothing to suspend after delivery, so payment comes first — that is the standard arrangement and it runs both ways.
-
Monitoring, if you take it, is monthly in advance
Non-payment simply suspends report processing. Nothing is billed silently in the background and you can stop whenever you like.
Run the free check, then send me the result.
It takes about a minute and costs nothing. If it comes back clean, your problem is not authentication and I will tell you where to look instead. If it comes back with findings, paste them below and you have already done the first half of the audit yourself.
Prefer to talk? Book a free call ↗ · Or hire me on Upwork ↗ · Typical reply within one business day.
Questions
How long does this take?
Do you need my domain registrar login?
What happens if you find something you cannot fix?
Can you guarantee my email reaches the inbox?
Why does my mail reach Gmail but bounce from Outlook?
550 5.7.15 Access denied instead of being filed in junk. Search your bounce log for that string. If it is there, you have found your answer and it is a fixable one.