Deliverability is whether your email reaches the inbox — not whether your ESP “sent” it. During our platform tests we watched how tools expose authentication setup, bounce handling, and reputation signals. This guide explains the mechanics so you can evaluate any ESP honestly.
SPF lists servers allowed to send for your domain. DKIM cryptographically signs messages so receivers can detect tampering. DMARC tells receivers what to do on failures and where to send reports. Missing any of these is the fastest way to land in spam — regardless of how pretty your templates look.
In our lab, platforms that surface DNS records clearly and validate them in-panel reduce setup errors. That is a product quality issue, not a minor UX nicety.
Buying lists, ignoring bounces, and mailing cold scraped addresses destroy reputation. ISPs score your domain and IP history. A smaller engaged list outperforms a huge dead list on open rates and inbox placement.
New domains and new IPs need gradual volume. Sudden spikes look abusive. Keep From names stable, align visible From domains with authenticated domains, and avoid URL shorteners that resemble phishing patterns.
Compare platforms on our 2026 email tool ranking and individual reviews. Methodology: how we test.
Since February 2024 Google and Yahoo have enforced requirements on anyone sending roughly 5,000 or more messages a day to their users. Authenticate with SPF, DKIM and DMARC. Offer one-click unsubscribe on marketing mail and honour requests within two days. Keep spam complaints low — the current ceiling is published in Google's Postmaster Tools and is worth checking directly rather than trusting a number in a blog post. Yahoo began enforcing the unsubscribe requirement in June 2024.
The practical effect is that authentication stopped being an advanced topic. It is the entry fee.
Passing SPF and DKIM is not enough on its own: DMARC also checks that the domain your recipient sees in the From line matches the domain that authenticated. Send as your own domain through a provider without completing their DNS setup and you can pass the individual checks while failing alignment. This is the most common reason a technically "authenticated" sender still lands in spam.
Receivers score the sending domain and address over time. That history is yours, it follows you between providers, and it is far easier to damage than to rebuild. A single campaign to an old purchased list can undo months of careful sending, which is why the cheapest deliverability decision available is refusing to import a list you did not collect.
New domains and new sending addresses need volume introduced gradually. A domain that has never sent and suddenly mails fifty thousand people looks exactly like a compromised account. Keep the From name stable, keep sending on a predictable rhythm, and avoid link shorteners, which share reputation with whatever else was shortened on that service.
A hard bounce means the address does not exist: remove it immediately, because continuing to mail it is a direct signal that you do not clean your list. Soft bounces — a full mailbox, a temporary rejection — deserve a limited number of retries and then suppression. Providers differ enormously in how much of this they automate, and it is a legitimate reason to pay for a better one.
A platform that hides these numbers is not protecting you from complexity. It is protecting itself from an unflattering comparison.
Spam-word checkers, subject-line graders and "deliverability scores" sold as add-ons address almost none of this. Inbox placement is decided by authentication, list quality, complaint rate and sending history. Content matters at the margin, and only once the four things above are in order.
Delivered only means the receiving server accepted the message. It can still be filed as spam. Inbox placement is what you actually care about, and your provider's delivery rate does not measure it.
Yes. Google and Yahoo require it of bulk senders, and DMARC is what checks that the visible From domain matches the authenticated one — the alignment step that SPF and DKIM alone do not enforce.
Only at consistent volume. A dedicated IP with irregular sending has no reputation to speak of and often performs worse than a well-managed shared pool. Most small senders should stay shared.