Why are my emails going to spam, and how do I fix it?
Why are my emails going to spam? Four checks in the order that finds the fault fastest, and the sender rules Gmail, Outlook and Yahoo now apply.
You sent an ordinary email to a customer. It sat in their spam folder for three days. Now you're typing "why are my emails going to spam" into a search box and getting lists of twenty causes in no particular order, half of them about subject lines.
Subject lines are almost never it. Since 2024 the big mailbox providers have published the rules they hold senders to, and those rules are about who you are (authentication), who you send to (your list), how those people react (complaints), and only then what you wrote. So that is the order to check. This guide walks the four checks in that order, shows what each failure looks like from your side of the screen, and quotes the rules from Gmail, Outlook and Yahoo's own pages, all read on 2026-09-24. It is general guidance; if a business runs on this mailbox, have whoever manages your domain look at the real headers too.
Why are my emails going to spam: check in this order
Most guides list causes. A list is no use at 4 pm with an unhappy customer on the phone, because you can't fix twenty things. You need to know which one it is.
Check authentication first, because it is a yes-or-no answer you can get in ten minutes, and because a failing record explains everything downstream: a domain that can't prove it sent the mail gets no credit for anything else it does right. Check the list second, because the addresses you send to decide the bounces and the traps, and both show up in your reports before anything else does. Check complaints third: they are the one number the providers publish a limit for. Check content last. A well-authenticated domain with a clean list can write "FREE!!!" in the subject and reach the inbox; a domain that looks spoofed lands in spam with a perfect subject line.
Work left to right and stop at the first check that fails; the checks to its right rarely matter until it is fixed.
Check 1: authentication, and what a failure looks like
Three DNS records tell a receiving server that mail from your domain is really yours. Four of the six ranking pages we read name them; none explains them, so here they are in plain words.
SPF is a text record on your domain listing the servers allowed to send mail as you. It fails when a tool you added later (a CRM, an invoicing app, a newsletter service) sends "from" your domain but isn't in the list. It also fails when the record grows past 10 DNS lookups, a limit Microsoft's own FAQ points to: too many include: entries and the whole check errors out.
DKIM is a signature your sending server adds to each message, checked against a public key published in your DNS. It fails when the tool was never set up to sign for your domain (it signs with its own instead) or when someone tidied the DNS and deleted the key. Google and Yahoo both require a key of 1024 bits or longer.
DMARC is a policy record that does two jobs: it says what a receiver should do when both checks fail, and it requires the domain in your From address to match (the providers say "align with") the domain SPF or DKIM passed for. Gmail, Outlook.com and Yahoo all ask bulk senders for a DMARC record with at least p=none.
What a failure looks like from your side: nothing, at first. Mail keeps leaving. Then replies dry up, one customer says "it was in my junk," and a test message to your own Gmail address lands in spam with a red warning about the sender. At Outlook.com the failure looks different. Microsoft's announcement, in its update of 30 April 2025, says mail from domains sending over 5,000 messages a day that fails these checks is rejected from 5 May 2025 with the error 550 5.7.515 Access denied, sending domain does not meet the required authentication level; the page still carries its earlier wording about routing such mail to the Junk folder first. Either way, a bounce carrying that code is an authentication failure, not a content problem.
Here is how to read your own result. Send a message from your normal mailbox or your sending tool to a Gmail address you control, open it, and choose "Show original". Near the top you'll see three lines: SPF, DKIM and DMARC, each with PASS or FAIL. Outlook.com has the same information under "View message source" in a header called Authentication-Results, which reads like spf=pass dkim=pass dmarc=pass.
Three words settle check 1; a fail on any of them is your afternoon's work.
The limits: p=none only asks receivers to report, it stops nobody spoofing you, so it is the floor, not the target. Mail that a recipient forwards on can fail SPF through no fault of yours; DKIM survives forwarding, which is one reason to have both. And a record that passes today does not repair a reputation you burnt last month. That takes weeks of clean sending.
Check 2: your list, and the addresses that never asked
If authentication passes, look at who you send to. A list gathers three kinds of bad address: people who never signed up (a bought list, a scraped list, a conference attendee export), addresses that have died (the person left the company, the domain lapsed), and spam traps, addresses that mailbox providers and blocklist operators keep purely to catch senders who mail people who didn't ask. You cannot tell a trap from a customer by looking at it.
What a failure looks like: a bounce report full of "user unknown" after a send, then inbox placement falling on the sends after that, including to people who did sign up. Microsoft's guidance for large senders puts it as list hygiene and bounce management: "remove invalid addresses regularly to reduce spam complaints, bounces, and wasted messages."
The fix, in order:
Remove every address that hard-bounced, today, and stop your tool from retrying them.
Stop mailing people who have not opened or clicked in a long time. There is no published cut-off; our view is that a year of silence is a no.
Turn on double opt-in for new signups, so a typo or a prank address never joins the list.
Before importing any old list, run it through an email verification tool. The checks worth having are syntax and MX record checks (does the domain accept mail at all), an SMTP mailbox check, catch-all domain detection, disposable address detection, role account detection (info@, sales@) and spam trap detection.
Never buy a list. Every address on it failed step 3 by definition.
Check 3: complaint rate, and the 0.3% line
A complaint is a recipient clicking "Report spam". This is the one measure with a published number. Google's sender guidelines say to keep the spam rate reported in Postmaster Tools below 0.3%, and the same page's Postmaster Tools guidance says to aim below 0.10% and never reach 0.30% or higher. Yahoo's page says the same 0.3%. In plain figures: three complaints per thousand delivered messages is the edge, and one per thousand is where you want to live.
People complain when they don't remember signing up, when they can't find the unsubscribe link, and when the mail comes more often than they expected. So the fix is to make leaving easy:
Support one-click unsubscribe for marketing and subscribed mail. Gmail requires it of bulk senders; Yahoo asks bulk senders to support it and calls the RFC 8058 method, a pair of headers your sending tool adds so the mailbox can show its own unsubscribe button, highly recommended.
Keep a visible unsubscribe link in the body as well; Yahoo requires it, Microsoft recommends it.
Act on an unsubscribe fast. Yahoo's rule is within 2 days.
Register your domain in Google's Postmaster Tools and read the spam rate chart weekly. It is free.
The whole margin is three complaints per thousand delivered; the safe line is one.
The limit here: Microsoft's announcement gives no complaint-rate number for Outlook.com, so for that inbox you are working to Google's line as the best published proxy.
Check 4: content and sending pattern, last for a reason
Only now does content come in, and even here the things that matter are rarely the words. In rough order of how often they bite:
A From address that can't receive replies. Microsoft asks that the From or Reply-To address "is valid, reflects the true sending domain, and can receive replies." A no-reply address on a domain nobody answers is a signal.
Links to a different domain than you send from: a link shortener, a tracking domain your tool set up, an image host. Use your own domain for links where the tool lets you.
Image-only mail with no text a filter can read.
A volume jump. A domain that sent 50 messages a day and suddenly sends 20,000 looks like a compromised account. Ramp up over days, not hours.
Deceptive subject lines and headers. Microsoft's page lists "accurate subject lines" and consent under transparent mailing practices; a "Re:" on a message that is not a reply is the classic offence.
Exclamation points and the word "free" get a paragraph on three of the six ranking pages we read. They are a small weight on a scale that authentication and complaints already tipped. Fix them last.
Why are my emails going to spam all of a sudden?
Sudden means something changed. Before you touch anything, list what changed in the last month:
A DNS edit (a website move, a new host, a tidy-up) that dropped an SPF include or a DKIM key.
A new tool that sends as your domain and was never added to SPF or set up for DKIM.
A list import, especially one older than a year.
A bigger campaign than usual, or a new domain sending at full volume from day one.
A domain or a DKIM key that expired.
A provider's rule taking effect: Gmail and Yahoo from February 2024, Outlook.com's rejection of unauthenticated high-volume mail from 5 May 2025.
The last one is the reason many "it used to work" complaints in 2025 and 2026 have the same answer: the rules changed under mail that had stayed the same.
Gmail, Outlook and Yahoo: the rules as each provider publishes them
The three providers publish their sender rules on their own pages, and vendor summaries drift from them, so this table is taken from the pages themselves, read on 2026-09-24. "Bulk" is Google's 5,000 or more messages a day and Microsoft's "more than 5,000 emails per day"; Yahoo's page has a bulk-sender section but no number.
Rule | Gmail (Google) | Outlook.com (Microsoft) | Yahoo |
|---|---|---|---|
SPF or DKIM, every sender | Required | Not stated | Required |
SPF and DKIM, bulk senders | Required at 5,000 a day | Required, both must pass, over 5,000 a day | Required |
DMARC with at least | Required | Required | Required |
From domain aligned with SPF or DKIM | Required | Required | Required, relaxed alignment accepted |
DKIM key length | 1024 bits or longer | Not stated | 1024 bits minimum |
Spam rate | Below 0.3%; aim below 0.10% | Not stated | Below 0.3% |
One-click unsubscribe, bulk marketing mail | Required | Visible unsubscribe link recommended | Required; the RFC 8058 method "highly recommended", plus a visible link in the body |
Time to honour an unsubscribe | Not stated | Not stated | 2 days |
TLS, valid forward and reverse DNS, RFC 5322 format | Required, every sender | Not stated | Not stated |
What happens on failure | "marked as spam" or "might not be delivered as expected" | Rejected with 550 5.7.515 from 5 May 2025 (the 30 April 2025 update); the page's earlier Junk-folder wording is still on it | "a negative impact to the delivery of your mail" |
In force since | 1 February 2024 | 5 May 2025 (published 2 April 2025, updated 30 April 2025) | February 2024 |
One detail on the Microsoft page that recipients should know: its FAQ says the Safe Senders list will not be honoured for mail that fails the authentication requirement. A customer adding you to their safe list does not get an unauthenticated domain past the check. Only fixing the records does.
Google Workspace and other business mailboxes
"Why are my emails going to spam google workspace" is a real search, and the answer is that the rules above are about your domain, not about the mailbox you rent. A business on Workspace, or on Microsoft 365 or any hosted mailbox, sends from its own domain, so its own DNS has to carry the SPF, DKIM and DMARC records, and Google's guidelines page is the same one whether you send from a Workspace mailbox or a marketing tool.
The trap for a small business is the second sender. The mailbox provider set up its own SPF and DKIM when you signed up, so mail from the mailbox passes. Then you add a newsletter tool, then an invoicing app, then a booking system, and each one sends as you@yourdomain.com. Every one of them has to be added to SPF and given its own DKIM key, or its mail fails alignment while the mailbox's mail passes, and you get the confusing case where your replies arrive and your invoices don't.
Incoming mail landing in your junk folder
Some of the searches for this question are from the other side: "why are my incoming emails going to spam," "why are all my emails going to junk in outlook." If the mail you receive is being filed as junk, the sender's records may be at fault (send them this page), but check your own settings first: a junk-filter level set to strict, a rule or a filter created by accident, a blocked-senders entry, or a mailbox that was recently migrated and lost its safe-senders list. Marking a message "not junk" and adding the sender to your contacts fixes the individual case; a filter set to "safe lists only" is usually behind "all of my mail."
How to check if your emails are going to spam
You can do the basic test yourself: keep one mailbox at each of the three providers, send every new template to all three, and read the headers as in check 1. Register your domain with Google's Postmaster Tools for the spam rate and the domain reputation.
What that misses is the rest of the inbox world and the trend over time, which is what email deliverability tools exist for. The listing compares every tool on the same 16 rows, and the rows you need here are these: inbox placement testing across mailbox providers, an SPF, DKIM and DMARC checker, DMARC report analytics (so the p=none reports become readable), blocklist monitoring, IP and domain reputation monitoring, bounce and complaint monitoring, and email header analysis. If your problem is receipts and password resets going astray rather than newsletters, the fix is usually to move them to their own sending stream on a transactional email service, so a marketing complaint spike can't drag a receipt into spam.
The one thing to do today
Send yourself a message at a Gmail address, open "Show original", and read the three lines. If all three say PASS, move to your bounce report and your spam rate. If any says FAIL, you've found it, and everything else in this guide waits until the record is fixed. When you're past the ten-minute check and want the placement tests and the monitoring done for you, start with the email deliverability tools listing, or the wider software categories if your problem turns out to be the sending tool itself.