Email deliverability: staying out of the spam folder

Email authentication gets your mail through the door. Deliverability is about staying welcome: keeping a good reputation with Gmail, Outlook and others so your newsletters and personal mail keep landing in the inbox. Set up Email authentication first, then use this pattern to split your sending, enforce DMARC and keep an eye on things.
Who does this? Your IT or InfoSec lead. Setup takes about two hours spread over a few weeks, then 15 minutes a month.

How reputation works

Inbox providers judge every message partly on the reputation of the domain that sent it. That reputation comes from how recipients react: opens and replies help, spam complaints and bounces hurt. Everything sent from one domain shares that reputation, so one badly received newsletter can push your colleagues' everyday mail into spam too.

Split your sending over subdomains

Give each kind of mail its own subdomain, so each builds its own reputation:
  • Personal mail from your team stays on yourorg.org (for example Google Workspace).
  • Newsletters and campaigns go out from news.yourorg.org (MailerLite, Brevo, Mailchimp).
  • Automated mail from apps, forms and invoicing goes out from notify.yourorg.org .
Use subdomains of your own domain, not a new lookalike domain: a new domain starts with no reputation and looks like phishing. Each newsletter tool has a "sending domain" or "domain authentication" setting that gives you the DNS records to add. Check first that the name is free: some tools already use a subdomain like mail. for link tracking. Most tools also send a confirmation mail to the sender address on the new subdomain, so make it reachable before you start. In Google Workspace, add the subdomain as a user alias domain (Admin console → Account → Domains): every colleague then gets an address like name@news.yourorg.org in their normal inbox. Keep the reply-to address on a real inbox so replies still reach a person, and send the first mailing from the new subdomain to your most engaged subscribers.

Enforce DMARC

A DMARC policy of p=none only watches; it doesn't stop anyone sending mail in your name. Send your DMARC reports to a reader that turns them into a readable overview, such as URIports , a small independent Dutch service that keeps all data on its own servers in the Netherlands (we use it ourselves). It gives you a report address to put in your DMARC record. If you manage many domains or want hosted MTA-STS, Mailhardener in Amsterdam is a good alternative. When four weeks of reports show every tool you use passes, move to p=quarantine, and four weeks later to p=reject. Our DMARC how-to has the exact records.

Monitor

  • Google's Postmaster Tools shows your spam complaint rate at Gmail and whether you meet Google's sender requirements. It only shows data once you send a few hundred mails a day to Gmail addresses.
  • Your newsletter tool shows complaints and bounces per send. Keep spam complaints under 0.1% and hard bounces under 2%.
  • internet.nl , run by the Dutch Internet Standards Platform, scores your website and mail setup. Aim for 100%.
  • mail-tester.com gives a test newsletter a spam score out of 10. Aim for 9 or higher.
  • Our Domain & server security checklist covers the deeper DNS settings: DNSSEC, MTA-STS and TLS-RPT.

Blocklist false positives

Blocklist checkers such as MXToolbox also test the IP address your website runs on. If your site sits behind a CDN like Cloudflare or Bunny, that address is shared with thousands of other sites and sometimes shows up on a list. That says nothing about your email, which leaves from your mail provider's servers. What counts is whether your domain itself is listed; check that with Spamhaus's own lookup .

Accompanying tasks

12 tasks to put this pattern in place and keep it running. Untick anything you've already done. In Asana they all sit under one task, "Email deliverability".

Log in to create in Asana No Moral Fabric account?

Setup, one-off

Maintenance, recurring

29 Sept 2026 by Ruben

12 accompanying tasks

9 to set it up, 3 to keep it running.

Log in to create in Asana See the tasks