Passing authentication but still in spam: a diagnosis flow
SPF, DKIM and DMARC all pass, yet mail lands in spam. Work through reputation, engagement, content and infrastructure in order to find the real cause.

On this page(11 sections)
- First, confirm what you are seeing
- Step 1: read the evidence in the headers
- Step 2: check the sending infrastructure
- Step 3: look at your reputation
- Step 4: look at engagement
- Step 5: look at the content
- Step 6: check what changed
- Step 7: test, but carefully
- What to do once you know
- Keep it from happening again
- Key takeaways
You did the homework. SPF passes, DKIM passes, DMARC is in place and aligned. The headers say pass three times. And the message still lands in the spam folder at Gmail, or Outlook, or the one customer who matters.
This is a common and frustrating spot. Authentication proves who sent a message. It does not prove the message is wanted. Mailbox providers decide placement from many other signals, and a perfectly authenticated message can still look like junk. This guide gives a diagnosis order, from the cheap checks to the deeper ones, so you find the cause instead of guessing.
For the case where mail does not arrive at all, start with email not received: a systematic debugging order. Here the mail arrives, in the wrong place.
First, confirm what you are seeing
Before diagnosing, make sure the problem is real and understood.
- Where does it land? Spam, the Promotions tab or a "Other" or "Updates" tab are different problems. A tab is not spam. See why mail lands in the Promotions tab.
- How often? One message to one person is different from most messages to one provider.
- Which providers? If only one provider is affected, the cause is likely specific to it.
- Since when? A sudden change points to something you changed or a blocklist. A slow decline points to reputation or engagement.
- Which kind of mail? Marketing, transactional or one-to-one conversations behave differently.
Write the answers down. They narrow the search.
Step 1: read the evidence in the headers
Open the full headers of an affected message in a test account and check Authentication-Results, as explained in the Authentication-Results header.
- Do SPF, DKIM and DMARC all pass, and are they aligned with the From domain?
- Is there any
spamorx-spamheader from the receiving side? Some providers add a score or a reason. - Does the message carry the headers a bulk sender needs, such as List-Unsubscribe?
If something does not pass or align, fix that first. Otherwise, continue.
Step 2: check the sending infrastructure
Mailbox providers look at the server that connects to them.
- Reverse DNS. The sending IP should have a PTR record that points to a hostname, and the hostname should resolve back to the same IP. See reverse DNS, PTR and HELO.
- Blocklists. Check the sending IP and your domain on major lists. If you are listed, see the blocklist delisting playbook.
- TLS. Mail should be sent over an encrypted connection.
- Shared or dedicated IP. On a shared address, other senders' behaviour affects you. See shared vs dedicated IP.
If you use a sending service, ask them which IPs and domains your messages use, and check those.
Step 3: look at your reputation
Reputation attaches to your domain and to your IP, and it changes slowly.
- Google Postmaster Tools shows domain and IP reputation, spam rate and authentication results for Gmail. See the Postmaster Tools guide.
- Microsoft's tools (SNDS and JMRP) show similar data for Outlook.
- Your sending provider's dashboard shows bounces, complaints and delivery rates.
Pay attention to the spam complaint rate. Providers expect it to stay low; see the complaint rate threshold. Remember that domain and IP reputation are separate, and a new domain has no history to lean on. See warming up a new domain.
Step 4: look at engagement
Providers learn from what recipients do.
- Do people open and reply, or delete without opening?
- Do they move your mail out of spam, or report it?
- Is your list full of inactive addresses? Sending to people who ignore you teaches filters that you are unwanted. See list hygiene.
- Did a recent campaign go to an old or purchased list? One bad send can damage weeks of reputation.
For transactional mail to engaged recipients, this step usually passes. For marketing mail it often explains the problem.
Step 5: look at the content
Content matters less than people think, but it still matters. See spam filter myths for what is outdated. Things that do count:
- Links to domains with poor reputation, including some link shorteners and tracking domains. A shared tracking domain can carry the reputation of other senders. A custom tracking domain helps.
- Mismatches between the visible link text and the destination.
- Image-only messages with little or no text.
- Large attachments or unusual file types.
- A big difference between the plain-text and HTML versions.
- A suspicious pattern, such as a message that looks like a password reset sent in bulk.
Test by sending a plain, short version of the message to the same recipient. If that lands in the inbox, the content is part of the story.
Step 6: check what changed
Placement shifts when something changes.
- Volume suddenly increased.
- A new sending tool or a new IP was added.
- A new domain, subdomain or template went live.
- A list was imported.
- A forwarding setup or a mailing list changed how your mail travels. See how forwarding breaks authentication.
Compare dates with the date the problem started. A cause often sits right beside it.
Step 7: test, but carefully
Seed tests and placement tools show where a message goes for test accounts, not for your users. Use them as a clue, not a verdict. Inbox placement testing: seed lists, panels and limits explains how far to trust them. The strongest evidence is a real recipient at the affected provider, who checks spam and tells you what they see.
What to do once you know
| Cause | What to do |
|---|---|
| Blocklist | Fix the root cause, then request delisting |
| Poor reputation | Reduce volume, send only to engaged people and rebuild slowly |
| New domain or IP | Warm up gradually |
| Inactive list | Prune and re-confirm |
| Shared tracking domain | Move to a custom tracking domain |
| Content patterns | Simplify and rebalance text and links |
| A specific provider | Contact their postmaster channel with evidence |
Change one thing at a time, and wait long enough to see the effect. Reputation recovers over days or weeks, not hours.
Keep it from happening again
- Watch complaint and bounce rates, and alert on changes. See deliverability metrics to alert on.
- Separate marketing and transactional mail on different subdomains.
- Keep your list clean and your volume steady.
- Document what you changed and when.
Key takeaways
- Passing authentication means the sender is identified, not that the message is wanted.
- Diagnose in order: confirm the symptom, read the headers, check infrastructure, reputation, engagement, content and recent changes.
- Use provider tools and a real recipient as evidence, and treat seed tests as clues.
- Change one thing at a time and give reputation time to recover.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


