If mail from your own server is landing in the spam folder (or not arriving at all), the cause is almost never one broken checkbox. Receiving mail servers score every message using a mix of who sent it, how it was sent, what it says, and what happened the last hundred times you sent something.
That means deliverability is fixed by changing behaviour over time, not by finding a magic setting. This guide covers the things that actually move the needle, roughly in the order they matter.
SPF, DKIM and DMARC do not guarantee delivery, but missing them is one of the fastest ways to be filtered or rejected outright by Gmail, Outlook.com and Microsoft 365 in 2026. All three are checked by large receiving networks before your reputation is even considered.
- SPF lists which servers may send as your domain.
- DKIM cryptographically signs outgoing mail so it cannot be altered in transit without detection.
- DMARC tells receiving servers what to do when SPF or DKIM fail, and where to send reports.
If you have not set these up yet, do that first: setting up DMARC, SPF and DKIM. Everything below assumes authentication already passes.
A brand-new sending IP or a domain with no sending history has no reputation at all, which large mailbox providers treat with suspicion, not neutrality. Sending a large volume immediately is one of the most common ways self-hosted servers get filtered in the first few weeks.
A reasonable warm-up approach:
- Start with low daily volume to addresses you know are valid and will actually open the mail.
- Increase volume gradually over one to two weeks rather than jumping straight to production traffic.
- Prioritise engagement (opens, replies) over volume in the early period — receiving networks watch what recipients do with your mail, not just whether it was accepted.
- Keep bounce and complaint rates low from day one; a bad start is hard to undo quickly.
Beyond authentication, the signals that most influence whether mail is filtered include:
- Reverse DNS (rDNS/PTR) — your sending IP should resolve to a hostname that matches your mail server, not a generic ISP name.
- Consistent sending patterns — the same IP and domain sending similar volume day to day is trusted more than sudden spikes.
- Bounce handling — continuing to send to addresses that hard-bounce damages reputation fast; remove them.
- Complaint rate — spam button clicks are tracked by major providers through feedback loops and weighted heavily.
- Blocklist status — being listed on a DNSBL is itself a deliverability problem; see how to get delisted from an email blacklist if you think this applies to you.
Authentication and reputation get mail considered. Content and list quality decide what happens next:
- Sending to purchased or scraped lists is one of the fastest ways to accumulate spam complaints and hit spam-trap addresses.
- Mismatched links (display text pointing to a different domain than the actual URL) are a strong spam signal.
- Excessive images with little text, or a single large image as the whole message, reduce trust with content filters.
- Sending the same message unchanged to a large list repeatedly looks automated even when it is a legitimate newsletter.
- A working, honoured unsubscribe path is expected by every major provider and reduces spam-button complaints, which matter more to your reputation than unsubscribes do.
Deliverability problems are far cheaper to fix early than after a week of silent filtering. Worth checking periodically:
- Google Postmaster Tools and Microsoft SNDS/JMRP, if you send meaningful volume to Gmail or Outlook/Hotmail addresses — both report spam rate and reputation directly from the source.
- DMARC aggregate reports, which show you every server claiming to send as your domain, including ones you did not authorise.
- Your own bounce and quarantine logs on the mail server or gateway, which usually show a developing problem before recipients complain.
None of this is a one-off setup task. Treat deliverability as something you check the way you check backups — rarely urgent until the day it suddenly is.
Hexamail Server signs outgoing mail with DKIM and includes bounce and queue logging so degrading delivery is visible before recipients complain. Hexamail Guard sits in front of your mail server and can apply outbound scanning, sender allowlisting from real sent mail, and DNSBL checks so a compromised account or misconfigured relay is caught before it damages your domain's reputation. Neither product can guarantee delivery — no vendor can — but both make the warning signs visible early.