Sequencer, Unibox and CRM are live:send, reply and close from the same login, included on every plan
Use case · Troubleshooting

Why cold emails go to spam: a checklist

A prioritized checklist for why cold emails land in spam: authentication, new-domain reputation, volume per mailbox, bounce rate, content, complaints and shared IPs.

The short answer

Cold email lands in spam for a handful of repeatable reasons, and they should be checked in a fixed order: authentication (SPF, DKIM, DMARC), an unwarmed domain or mailbox, too much volume per mailbox, a list that bounces, content and links, complaints, then shared-infrastructure reputation. EmailPal pauses a campaign automatically when hard bounces pass 5% after at least 200 sends, because a dirty list is the most common fixable cause. No setting guarantees inbox placement.

Work the list top to bottom and stop at the first thing that is broken. Confirm SPF, DKIM and DMARC pass on public DNS; confirm the mailbox has been warmed (EmailPal flags campaign-ready after 14 days of warming); keep cold volume per mailbox low (15 a day is the cap on EmailPal pre-warmed inboxes; the hard ceiling on any mailbox is 100); verify the list so hard bounces stay near zero; keep the first email plain with few links; and keep spam complaints under the 0.1% to 0.3% range Google publishes. EmailPal covers the infrastructure half of this: DNS, warming, verification, bounce guards. The list, the targeting and the copy are still yours.

How it works, step by step

  1. Step 1

    Confirm SPF, DKIM and DMARC pass on public DNS

    Look up the records from a public resolver, not the registrar screen. You need exactly one SPF record, a DKIM key that validates, and a DMARC policy that exists. Fix authentication before changing anything else, because every other signal is weighed after it.

    Check records for example.combash
    dig +short TXT example.com
    dig +short TXT rsa._domainkey.example.com
    dig +short TXT ed._domainkey.example.com
    dig +short TXT _dmarc.example.com
  2. Step 2

    Check whether the domain and mailbox have any history

    A mailbox provisioned this week has no sending history, and unknown senders are filtered harder than known ones. If the mailbox is not warmed, pause campaign volume and warm it, or move the volume to a mailbox that has history.

  3. Step 3

    Cut volume per mailbox

    Count what each individual mailbox sent per day, not what the campaign sent in total. Move to more mailboxes across more domains (2 to 5 per domain) rather than more mail per mailbox.

  4. Step 4

    Verify the list and read the bounce rate

    Run the list through verification and drop invalid, disabled, full and role addresses. Treat catch-all addresses as a separate decision rather than a yes. Resume only when the next batch is clean.

  5. Step 5

    Strip the first email down

    Send plain text or minimal HTML with no attachments, one link at most, no link shorteners, no open-tracking pixel and a working unsubscribe. Test the same message from a mailbox that is known to inbox.

  6. Step 6

    Read complaint and unsubscribe signals

    Complaints are the provider-visible signal you cannot see in most sequencers. If replies say “stop emailing me”, or unsubscribes outnumber replies, the problem is targeting and message, not infrastructure.

  7. Step 7

    Rule out shared infrastructure and blocklists

    Check whether the sending IP or domain is on a blocklist, and whether the same sending pool is also carrying other senders’ bad traffic. A burned domain is retired, not repaired.

  8. Step 8

    Measure placement with seeds and replies, not opens

    Send the same message to your own Gmail, Outlook and Yahoo test accounts, and look at where it lands. Treat human replies as the ground truth. Open rates are inflated by security scanners and are not placement evidence.

01

1. Authentication: SPF, DKIM, DMARC, and alignment

Google and Yahoo’s published sender guidelines (2024) require SPF and DKIM authentication for mail sent to their users, a DMARC policy for bulk senders, and alignment between the visible From domain and the domains that SPF and DKIM authenticate. Fail any of these and mail is rejected or filtered regardless of how good the copy is. Common breakages are two SPF records on one domain, a DKIM selector that was never published, and a From address on a different domain from the one that authenticated.

On domains EmailPal hosts, the records are written automatically and re-verified against public resolvers: SPF with -all, DKIM at rsa._domainkey (RSA-2048) and ed._domainkey (Ed25519), and DMARC p=reject. A strict DMARC or SPF policy does not cause spam placement; it stops spoofing. If you bring your own domain or send through another tool’s SMTP, you own those records and should check them from public DNS.

Test from public DNS

A green check in a registrar screen only proves the nameserver you edited. Check from a public resolver, because that is what Gmail’s lookup sees.

02

2. A new or unwarmed domain and mailbox

A mailbox with no sending history gives providers nothing to score. Jumping from zero to campaign volume is the fastest way to collect negative signals: bounces, spam-folder placements and blocks. Warm-up exists to give the mailbox a small, rising history of real conversations first.

EmailPal warming runs against real accounts at Gmail, Yahoo and AOL for $0.60 per inbox per month and flags a mailbox campaign-ready after 14 days of warming (immediately on the no-ramp profile). That flag is a calendar signal and a guide to risk, not a lock: EmailPal does not stop you sending before it, and a mailbox past day 14 can still land in spam. The step-by-step version is in the warm-up guide linked below.

03

3. Volume per mailbox

Providers cluster senders that suddenly look like a list. A mailbox that inboxed at 5 emails a day during warm-up can look like a new bulk sender the week it jumps to 50. EmailPal caps pre-warmed inboxes at 15 cold emails a day, recommends 15 a day when it exports mailbox credentials, and enforces a hard ceiling of 100 cold emails a day on any mailbox. The ceiling is not a target.

Scale by adding mailboxes, not by raising the number. Fifty mailboxes at 15 a day is 750 sends a day. Spread them across more domains at 2 to 5 mailboxes per domain, so losing one name to a filter does not take the whole campaign with it. Do not send the same body from every mailbox on a domain in the same hour.

04

4. List quality and bounce rate

Hard bounces are the clearest bad signal a sender can produce, and they come almost entirely from the list. Invalid, disabled and full mailboxes bounce. Catch-all domains accept everything at the door and often bounce or silently drop later, so they hide the true bounce rate while still wasting the send. Run the list through verification first: EmailPal list verification (/products/list-verification) returns eight statuses (safe, catch_all, role_account, disposable, inbox_full, disabled, invalid, unknown), and the catch-all guide (/use-cases/catch-all-emails) covers when to send to risky addresses.

EmailPal has two automatic guards. A campaign pauses when hard bounces reach its limit (5% by default, adjustable from 0.5% to 5%) after at least 200 sends. Separately, a mailbox’s campaign sending is paused when 5% of its cold mail is rejected by receiving servers, after a minimum sample, with a warning email at 3%; a resumed mailbox cannot be paused again for 7 days. These are safety nets, not targets: aim for a bounce rate as close to zero as the list allows.

05

5. Content, links and tracking

Identical HTML sent to thousands of recipients, several tracking links, link shorteners, bare-IP links, “limited time” wording and attachments all resemble existing spam. A first email that is short, plain and personal to the recipient gives filters less to match. Do not use a subject line beginning “Re:” or “Fwd:” to imitate a reply.

Open-tracking pixels add a remote image load and measure security scanners as much as people, so open rates mislead. EmailPal’s sequencer deliberately does not offer open tracking; it can count link clicks. Whatever sequencer you use, include a working unsubscribe link. In EmailPal’s sequencer the first email requires one, and it sets the one-click List-Unsubscribe and List-Unsubscribe-Post headers by default. Mail sent through another tool’s SMTP uses that tool’s headers.

06

6. Complaint signals

Google’s published guidance for senders is to keep the user-reported spam rate under 0.1% and never reach 0.3%. Those are provider figures for rates measured in Postmaster Tools, and Postmaster Tools shows nothing until you send meaningful volume to Gmail. In practice: every person who clicks “report spam” is a negative signal that outweighs many opens, so narrow the targeting and write for a specific role rather than widening the list.

EmailPal suppresses a contact permanently after a complaint or unsubscribe, and the campaign keeps sending to everyone else. Complaints and unsubscribes do not pause a campaign automatically, so watch them in campaign analytics yourself.

07

7. Shared infrastructure and burned domains

Mailboxes hosted by a provider send through that provider’s IPs. On shared IPs, another customer’s behavior can affect you unless the provider isolates them. EmailPal runs isolated IP pools so one customer’s list does not define another’s reputation, monitors its sending IPs against blocklists and reduces traffic from addresses that show blocks, and offers a dedicated IP at $20 per month on the Growth and Scale plans.

A new IP does not fix a burned domain, because providers score the domain too. If a domain has earned complaints, the realistic fix is to stop using it and start a new name on a clean, verified list. Check blocklists and Google Postmaster Tools (for domains with enough Gmail volume) before deciding. Treat a random blocklist entry on a brand-new domain as a signal to check, not to panic-rotate.

08

8. How to measure placement

Three measurements are honest. First, seed accounts: send the real message to inboxes you control at Gmail, Outlook and Yahoo and look at the folder. Second, human replies: a reply is proof of inbox delivery that no dashboard can fake. Third, provider tools: Google Postmaster Tools for domain and spam-rate trends once volume is high enough.

EmailPal reports an inbox rate beside every warming mailbox, measured by seed accounts at Gmail, Yahoo and AOL, and attaches that rate to pre-warmed listings. That measures warming traffic, not your campaign. It does not replace testing your actual first email. For dedicated seed-test tools, see the EmailPal vs Folderly and EmailPal vs MailReach comparisons below; EmailPal does not sell a separate seed-test product.

09

Where EmailPal helps, and where it does not

EmailPal helps with the infrastructure causes: automatic SPF, DKIM and DMARC, warming at $0.60 per inbox per month, pre-warmed inboxes with a measured inbox rate, built-in list verification with catch-all detection, campaign and mailbox bounce guards, isolated IP pools, and a launch check that blocks link shorteners and bare-IP links and warns on blank merge variables, spam wording and more than three links.

EmailPal does not help with the causes it cannot see: who you target, what you write, whether the offer is relevant, and whether recipients consider it spam. It cannot guarantee inbox placement at Gmail, Microsoft or Yahoo, it cannot rehabilitate a domain that already earned complaints, and it does not provide a lead database. If the list is scraped and the email is a three-link HTML pitch, no infrastructure fixes it.

The numbers

Limits, prices and names, in one table

The figures this page relies on, so you do not have to hunt for them.

Complaint rate (Google published guidance)Under 0.1%; never 0.3%User-reported spam rate in Postmaster Tools. This is Google’s figure, not an EmailPal guarantee.
Bulk sender definition (Google published guidance)5,000+ messages/day to GmailCold programs below this can still be filtered like bulk. Authenticate regardless.
Campaign bounce auto-pause5% default, 0.5% to 5% adjustableHard bounces only, after at least 200 sends.
Mailbox rejection hold5% of cold mail rejectedWarning email at 3%. A resumed mailbox cannot be paused again for 7 days.
Cold volume per mailbox15/day on pre-warmed; 100/day hard ceilingSpread across 2 to 5 mailboxes per domain.
Campaign-ready flag14 days of warmingImmediate on the no-ramp profile. Informational, not a lock.
Warming$0.60/inbox/moReal Gmail, Yahoo and AOL accounts. Included on pre-warmed leases.
Pre-warmed inbox$3/mo, 90-day minimum15 cold emails a day from day one. Domains aged 90+ days.
DNS written automaticallySPF -all, DKIM RSA-2048 + Ed25519, DMARC p=reject
Dedicated IP$20/moGrowth and Scale plans only.

Checked against the product and the API on . Plans and limits change, so confirm in the docs before you build on them.

This is not for you if

  • You need a guaranteed inbox placement rate. No sender can promise one, and EmailPal does not.
  • Your problem is the list or the offer. Infrastructure checks will pass and mail will still be reported as spam if the targeting is wrong.
  • You need legal advice on cold email rules such as CAN-SPAM or GDPR. This page covers deliverability, not compliance.
  • You need a full seed-testing and inbox-placement monitoring suite for existing mailboxes. A dedicated deliverability tool does that; EmailPal measures placement during warming and does not sell a separate test.
  • Your domain is already burned or blocklisted. The fix is a new name and a clean list, not more volume or a new IP.
FAQ

Common questions

Why do my cold emails go to spam even though SPF, DKIM and DMARC pass?

Authentication only proves who sent the mail. Providers then judge reputation, volume, bounce rate, complaints and content. If authentication passes, check in order whether the mailbox was warmed, how many emails each mailbox sent per day, whether the list bounced, and how many links the first email contains.

How many cold emails can I send per mailbox per day?

Keep it low. EmailPal caps pre-warmed inboxes at 15 cold emails a day, recommends 15 a day when it exports mailbox credentials, and enforces a hard ceiling of 100 on any mailbox. Add mailboxes across more domains for more volume instead of raising the per-mailbox number.

What bounce rate is too high for cold email?

Aim for as close to zero as verification allows. EmailPal pauses a campaign when hard bounces reach 5% by default after at least 200 sends, and the threshold can be lowered to 0.5%. Treat that pause as a safety net, because providers see bounces before any dashboard does.

Does open tracking cause emails to go to spam?

It can contribute, and it makes results harder to read. A tracking pixel adds a remote image request and open counts are inflated by security scanners. EmailPal’s sequencer deliberately does not offer open tracking. Judge placement from seed tests and replies instead.

Will a new IP address fix a domain that lands in spam?

Usually not. Providers score the domain as well as the IP, so swapping the IP under a domain that earned complaints rarely helps. Stop using the burned name, verify the list, and start a new domain with warming.

Can EmailPal guarantee my emails land in the inbox?

No. EmailPal handles authentication, warming, verification and bounce guards, and shows measured inbox rates during warming. It cannot control what recipients mark as spam or how Gmail, Microsoft and Yahoo score your content and list.

Build it on infrastructure that holds up

Domains, mailboxes, warming and verification over one REST API and MCP server, with the sequencer, Unibox and CRM on every plan.

No card to start — cancel any time.