RUN THE PROGRAM · Chapter 4

Email deliverability, explained for an owner.

Email deliverability is the practice of keeping messages out of spam and the Promotions tab, so the subscribers who asked to hear from the business actually read what the business sent. Since February 2024, Gmail, Yahoo, and Microsoft have made DMARC authentication, one-click unsubscribe, and a 0.3 percent complaint-rate ceiling hard requirements for bulk senders. For an SMB owner, this chapter covers the seven checks every program should pass before the next send goes out.

KEY TAKEAWAYS

  • SPF, DKIM, and DMARC are three DNS records the sending domain must publish. All three. In 2026, the hard requirements apply to any domain sending bulk mail.
  • Spam complaint rate ceiling is 0.3 percent, with a target under 0.1 percent. A single send above the ceiling degrades reputation for weeks.
  • Google Postmaster Tools shows the sending domain's reputation at Gmail. Free, 1-hour setup, checked weekly.
  • Shared IPs are the right default below 100,000 messages per month. Spend the time on domain authentication and list hygiene instead.

The seven checks every SMB sender should run

Run this list once before the first send on a new domain, then every quarter afterward. Any check that is failing goes on this week's fix list.

CheckWhat it confirmsHow to verify
SPF record publishedThe sending domain's DNS lists the sending service as an authorized sender. Required by Gmail and Yahoo for any sender over 5,000 messages per day to their users.Query the domain's TXT records for 'v=spf1'. The record must include the sending platform's include mechanism and end in '-all' or '~all'.
DKIM key published and signing activeEach outgoing email carries a signature that proves it was sent by the domain's authorized platform and has not been tampered with in transit.Send a test email to a Gmail address, open the raw headers, and confirm the DKIM-Signature header shows pass. The sending platform's dashboard also shows the DKIM status.
DMARC policy published at p=none or stricterThe domain owner has published a policy telling mailbox providers what to do with mail that fails SPF or DKIM. Required by Gmail and Yahoo for bulk senders.Query the TXT record at _dmarc.yourdomain.com. Policy must be at least p=none with a rua= reporting address. Move to p=quarantine once reports are clean.
List-Unsubscribe header enabledGmail and Yahoo require one-click unsubscribe (RFC 8058) on bulk mail. The platform must send both the mailto: and List-Unsubscribe-Post headers.View headers on a received message. Confirm 'List-Unsubscribe: <mailto:...>, <https:...>' and 'List-Unsubscribe-Post: List-Unsubscribe=One-Click' are both present.
Spam complaint rate below 0.3 percentFewer than 3 complaints per 1,000 delivered messages. Google states senders should stay below 0.1 percent, with 0.3 percent as the hard ceiling.Check Google Postmaster Tools (postmaster.google.com) weekly for the domain. The spam rate graph shows the exact figure.
Bounce rate under 2 percentMost sends reach a valid address. A rising bounce rate means list hygiene is slipping, which lowers inbox placement for the good addresses too.The sending platform's campaign report shows the bounce percentage per send. Investigate any send above 2 percent before sending again.
Sender reputation on Google Postmaster ToolsGoogle rates the domain reputation as High, Medium, Low, or Bad. Medium or lower routinely means inbox placement is already degraded, not that it is at risk.Open Postmaster Tools, verify the domain, and check the Reputation report. Confirm the domain is at least Medium and trending toward High before scaling send volume.

What SPF, DKIM, and DMARC each do, in plain language

SPF (Sender Policy Framework)

SPF is a DNS record that lists which services are allowed to send mail for the domain. If someone else tries to send mail claiming to be from the domain, the recipient's mail server can check SPF, see the sender is not on the list, and treat the message as suspicious. Published as a TXT record, example: v=spf1 include:_spf.google.com include:mail.hubspot.com ~all. The two things that break SPF most often: forgetting to include a new sending platform (invoices, support, newsletters), and leaving old services on the list after switching away from them.

DKIM (DomainKeys Identified Mail)

DKIM is a cryptographic signature attached to every outgoing message, which proves the message was actually sent by the authorized platform and has not been altered in transit. Setup is on the sending platform: it generates a public key, the domain owner publishes it as a DNS record, and the platform signs every outbound message with the matching private key. Every major sending platform has a setup page that walks the owner through it. The verify step is sending a test email to a Gmail address, opening the raw headers, and confirming "DKIM-Signature" shows "pass".

DMARC (Domain-based Message Authentication, Reporting, and Conformance)

DMARC is the policy that tells mailbox providers what to do when a message fails SPF or DKIM, and where to send the daily report. It has three enforcement levels: p=none (just report, don't block), p=quarantine (route failures to spam), and p=reject (reject failures entirely). The right rollout is p=none for two to four weeks while fixing anything the reports flag, then p=quarantine, then p=reject once reports are clean. Starting at p=reject before confirming the reports are clean silently rejects legitimate mail from authorized sources (calendar invites, invoices, support tickets).

The warm-up for a new sending domain

A new sending domain has no reputation at Gmail, Yahoo, or Microsoft. The first few sends are how it builds one. The warm-up protocol:

  1. Week 1: 500 to 1,000 messages per day, sent only to fully-engaged subscribers (opened or clicked something in the last 30 days).
  2. Week 2: Double the daily volume if the previous week's complaint rate stayed under 0.1 percent. Still only to fully-engaged subscribers.
  3. Week 3: Expand to the lightly-engaged segment (opened or clicked in the last 90 days). Continue doubling daily volume if complaints stay clean.
  4. Week 4: Steady-state volume. Dormant subscribers remain excluded until they re-engage through the re-engagement flow.

Breaking the warm-up (sending the first large batch to an imported list, for example) spikes complaints and locks the new domain into a bad reputation at Gmail before it has had a chance to earn a good one. The cost to recover from that is roughly four to eight weeks of degraded deliverability.

Best for
  • Any sender over 1,000 messages per day. The 2024 Gmail and Yahoo rules apply before you reach the 5,000 ceiling in practice, because enforcement is domain-wide.
  • Senders launching a new domain or migrating from one platform to another. Warm-up protects the reputation of the new setup.
  • Programs where transactional mail (invoices, receipts, password resets) ships from the same domain as marketing. One deliverability program protects both.
Fails when
  • The owner delegates DMARC setup to a tool promising 'one-click enforcement' without reviewing reports. p=reject on an unaligned source still rejects legitimate mail.
  • The sending domain was recently on a blocklist and the cause of the listing (bought list, cold outbound from marketing domain, misconfigured platform) has not been removed.
  • Transactional and marketing mail share one sending identity and a bad marketing send takes down password resets.
Verify before
  • Google Postmaster Tools shows the domain at Medium or High reputation, not Low or Bad.
  • A test send to a Gmail address shows SPF: pass, DKIM: pass, DMARC: pass in the raw headers.
  • The sending platform's dashboard shows List-Unsubscribe and List-Unsubscribe-Post headers active on every outbound message.

Common questions.

What are the SPF, DKIM, and DMARC settings for an SMB sender?

+

SPF, DKIM, and DMARC are three DNS records the sending domain must publish for mail to reach the inbox at Gmail, Yahoo, and Microsoft. SPF lists which services are allowed to send mail for the domain. DKIM signs each outgoing message so the recipient can verify it came from the authorized platform. DMARC is the policy telling mailbox providers what to do when a message fails SPF or DKIM, and where to send reports. All three are hard requirements for any sender over 5,000 messages per day to Gmail or Yahoo users, as of February 2024. For an SMB sender below that volume, publishing all three is still the baseline, because the policies are becoming universal.

What is a safe DMARC policy for a small sender?

+

A safe starting DMARC policy for a small sender is p=none with a rua= reporting address, which asks mailbox providers to send authentication failure reports without changing how any mail is treated. After two to four weeks of clean reports (no legitimate sources failing authentication), the policy moves to p=quarantine, which routes failures to spam. After another two to four weeks of clean reports, the policy moves to p=reject, which rejects failures entirely. Starting at p=reject before confirming reports are clean is the single most common deliverability mistake, because it silently rejects legitimate mail from authorized but unaligned sources (invoices, calendar invites, support systems).

What is the spam complaint rate ceiling for a sender in 2026?

+

The spam complaint rate ceiling for a sender in 2026 is 0.3 percent, as published by Google in its bulk sender guidelines, with a target of staying under 0.1 percent on healthy sends. A send that crosses 0.3 percent complaint rate has its sender reputation downgraded at Gmail, which routes future mail to spam or the Promotions tab for days to weeks afterward. The practical implication: a single bad send to a stale segment can degrade deliverability for every subscriber on the domain. The protection is to exclude dormant segments from broadcasts, cap send volume growth to 50 percent per week during warm-up, and watch Google Postmaster Tools weekly.

What is Google Postmaster Tools and how do I use it?

+

Google Postmaster Tools (postmaster.google.com) is Google's free dashboard showing a sending domain's reputation at Gmail. It reports spam complaint rate, delivery errors, authentication pass rate, and overall domain reputation (High, Medium, Low, Bad). Setup takes one hour: verify the sending domain by publishing a DNS record Google provides, wait 24 to 48 hours for data to populate, then check it weekly. For an SMB sender, this is the single most useful deliverability tool and it costs nothing. Microsoft and Yahoo offer similar programs (SNDS for Microsoft, Yahoo Sender Hub), both worth signing up for.

How do I warm up a new sending domain?

+

A new sending domain is warmed up by increasing send volume gradually across the first two to four weeks, starting at 500 to 1,000 messages per day and no more than doubling the daily volume per week. The warm-up should go to the most engaged segment of the list first (fully-engaged, recent subscribers), because high open and click rates on early sends signal to mailbox providers that the new domain is legitimate. Sending the first large batch to a cold or imported list spikes complaints, which assigns the new domain a bad reputation at Gmail before it has had a chance to earn a good one.

What happens if the sending domain is already on a blocklist?

+

If the sending domain is already on a blocklist (Spamhaus, SURBL, SpamCop, Barracuda), the practical first step is checking which specific list through a free multi-blocklist checker such as MXToolbox. Most blocklists have a self-service de-listing process that takes 24 to 72 hours. The important part is identifying what caused the listing first, because a de-listing without a fix (removing the bad list source, improving list hygiene, pausing the problematic sequence) results in a relisting within the week. Repeated listings make de-listing harder each time.

Do shared sending IPs cause deliverability problems?

+

Shared sending IPs rarely cause deliverability problems for an SMB sender below 100,000 messages per month, because the sending platform (HubSpot, Mailchimp, Klaviyo) manages the IP pool's reputation. The sending domain's own reputation is what matters at the mailbox provider, not the IP. Dedicated IPs are worth paying for only above 500,000 messages per month, where the sender has enough volume to maintain the IP's own reputation. For a 10 to 50 person B2B company, shared IPs are the right default; the deliverability work goes into domain authentication and list hygiene instead.

What is the one-click unsubscribe requirement, and how do I implement it?

+

One-click unsubscribe is RFC 8058, which requires bulk senders to honor an unsubscribe request made by a single click or HTTP POST, without a confirmation page. Gmail and Yahoo made this a hard requirement for senders over 5,000 messages per day, as of February 2024. Implementation is on the sending platform's side: it must emit two headers on every outbound message, List-Unsubscribe (with both mailto: and https:/ URIs) and List-Unsubscribe-Post: List-Unsubscribe=One-Click. Every major sending platform supports it. The owner's job is to verify the headers are being sent, by viewing the raw headers of a received message after the next send.

NEXT CHAPTER

Automating the four flows that generate the revenue.

With deliverability sorted, the next question is which automated flows to build first. The Lifecycle Automation chapter covers the four flows that produce almost all the revenue an SMB email program earns.

Official sources

← Back to the email-marketing-for-smbs guide