Why emails go to spam and what to do

Why do your outgoing emails land in the Spam folder on the recipient’s side

How does the spam filter work?

What a typical spam filter checks for can be divided into three categories:

  • Where the message came from

Anti-spam organizations have created special network lists called RBLs (Real-time blackhole lists). Spam filter checks such lists for the IP address and the domain name that the message was sent from. If the IP address matches one on the list, the spam score of the message increases, and that’s why the email may land in spam.

  • Who sent the message

Using email headers spam filters check if the email was sent by a spam engine or by a real sender. Every email has a unique ID, but when the spammers send mass emails, they all have the same ID.

  • What the message looks like

The spam filter analyzes the body and the subject of the email. Strings, which can be identified as spam are 'buy now', 'lowest prices', 'click here', etc. Also, it looks for flashy HTML such as large fonts, blinking text, bright colors, and so on. A lot of spam filters compare the whole text to the number of suspicious words. So, for example, if your email is long, it will not be identified as spam because of a few suspicious words.

Things you can do to improve your email delivery

Valid Sender Information

  • Use a recognizable and legitimate sender email address. Avoid generic or suspicious sender names.

  • Ensure that the “From” field accurately represents your organization or brand.

Clear Subject Line

  • Write a subject line that reflects the email’s purpose concisely.

  • Avoid misleading or clickbait-style subject lines.

  • Do not end a subject with a question mark or space.

  • Do not use only uppercase letters.

  • Do not use the words like Test/Testing in the subject.

Structured Email Body

  • Organize your email content into paragraphs or sections.

  • Use headings, bullet points, and numbered lists to improve readability.

  • Do not use too many special symbols, especially at the beginning or at the end of the sentence.

Signature and Contact Information

  • Include a professional email signature with your name, job title, and contact details.

  • A well-formatted signature adds credibility to your email.

Avoid Excessive Links and Attachments

  • Limit the number of hyperlinks in your email.

  • Avoid overloading the email with files.

  • Be careful with the images. It is recommended not to send emails with images only. Make sure you have no less than two strings of text per image.

  • Do not use shortened URLs. Spammers often use those to hide their real URLs.

  • Avoid some types of attachments like .exe, .zip, .swf. It is okay to use .jpg, .gif, .png and .pdf.

NOTE: Attachments are an important factor in spam filtering and overall message evaluation. Certain file types in attachments can increase the spam score of an email. As a result, messages containing such attachments have a higher likelihood of being rejected or filtered. These file types are not directly prohibited, but they are commonly associated with higher risk, which can affect deliverability.

Below you can check a list of attachment extensions that can negatively impact email delivery:

.ace .arj .cue .smi .zpaq .ade .adp .apk .appx .appxbundle .Bat .cab .chm .cmd .cpl .diagcab .diagcfg .diagpack .dll .dmg .ex .ex_ .exe .hta .img .ins .iso .isp .jar .jnlp .js .jse .lib .lnk .mde .mjs .msc .msi .msix .msixbundle .msp .mst .nsh .pif .ps1 .scr .sct .shb .sys .vb .vbe .vbs .vhd .vxd .wsc .wsf .wsh .xll .app .application .appref-ms .msh .msh1 .msh2 .msu .pl .ps2 .py .pyc .pyo .pyw .pyz .pyzw .reg .scf .shs .theme .vhdx .vsmacros .website .ws

Unsubscribe Option

  • The email should be identified as an ad if that is what you are sending.

  • Include an easy-to-find unsubscribe link. Compliance with anti-spam regulations is crucial. Honoring unsubscribe requests builds trust with recipients.

Plain Text Version Alongside HTML

  • Some email clients may not render HTML properly. Including a plain text version ensures accessibility for all recipients.

If it is possible, avoid different colors of the fonts.

Domain Configuration

  • Check SPF, DKIM, and DMARC records. Sender Policy Framework (SPF) records allow domain owners to publish a list of IP addresses that are authorized to send emails on their behalf. The goal is to reduce the amount of spam and fraud by making it much harder for malicious senders to disguise their identity. Domain Keys Identified Mail (DKIM) helps you protect your company from email spamming and phishing attempts. It provides a method for validating a domain name identity that is associated with a message through cryptographic authentication. Domain-based Message Authentication, Reporting, and Conformance (DMARC) helps protect your domain from email spoofing and phishing by defining how unauthorized emails should be handled. Domains without properly configured authentication records are significantly more likely to experience:

    - spam folder placement;
    - delivery delays;
    - reputation-related restrictions;
    - or message rejection by receiving providers.

    We strongly recommend configuring all three authentication methods for any domain used for sending email.

  • Check your IP and domain in blacklists. If your IP or domain is blacklisted you should whitelist it or contact your email service provider before sending emails.

  • If you use a newly registered domain name or it wasn’t used for sending emails before, it’s necessary to warm it up for better deliverability. Feel free to check this guide: How to warm-up your email sending domain

Other recommendations

  • We do not recommend purchasing email lists. It is common practice to purchase lists of potential clients. However, a lot of email addresses in such lists are not correct and your IP/domain can get blacklisted for mass mailing very fast. It is better to send individual emails to real people.

  • Check how your emails are delivered. You can create different email accounts with popular email providers like Google, Yahoo, and so on and send test emails to them.

  • Send the emails to your clients on a regular basis and instruct your recipients on how to whitelist your email address.

Why you can receive spam in incoming emails

Although anti-spam systems are quite advanced nowadays and should block about 90,9% of spam emails, it’s important to note that no system is perfect enough to block 100% of spam emails for all users (at least for now).

When an email containing spam is incorrectly identified as a legit one and is delivered to Inbox it’s called a false negative. For example, links that appear to be of familiar websites, but in fact, lead to phishing websites. So what factors contribute to getting false negatives?

  • A new spam pattern that is not known to the system yet. Since most anti-spam filters use machine learning technology, they constantly learn on the go, meaning that new spam patterns are added to their database for identifying such emails and blocking them. At the same time, spammers do this as well. When they constantly try to adjust to new realities to deceive anti-spam filters, they create new patterns that systems may not identify at once.

  • Subjective content filtering. In some cases, content filtering may get tricky. Where some things are easy to identify, email content is not black and white. Of course, there are known indicators of spam: blocklisted domains, TLDs that are used for sending spam most of all, executable file attachments, or known spam keywords contained in the email. However, content guidelines for spam are always changing, much like our world. That’s what makes it difficult sometimes for anti-spam systems to distinguish whether some email is spam or ham.

  • Users may have different opinions about what is considered spam. The definition of spam can be very subjective to most recipients. Some refer to it as simply unwanted communication (including legitimate advertisements that they no longer wish to receive) even if such emails don’t possess spam factors.

How to identify spam?

These types of emails are not usually considered spam by anti-spam systems and therefore can get to your inbox:

  • Direct marketing and newsletter emails that users agreed to (e.g. subscribed to);

  • Transaction emails (e.g. receipts, confirmations, invoices, etc);

  • Auto-renew or "up for renewal" notices (for the services that you willingly purchased);

  • Email bounce notifications;

  • Messages sent to the recipient by mistake.

At the same time, spam can be recognized by its exaggerated promises, sense of urgency, and commercial aims. Here are a few things to pay close attention to when checking a potential spam email:

  • Sender

First of all, spammers use long email addresses (using free email services like Gmail, Yahoo, etc) that contain a random collection of letters and numbers. For example, ell45704truiw@gmail.com.

In addition, they may impersonate reputable organizations to get access to your data. For example, you may come across fake email addresses that resemble real ones (like, @paypai.com for PayPal or @nelflix.com for Netflix which are not their domains). It is sometimes difficult to spot the difference at once, that’s why it’s very important to look closely at the sender, especially before clicking links in the email or replying to it.

  • Language

Typos, incorrect spelling, obvious grammatical mistakes, or resemblance to a poorly translated text from another language are also obvious identifications of a spam email. Valid promotional emails from reputable sources don’t usually contain such mistakes since they take care of their copy.

  • Links

In general, if you receive an unknown email, don’t hurry to click on any links since it can lead to your data leak or you may just download some virus. Spammers can use shortened URLs (like bit.ly, tinyurl.com, tiny.cc, etc) to disguise the links to fraudulent resources that they use to take your personal information, credit card details, passwords, etc. In some cases, these links may lead to downloading a file on your PC. To secure yourself it’s recommended not to open the links at all if you’re not sure about the sender or check them in an online links checker.

  • Unrealistic claims

If you get an email offering to purchase something at a ridiculously low price or offering a money reward/prize, you’re most likely looking at a spam message. The best course of action would be to delete the email and report it as spam.

A valid email is required