The layers

Filtering happens in stages. At the connection layer, the receiver checks the sending IP against blocklists and its own reputation data before accepting a single byte. At the authentication layer it evaluates SPF, DKIM and DMARC. At the reputation layer it weighs your domain history and recipient engagement. At the content layer it examines the message itself — links, images, formatting, the domains you reference.

Failing early is worse than failing late. A connection-layer rejection means the message never arrives at all; a content-layer penalty just moves it to spam.

Gateways in front of the mailbox

Many businesses put an appliance ahead of their mail provider — Proofpoint, Mimecast, Barracuda and others. These take the MX position, so mail is filtered by them before Microsoft or Google ever sees it, and they apply their own much stricter rules.

This matters because the fix differs. A Google spam placement and a Proofpoint block are different problems, and treating a gateway rejection as a Google reputation issue wastes weeks. Checking what sits in front of the mailbox should be an early step in any diagnosis.

What content filtering actually looks at

Less than folklore suggests. Individual trigger words matter far less than people believe. What matters more: link domains and their reputation, the ratio of images to text, whether tracking is on a domain nobody trusts, URL shorteners, and mismatches between the visible link text and its destination.

Your tracking domain is part of your content. A shared click domain used by every other customer of your sending tool is one of the most commonly overlooked content-layer problems in cold email.

Check yours

These run free in your browser. Nothing you type reaches a server.

Common questions

Do spam trigger words still matter?

Far less than the folklore claims. Reputation and authentication dominate. A trusted sender can write 'free' without consequence; an untrusted one will land in spam with immaculate copy.

How do I know which layer is failing me?

Read the headers of a message that landed badly. They contain the receiver's actual SPF, DKIM, DMARC and often spam-score verdicts, which tells you which layer objected instead of guessing.

Why does the same email land differently for two recipients?

Because they are behind different filters with different reputation data and different engagement histories with you. Placement is per-recipient, not per-message.

Next

Related concepts

How I measure this on client accounts

Everything above is diagnosis. To confirm a fix worked you need placement data — seed accounts across the major providers, plus the DMARC aggregate reports read as a trend rather than a wall of XML. GlockApps is what I run for both.

See GlockApps →Affiliate link — it costs you nothing and help keep these tools free. Everything I use →
When it is broken

If this is the thing going wrong

The pages explain it. If you would rather it was simply fixed, that is the work I do.

← All conceptsEmail authenticationReputationDeliveryInfrastructureBook a call →
Back to top