You've written a compelling email. You've built a quality list. You've crafted a great offer. But if your email lands in the spam folder, none of that matters. Deliverability has tightened considerably. Gmail and Yahoo set bulk sender authentication requirements in February 2024, and Microsoft followed with its own for Outlook, Hotmail and Live addresses, announced in May 2025. All three major consumer providers now expect authentication rather than merely rewarding it. Here's how to protect and improve your deliverability.
βοΈ Industry benchmark: Average email deliverability sits around 85%. That means 15 in every 100 emails you send never reach an inbox. Top performers achieve 95β99% deliverability β the difference is largely technical setup and list hygiene.
Authentication: The Non-Negotiable Foundation
Email authentication protocols tell receiving mail servers that your emails are genuinely from you. All three must be correctly configured: SPF specifies which servers are authorised to send email on behalf of your domain. DKIM adds a digital signature that verifies the email hasn't been tampered with. DMARC tells receiving servers what to do if SPF or DKIM checks fail. Since February 2024 Gmail and Yahoo have required all three for bulk senders, and Microsoft added the same requirement for its consumer domains from May 2025. Providers also expect TLS encryption in transit, and a functional one-click unsubscribe for marketing mail.
Sender Reputation
Email service providers evaluate the reputation of IP addresses and domains used to send emails. High bounce rates, spam complaints, and low engagement rates all damage your sender reputation. Conversely, consistent sending, high open rates and low unsubscribes build a positive reputation that improves deliverability over time.
List Hygiene
Remove hard bounces immediately β sending to invalid email addresses is a major reputation signal. Suppress long-term inactive subscribers who haven't opened an email in 12+ months. Run a re-engagement campaign before unsubscribing cold subscribers: a well-crafted "Are you still interested?" sequence often reactivates 10β20% of dormant contacts.
Engagement and Content Signals
Mail servers increasingly use engagement signals β open rates, click rates, reply rates β to determine inbox placement. Avoid spam trigger words (free, guaranteed, no risk, act now) in subject lines. Use a consistent, personalised "From" name that recipients recognise and trust. Send from a personalised email address rather than a generic noreply@ address.
The Microsoft Requirement Most Senders Missed
Microsoft's bulk sender rules got far less coverage than the Gmail and Yahoo changes, and they catch a lot of Australian businesses whose lists skew toward Outlook and Hotmail addresses.
The threshold is 5,000 or more messages a day to Microsoft consumer domains, which include outlook.com, hotmail.com, live.com and msn.com. Senders above it must pass SPF and DKIM, and have a DMARC record at a minimum policy of p=none aligned with at least one of them. Non-compliant mail from high-volume domains started being routed to Junk from May 2025, with outright rejection signalled as the eventual endpoint. Below the threshold the same setup is strongly recommended rather than enforced, and authenticated mail is treated more favourably regardless of volume.
The good news is that there is no separate work involved. If you already meet the Gmail and Yahoo requirements, you almost certainly meet Microsoft's. Send a test to an Outlook.com address and read the Authentication-Results header to confirm.
Getting the DMARC policy progression right
The most common self-inflicted deliverability disaster is jumping straight to a strict DMARC policy. Publishing p=reject before you know which legitimate systems send on your behalf will silently block your own mail, and the systems people forget are usually the important ones: the CRM, the invoicing platform, the booking tool, the help desk.
Start at p=none and actually read the aggregate reports for a couple of months. Move to p=quarantine once every legitimate sender is authenticating. Only then consider p=reject. One caveat on SPF while you are in there: the record has a ten DNS lookup limit, and exceeding it causes SPF to fail silently rather than loudly, which is a genuinely nasty failure mode if you have accumulated a long chain of includes.
π DigiWolf approach: Our email marketing setup includes full authentication configuration, list hygiene audits and ongoing deliverability monitoring β so your emails reach inboxes consistently. Book a free session to audit your current email setup.