Why your emails are going to spam and how to fix it
All dispatches
News30 Sept 202515 min read

Why your emails are going to spam and how to fix it

Sam McNeill
Sam McNeill
Commercial Consultant · Black Sheep Support
Share this dispatch

You’ve spent hours crafting a vital sales proposal or client update. You hit send, confident it will land—only to receive a frantic call days later asking why it never arrived. Your sent folder confirms it went out, yet your client’s inbox is empty. The eventual discovery: it was buried deep in their "Junk" or "Spam" folder, filtered as "suspicious." This isn't merely inconvenient; it costs you time, potential revenue, and can damage professional relationships. Missed opportunities and the perception of unreliability quickly accumulate.

For UK SMEs, this isn’t a minor annoyance; it is a direct threat to your bottom line, your professional reputation, and your operational efficiency. Email remains the primary vehicle for most business transactions. Having your domain blacklisted or your messages automatically shunted to spam is the digital equivalent of your mail being intercepted before it reaches your customer's door. Email deliverability isn’t a matter of chance. It is a technical discipline governed by specific protocols, reputation metrics, and content hygiene. This guide will explain why your emails are failing and provide a roadmap to ensure your business communication lands exactly where it belongs: in the inbox.

What email deliverability actually means

Email deliverability is not simply about whether an email leaves your outbox. It is about whether it successfully arrives in the recipient's primary inbox, bypassing spam filters and avoiding rejection entirely. Many businesses confuse "sent" with "delivered." An email can be sent successfully from your server, but if the receiving server judges it to be suspicious, it might be quarantined, sent to a junk folder, or bounced back completely.

This technical distinction is crucial. Modern email systems employ sophisticated algorithms to protect users from unwanted mail, phishing attempts, and malware. Your emails are scrutinised against a range of criteria, including your domain's authentication records, your sender reputation, and the content of the message itself. Achieving good deliverability means satisfying these criteria consistently, ensuring your legitimate business communications are not erroneously flagged as spam.

Why it matters for UK SMEs

For UK SMEs, consistent email deliverability is fundamental to commercial viability and regulatory compliance. The repercussions of poor deliverability extend far beyond a few missed messages:

  • Financial Impact: Delayed invoices, missed sales proposals, and unconfirmed appointments directly impact your cash flow and revenue. Every email shunted to spam represents a lost opportunity or an unnecessary administrative burden.
  • Reputational Damage: Clients and partners expect reliable communication. When your emails consistently fail to arrive, it erodes trust and makes your business appear unprofessional or disorganised.
  • Operational Inefficiency: Time spent chasing up unreceived emails, resending information, or dealing with client complaints is time taken away from productive work. This is a drain on your resources.
  • Regulatory Compliance: In the UK, the Information Commissioner’s Office (ICO) enforces GDPR and the Privacy and Electronic Communications Regulations (PECR). Poor deliverability, often caused by sending to unverified lists or lacking proper unsubscribe mechanisms, can lead to spam complaints. These complaints not only damage your sender reputation but can also trigger an ICO investigation, potentially leading to significant fines and further reputational harm.
  • Cyber Security Posture: The very protocols designed to enhance deliverability (SPF, DKIM, DMARC) are also foundational cyber security measures. Organisations like the NCSC (National Cyber Security Centre) advocate for these as essential steps for protecting against email spoofing and phishing. Without them, your domain is easier for criminals to impersonate, posing a direct threat to your clients and your own business. Cyber Essentials certification, increasingly a requirement for government contracts and supply chains, mandates robust email security, which inherently includes proper deliverability configurations.

The Foundation: Authenticating Your Domain (SPF, DKIM, and DMARC)

If you haven’t heard of SPF, DKIM, and DMARC, you are likely the reason your emails are hitting the spam folder. These three protocols act as your business's digital passport. Without them, email providers like Gmail, Outlook, and Yahoo have no way of verifying that you are who you say you are. They are not merely suggestions; they are critical components of modern email security and deliverability.

What these protocols actually do:

  • SPF (Sender Policy Framework): This is a DNS record that lists the specific IP addresses and services (like Microsoft 365, Google Workspace, or your CRM's email service) authorised to send emails on behalf of your domain. When a receiving server gets an email from your domain, it checks your SPF record. If the email’s originating IP address is not on your approved list, the SPF check fails, immediately raising a red flag. This helps prevent spammers from forging your email address.
  • DKIM (DomainKeys Identified Mail): DKIM adds a cryptographic digital signature to your outgoing emails. This signature is generated using a private key on your sending server and can be verified by the recipient's server using a public key published in your DNS records. It acts as a tamper-proof seal, ensuring that the content of the email (including attachments and headers) hasn't been altered in transit and that the email truly originated from your domain.
  • DMARC (Domain-based Message Authentication, Reporting, and Conformance): This is the "policeman" that builds upon SPF and DKIM. A DMARC record, also a DNS entry, tells receiving servers what to do if an email from your domain fails SPF or DKIM checks. You can instruct them to:
    • p=none: Monitor failures and send reports without blocking any mail (useful for initial setup).
    • p=quarantine: Send failed emails to the recipient's spam or junk folder.
    • p=reject: Block failed emails entirely. DMARC also provides you with reports on who is sending mail on your behalf, legitimate or otherwise, giving you invaluable insight into potential spoofing attempts and misconfigurations.

For UK SMEs, implementing these is no longer optional. With the rise in sophisticated phishing attacks and email spoofing, major email providers have tightened their authentication requirements significantly. If you do not have these configured correctly, your domain reputation is essentially non-existent, and your messages will be treated as suspicious by default. Frankly, ignoring these is akin to leaving your business premises unlocked.

On a recent client tenant audit, we found a Surrey-based logistics firm with 25 staff had no DMARC record configured, and their SPF record was missing several legitimate sending services, including their CRM and their accounting software's notification system. This led to a significant volume of their outbound emails being rejected or quarantined by major recipients, causing considerable frustration and delays in their operations. Correcting these DNS entries was a priority.

Managing Your Sender Reputation

Email providers assign every domain a "sender reputation score." Think of this as your credit score for the internet. If your score is high, your emails sail through. If it is low, you are automatically flagged and your emails are scrutinised far more harshly, often ending up in spam. This score is dynamic and influenced by a multitude of factors, reflecting how trustworthy your domain is perceived to be by the wider email ecosystem.

How your reputation is damaged:

  • High Bounce Rates: If you frequently send emails to old, invalid, or non-existent addresses, providers assume you are either careless or a spammer harvesting emails. There are two types of bounces:
    • Hard Bounces: Permanent failures (e.g., invalid address). These severely damage reputation and should be removed immediately.
    • Soft Bounces: Temporary failures (e.g., full inbox). While less damaging, a persistent pattern can still be problematic. Regularly cleaning your mailing lists is essential.
  • Spam Complaints: This is one of the most damaging indicators. If users frequently click the "Mark as Spam" button, your reputation plummets. This is often a result of sending unsolicited newsletters, irrelevant content, or failing to include a clear "Unsubscribe" link. Each complaint is a severe negative vote against your domain.
  • Low Engagement: If your emails are frequently ignored, deleted without being opened, or rarely replied to, email providers may infer that your content is not valued by recipients. Conversely, opens, clicks, and replies signal positive engagement, boosting your reputation.
  • Spam Trap Hits: These are email addresses specifically designed to catch spammers. They are usually old, abandoned, or non-existent addresses that have been repurposed. Sending to a spam trap indicates poor list hygiene or that you're using purchased lists, which is a significant red flag.
  • Sudden Volume Spikes: If your domain normally sends 50 emails a day and suddenly sends 5,000, email providers will flag your account for suspicious activity. This can happen if your account is compromised or if you suddenly send a large marketing campaign without warming up your sending IP.

To maintain a healthy reputation, ensure you are only emailing people who have explicitly opted in to receive communications from you. In the UK, this is also a requirement under GDPR and the Privacy and Electronic Communications Regulations (PECR). Unsolicited marketing is not only bad for your deliverability—it is a breach of data protection law and reflects poorly on your business.

Content Hygiene: Writing for Humans, Not Spambots

Sometimes, the technical setup is perfect, but the content itself triggers spam filters. Content filters scan your subject lines and body text for patterns commonly associated with malicious actors or aggressive marketing. These filters are constantly updated, but some common triggers remain consistent.

Common triggers to avoid:

  • Overused "Salesy" Language: Words like "FREE," "ACT NOW," "GUARANTEED," "LIMITED TIME OFFER," "CLICK HERE," or excessive use of exclamation marks (!!!) and capital letters are immediate red flags. While some marketing terms are unavoidable, their overuse, especially in subject lines, will likely land your email in junk.
  • Broken Links or Link Shorteners: Avoid using public link shorteners (e.g., bit.ly, tinyurl) in professional emails. They are often used by phishers to mask malicious destinations. Always use direct, branded links where possible. Ensure all links are functional and lead to reputable websites.
  • Attachment Overload or Suspicious File Types: Sending large attachments or suspicious file types (like .zip, .exe, .js, .vbs) will almost always land your email in the junk folder. If you need to share a file, use a secure cloud link (e.g., SharePoint, OneDrive, Google Drive) that points to the file rather than attaching it directly.
  • Poor HTML-to-Text Ratio or Image-Only Emails: If your email is nothing but a giant image with no discernible text, filters cannot read the content. This makes them nervous, and they will likely hide the email to be safe. Always include a substantial amount of plain text alongside any images. Ensure your HTML is clean, well-formatted, and not overly complex or reliant on obscure coding practices.
  • Spelling and Grammar Errors: While not a direct filter trigger, consistent errors can signal unprofessionalism or a lack of legitimate intent, which can indirectly affect how your emails are perceived.
  • Lack of Plain Text Version: Many email clients will display a plain text version of your HTML email. If this is missing or poorly formatted, it can raise suspicions.

IP Blacklisting and Shared Server Risks

Many SMEs use shared hosting for their email services or might be using a generic Microsoft 365 or Google Workspace IP range. The danger here is "guilt by association." If you share an IP address with a business that is sending out thousands of spam emails, that IP address will eventually be blacklisted by major email providers. When your mail server tries to send an email, the receiving server sees that the IP is on a blacklist and blocks your mail instantly, regardless of how legitimate your content is. This is a common and frustrating issue, as your deliverability is compromised by the actions of others.

How to mitigate this risk:

  • Check your IP health: Regularly use tools like MXToolbox, Spamhaus, or BarracudaCentral to check if your domain or IP is currently on any blacklists. If you find your IP listed, investigate the cause and follow the delisting procedures.
  • Monitor your provider: If you are on a shared IP address, speak to your IT support provider about the reputation of the sending IPs they use. For businesses using Microsoft 365 or Google Workspace, while you're on shared IPs, these providers generally maintain excellent IP reputations. The risk increases with smaller, less reputable hosting providers.
  • Dedicated Mail Gateways/SMTP Relays: For businesses that send large volumes of transactional emails (like invoices, system alerts, or marketing campaigns) separate from their primary business communication, using a dedicated SMTP relay service (e.g., SendGrid, Mailgun) can be highly beneficial. This keeps your primary business email clean and separate from automated traffic, protecting its reputation. A dedicated IP address, if justified by volume, gives you full control over its reputation.
  • Consider a business-grade email service: Generic consumer-grade email accounts or poorly configured self-hosted solutions are far more susceptible to deliverability issues than established business platforms like Microsoft 365 or Google Workspace, which invest heavily in maintaining high sender reputations and robust infrastructure.

The UK Context: Compliance and Best Practice

As a UK-based business, you must operate within the framework of the ICO (Information Commissioner’s Office). Compliance is not just a legal requirement; it is a deliverability asset. Adhering to UK data protection and electronic marketing laws signals legitimacy to both recipients and email providers.

Why GDPR and PECR matter for your inbox:

  • Consent: Under GDPR, you must have a lawful basis for processing personal data, and for marketing emails, this is almost always explicit consent. If you cannot prove that a recipient opted into your mailing list, you are at risk. An angry recipient who reports you to the ICO can cause significant damage to your domain reputation and lead to substantial fines. PECR has specific rules for electronic marketing, including consent requirements for individuals and, in some cases, for corporate subscribers.
  • Transparency: Always include your physical business address, company registration number, and VAT number (if applicable) in the footer of your commercial emails. This is a requirement for commercial emails in the UK and serves as a signal to spam filters that you are a legitimate, traceable entity, not an anonymous spammer. Your privacy policy should also be easily accessible.
  • The Unsubscribe Requirement: You must provide a clear, easy-to-use, one-click way for recipients to opt out of your communications. This link must be functional and process opt-out requests promptly (within a reasonable timeframe, typically a few days). If you make it difficult to unsubscribe, users are far more likely to hit the "Report Spam" button, which is the fastest way to get your domain blacklisted and incur ICO attention.
  • Data Accuracy: Maintaining accurate and up-to-date contact lists helps with both deliverability (fewer bounces) and GDPR compliance (data minimisation, accuracy). Regularly purging inactive or invalid addresses is good practice.

Ignoring these regulatory requirements is not merely a legal risk; it actively undermines your email deliverability. Email providers are increasingly factoring in user complaints and compliance signals when assessing sender reputation.

Common mistakes we see

Even with the best intentions, SMEs often fall foul of common pitfalls that hamper email deliverability.

  • Forgetting to update SPF records: When you switch CRM systems, add a new marketing platform, or change email providers, the SPF record often isn't updated, leading to legitimate emails failing authentication.
  • Not implementing DMARC, or leaving it on p=none indefinitely: While p=none is useful for monitoring, failing to move to p=quarantine or p=reject means you're not fully leveraging DMARC's protection against spoofing and you're missing a key deliverability signal.
  • Purchasing email lists: These lists are notoriously poor quality, full of invalid addresses and spam traps, guaranteeing a swift plummet in your sender reputation.
  • Neglecting list hygiene: Not regularly removing bounced addresses or inactive subscribers means you're continually sending to dead ends, which signals poor sender quality to email providers.
  • Sending emails with a poor sender name: Using generic "info@" or "no-reply@" addresses without a clear, recognisable sender name can reduce open rates and increase the likelihood of being marked as spam.
  • Over-reliance on images in newsletters: Emails composed almost entirely of a single large image are difficult for spam filters to analyse and often get flagged.

Key Takeaways

  • Authentication is non-negotiable: Ensure SPF, DKIM, and DMARC are correctly configured and regularly reviewed. If you are unsure, consult your IT provider immediately.
  • Clean your lists: Regularly audit your contact lists to remove invalid addresses, inactive subscribers, and those who have opted out. Quality over quantity is paramount.
  • Watch your content: Avoid "spammy" buzzwords, excessive capitalisation, and ensure your links are legitimate and transparent. Prioritise clear, valuable communication.
  • Monitor your reputation: Use tools to check if your domain or IP is blacklisted and keep an eye on your bounce rates and spam complaint figures.
  • Prioritise compliance: Adhering to GDPR and PECR is not just about avoiding fines; it is about building trust with your recipients and, by extension, email providers.
  • Email is a moving target: As cyber threats evolve, so do the defences of the major email providers. Regular maintenance by IT professionals is the best way to ensure your business communication remains uninterrupted.

Email deliverability is a foundational aspect of your digital presence. Treating it as a "set and forget" item is a common error, often discovered at the most inconvenient moment. By implementing these foundational security measures and maintaining high standards of communication, you protect your company’s ability to conduct business in the digital age.

When to call in help

If the technical details of DNS records, email authentication, or reputation monitoring seem daunting, or if you are consistently facing deliverability issues, it is time to engage professional IT support. Attempting to troubleshoot these complex issues without the requisite expertise can lead to further misconfigurations, more downtime, and increased frustration. A competent IT partner can audit your current setup, implement necessary changes, and provide ongoing monitoring to keep your email flowing freely.

To take the next step

Book a Discovery Call

Back to all dispatchesEnd of Intelligence · BSS Digital Dispatch
Monthly IT briefing

The three things worth knowing this month

One short email a month: what broke, what got patched, and what we would change in a small business this week. No sales pitch, unsubscribe in one click.

We only use your email for the briefing. See our privacy policy.