Limited Time: Sign up to get your special offer
Free Tool

Email Deliverability Checklist

A 41-point audit of everything that decides whether your email reaches the inbox — authentication, reputation, infrastructure, sending, content and monitoring. Tick items off as you go and share the result with your team.

Your progress

0 of 41 complete

Progress is saved in this browser only — nothing is uploaded, and clearing site data clears it.

  • SPF names the servers allowed to send for your domain. Without it a receiver cannot tell your mail from a forgery, and past ten lookups the record fails outright.

    Do this: Publish a TXT record at your domain root, then flatten or drop unused includes until you are inside the ten-lookup limit. Our SPF Generator builds the record for you.

  • DKIM adds a cryptographic signature proving the message left your infrastructure and was not altered in transit. Unsigned mail loses a trust signal every major provider looks for.

    Do this: Turn DKIM on in each sending platform, publish the selector TXT record it gives you, and confirm the record resolves before you send.

  • DMARC tells receivers what to do when SPF and DKIM fail, and it is the only one of the three that reports back to you. Gmail and Yahoo now require it from bulk senders.

    Do this: Start at p=none and read the aggregate reports for a few weeks, then move to p=quarantine once legitimate mail passes. Our DMARC Generator handles the syntax.

  • SPF authenticates the return-path, not the From header. If your platform uses its own bounce domain, SPF passes for them while your DMARC alignment quietly fails.

    Do this: Configure a custom return-path in your sending platform — usually a CNAME such as bounce.yourdomain.com — so the envelope sender sits on your domain.

  • A domain that sends mail but cannot receive it looks disposable, and bounce and reply handling breaks when there is nowhere to deliver.

    Do this: Point MX records at your mailbox provider for every sending domain, including the secondary domains used for outreach.

  • BIMI puts your logo beside your messages in Gmail and Yahoo, which lifts recognition. It also requires DMARC enforcement, so it doubles as proof your authentication is finished.

    Do this: Publish your logo as an SVG Tiny PS file, add the BIMI TXT record, and obtain a VMC if you want it displayed in Gmail.

  • Reputation attaches to the domain, not to its owner. A domain previously used for spam arrives pre-damaged, and no amount of warmup clears a listing you did not create.

    Do this: Look the domain up in the Internet Archive and on the major blocklists before you commit to it. If the history is bad, choose a different one.

  • A listing on Spamhaus, Barracuda or SORBS routes your mail to junk at thousands of receivers at once, and nothing bounces back to tell you.

    Do this: Run the domain through a multi-blocklist lookup. If it appears, follow that list's own delisting process rather than waiting it out.

  • The IP is listed separately from the domain, and on a shared pool another sender's behaviour can get it listed without you doing anything wrong.

    Do this: Get your sending IP from your provider, check it against the same blocklists, and escalate to the provider if a pool address is listed.

  • It is the only place Gmail tells you what it actually thinks of your domain — spam rate, domain reputation and authentication pass rates, straight from the receiver.

    Do this: Add and verify your domain in Postmaster Tools with a DNS record, then check the spam-rate graph weekly.

  • Outlook and Hotmail are opaque about filtering, and SNDS is the one feed that shows complaint rates and spam-trap hits for your IPs.

    Do this: Register your sending IPs in Smart Network Data Services and review the complaint-rate column after each campaign.

  • Volume from a domain registered days ago is the pattern filters associate with throwaway spam operations. Age alone buys you the benefit of the doubt.

    Do this: Register the domain well ahead of the campaign and spend the waiting period on authentication and warmup rather than on sending.

  • Reputation services score your sending IP from real receiver data. A low score means you are already being filtered somewhere, whatever your content looks like.

    Do this: Look your sending IP up on a reputation service. If the score is poor, treat list hygiene and volume ramping as the fix, not content edits.

  • On a shared pool you inherit every other sender's mistakes. A dedicated IP makes the reputation entirely yours, which cuts both ways and only pays off at steady volume.

    Do this: Ask your provider which pool you are on. Move to a dedicated IP once you send enough to keep it warm, and vet the pool's reputation if you stay shared.

  • Receivers check that the sending IP resolves back to a hostname on your domain. A missing or generic PTR is grounds for outright rejection at many gateways.

    Do this: Ask whoever controls the IP to publish a PTR record pointing at a hostname on your domain, and confirm the forward record matches.

  • Unencrypted mail can be read in transit, and Gmail flags it with a broken-padlock warning the recipient sees before reading a word.

    Do this: Confirm opportunistic TLS is on at your sending platform, and publish an MTA-STS policy so receivers know to require it.

  • Repeatedly mailing addresses that do not exist is the clearest sign a list was scraped rather than earned, and one of the fastest ways to lose reputation.

    Do this: Configure your platform to suppress hard-bounced addresses on the first failure, and never re-import them from the original source.

  • Gmail and Yahoo require it from bulk senders. Without it, recipients who want out reach for the spam button instead, and complaints cost far more than unsubscribes.

    Do this: Enable the List-Unsubscribe and List-Unsubscribe-Post headers in your platform, then test the link from a real inbox.

  • A feedback loop is how you learn someone marked you as spam. Without one you keep mailing complainers and never find out why your rates are sliding.

    Do this: Enrol your domain and IPs in the Yahoo, Microsoft and Comcast loops, and wire the reports into automatic suppression.

  • Open and click tracking rewrites your links through your platform's shared domain, which thousands of other senders also use and which regularly lands on blocklists.

    Do this: Set up a subdomain such as track.yourdomain.com, point it at your platform, and switch tracking over to it.

  • A brand-new sender opening at full volume is the loudest spam pattern there is. Reputation is built by consistency over weeks, never by one large send.

    Do this: Start around 20 to 50 messages a day and raise volume modestly every few days across two to four weeks. InboxWarm automates the ramp.

  • Every mailbox provider caps daily sends, and crossing the cap gets the account throttled or suspended mid-campaign.

    Do this: Look up the published limit for your plan, set your platform's daily cap below it, and split large campaigns across more days or more mailboxes.

  • A thousand messages leaving in the same second is a machine signature. Human sending is uneven, and receivers rate-limit bursts regardless of content.

    Do this: Enable send-time randomisation in your platform and spread the day's volume across working hours.

  • Replies are among the strongest positive signals a receiver can observe. A no-reply address throws that away and tells recipients you are not listening.

    Do this: Send from a real, monitored address and route team replies into a shared inbox so nothing is missed.

  • Lists decay constantly as people change jobs. Stale addresses become bounces and spam traps, and traps in particular trigger immediate blocklisting.

    Do this: Run the list through a verification service before every send and drop anything invalid, risky or role-based.

  • These streams carry different risk. If cold outreach damages the domain, it takes your password resets and receipts down with it.

    Do this: Keep your primary domain for transactional mail only and run outreach from separate, dedicated domains.

  • The subject is scored for content risk and is the first thing a recipient judges. Hype words, capitals and stacked punctuation add risk with no upside.

    Do this: Keep it under about 60 characters in ordinary sentence case, and run it through our Subject Line Tester before the campaign goes out.

  • A multipart message carrying both parts is what ordinary mail clients produce. HTML-only messages are disproportionately machine-generated, and filters weigh that.

    Do this: Enable the plain-text part in your platform and read it once — auto-generated versions are often unusable.

  • Hiding copy inside a picture is a long-standing way to evade text-based filters, so filters treat image-heavy mail as suspicious by default. It also breaks for anyone with images switched off.

    Do this: Write the message as text and use images only as support. Never send a single large graphic as the whole email.

  • Shorteners hide the real destination, which is exactly why phishing uses them and why filters distrust them. Shared shortener domains also carry other people's reputation.

    Do this: Link to full URLs on your own domain. If you need short links, route them through a branded domain you control.

  • Genuinely personalized mail earns better placement, but a broken merge tag is worse than none — it announces the automation to the recipient.

    Do this: Use merge fields in the subject and opening line, and always send yourself a live preview to confirm every token resolves.

  • Malformed markup is common in mail assembled by spam tooling, so filters score it. It also renders unpredictably across clients.

    Do this: Build with your platform's editor or a tested email template, and validate any hand-written HTML before sending.

  • Link-heavy messages read as promotional or as phishing, and every extra domain you link to is another reputation you are borrowing.

    Do this: Keep one clear call to action, and strip decorative footer and social links from cold outreach entirely.

  • Recognition is what earns the open on your second and third message, and receivers build reputation against the specific pairing of name and address.

    Do this: Choose one From name and one address per campaign and leave them unchanged for its duration.

  • CAN-SPAM and its equivalents require a real mailing address in commercial mail. Leaving it out is both a legal exposure and a signal filters look for.

    Do this: Add your registered address or a PO box to the footer template, alongside the unsubscribe link.

  • Reputation decays when sending patterns change. Warmup keeps a baseline of positive engagement underneath your campaigns instead of only around them.

    Do this: Leave warmup running continuously on every outreach mailbox, including through the quiet periods between campaigns.

  • A seed test tells you where the message actually lands — primary, promotions or spam — before you spend the list finding out.

    Do this: Send the final creative to a seed-test service and fix whatever it flags before launch. Our Spam Test reports placement across the major providers.

  • Reputation problems compound. A drop caught in week one is a small fix; the same drop found a month later has already cost you the domain.

    Do this: Put a recurring ten-minute slot in the calendar to review your platform's dashboard and Google Postmaster Tools together.

  • Nothing tells you when you get listed. Without monitoring you find out from the silence, usually after weeks of it.

    Do this: Register your domains and sending IPs with a monitoring service that emails you the moment a listing appears.

  • These are the two numbers receivers act on directly. Crossing either threshold pushes you toward the spam folder however good everything else is.

    Do this: Check both after every campaign. Treat a high bounce rate as a list problem and a high complaint rate as a targeting or consent problem.

  • Scoring tools run your message through the same rule sets receivers use, so you see the content penalties before your recipients do.

    Do this: Score every new template before its first send and fix the flagged rules. Our Spam Word Checker covers the copy side.

Audited the setup? Keep the reputation from slipping.

A checklist fixes the configuration once. Sender reputation needs upkeep every week — InboxWarm warms your inboxes continuously so the work you just did keeps paying off.

Start warming up free

What is an email deliverability checklist?

An email deliverability checklist is a structured audit of everything that determines whether your messages reach the inbox instead of the spam folder. Deliverability is not one setting — it is domain authentication, sender reputation, sending infrastructure, sending behaviour, message content and ongoing monitoring, all weighed together by the receiving provider. A checklist turns that sprawl into something you can work through and finish.

This audit covers 41 checkpoints across six categories. Each one names the check, explains why receivers care about it, and tells you what to actually do. Tick items off as you complete them — progress is stored in your browser, never uploaded — then copy the whole thing as text or Markdown to hand to whoever owns your DNS.

Why audit deliverability systematically?

1Failures are silent

Filtered mail does not bounce. Without a deliberate audit the first sign of trouble is a reply rate that quietly halved

2One weak link is enough

A missing DKIM record or a blocklisted IP undoes every other thing you got right, and receivers never tell you which one it was

3It makes the work delegable

Most items belong to whoever controls DNS or the sending platform — an exported checklist is a handover, not a conversation

4It gives you a baseline

Re-running the same audit after a provider change or a reputation drop shows you exactly what moved

How to use the deliverability checklist — step by step

1

Start with Domain Authentication and Domain & IP Reputation. If SPF, DKIM and DMARC are wrong or your domain is listed, nothing further down the list will rescue you.

2

Read the reason under each checkpoint before you tick it. The point is knowing why a receiver cares, not collecting ticks.

3

Work through Infrastructure, Sending Practices and Content next. These are where most day-to-day placement problems actually originate.

4

Treat the Monitoring & Maintenance category as recurring rather than one-off — those six items are the ones that catch the next problem early.

5

Copy the checklist as text or Markdown and send it to whoever owns your DNS and sending platform. Unticked items are the work order.

6

Come back and re-audit each quarter, after a provider migration, or the moment reply rates drop without an obvious cause.

Common deliverability mistakes and fixes

Fixing authentication and stopping there

Perfect SPF, DKIM and DMARC will not save a message packed with trigger words sent from a cold domain. Authentication earns you a fair hearing, not a free pass

Treating it as one-time setup

Reputation moves constantly as IPs get listed, lists decay and provider rules change. A setup audited once and never revisited degrades on its own

Ignoring bounce and complaint rates

These are the two numbers receivers act on most directly. Clean lists before every send and make unsubscribing easier than complaining

Sending at full volume after DNS changes

Receivers need time to observe new authentication records. Ramp back up gradually after any change rather than resuming at the old volume

Running every kind of mail from one domain

Cold outreach that damages a domain takes password resets and invoices down with it. Separate the streams before you need to, not after

Auditing without monitoring

A clean audit tells you about today. Without blocklist alerts and a weekly dashboard check, the next problem is found by accident

FAQs

Frequently Asked Questions

Anyone responsible for email reaching an inbox — sales teams running cold outreach, marketers sending campaigns, and engineers who own the sending infrastructure. It is most useful when placement has dropped and you need to find the cause methodically instead of guessing, but it works just as well as a setup guide before a first campaign.

No. Domain Authentication, Reputation and Infrastructure are foundational — work through those completely, because the rest depends on them. Content and Sending Practices vary with what you send; a transactional sender and a cold outreach team will legitimately answer some of them differently. Monitoring & Maintenance items are recurring habits rather than boxes you close once.

Start at the top. Confirm SPF, DKIM and DMARC pass and align, since a failure there caps everything else. Then check whether your domain or sending IP is on a blocklist, which explains sudden drops better than anything else. Only after both are clean is it worth reviewing content and sending volume, which explain gradual declines.

That is what the export is for. Copy as text or Markdown and you get the full checklist with your current tick state, ready to paste into an email, a Slack message or a ticket. The unticked items are the work order, and each one carries the action step, so whoever picks it up does not need the page open.

Progress is saved in your own browser's local storage and nowhere else. It is not uploaded, not tied to an account, and not visible to us or anyone else. That also means it does not follow you to another device or survive clearing site data, and a private window starts fresh each time.

Do a full pass when you first set up sending, and again whenever placement drops without an obvious cause. After that, quarterly is a reasonable cadence for the configuration items, and the six Monitoring & Maintenance items should be running continuously. Always re-audit after changing email provider, moving domains or editing DNS.