New Zapier CRM sync is live — push every reply straight into your pipeline. See what's new

September 6, 2026 · LegalBriefsUSA

Why Your Cold Emails Go to Spam: 11 Causes, Ordered by What Blocks You First

Cold email lands in spam for eleven reasons, and nine of them are infrastructure rather than copy. Since 5 May 2025, Outlook.com rejects mail outright from any domain sending 5,000 or more messages a day without SPF, DKIM and DMARC in place. Gmail and Yahoo apply the same authentication floor and add a hard ceiling of 0.3% on spam complaints. If your reply rate collapsed without a change to your messaging, start with the records, not the subject line.

This is the first article in our deliverability series. Everything below is drawn from the published requirements of Google, Yahoo, Microsoft and Spamhaus, checked on 6 September 2026, with links to each source. LeadButton runs this infrastructure daily across client campaigns, so the ordering reflects what stops mail first, not what is easiest to write about.

What actually decides whether a cold email reaches the inbox?

Four things, in order: whether the receiving server can authenticate you, whether your domain and IP have a reputation, whether recipients complain, and only then what the message says. Google, Yahoo and Microsoft all publish this stack. Authentication is a gate, not a ranking factor. You either pass it or your mail never gets scored on anything else.

The practical consequence is that copy testing is the last lever, not the first. A perfectly written email from a domain with no DMARC record, sent through a shared IP with a Spamhaus listing, will not be read by a human at Outlook.com. It will be refused at the SMTP handshake with a 550 5.7.515 error before the body is ever parsed.

What do Gmail, Yahoo and Outlook require in 2026?

All three now require authentication, a low complaint rate and working one-click unsubscribe from bulk senders. Google and Microsoft both draw the bulk line at 5,000 messages per day from a single primary domain. Google counts subdomains toward the parent domain total, and Google states that bulk sender status has no expiration date once you cross it.

RequirementGmailYahooOutlook.com
Bulk sender threshold5,000 msgs/day per primary domainNot published as a number5,000 msgs/day per domain
SPF or DKIMRequired of all sendersRequired of all sendersBoth required above threshold
DMARCRequired above 5,000/day, p=none acceptedRequired for bulk, p=none acceptedRequired above 5,000/day, p=none accepted
AlignmentFrom: domain must align with SPF or DKIMAlign with SPF or DKIMAlign with SPF or DKIM
Spam complaint ceilingBelow 0.3%, Google advises below 0.1%Below 0.3%Not published as a number
DKIM key length1024 bits minimum1024 bits minimumNot published as a number
UnsubscribeOne-click, honored within 48 hoursOne-click, honored within 2 daysRequired, no published window
Penalty for failing4.7.x deferrals, then rejectionFiltering and blocking550 5.7.515 rejection
Sources linked at the end. Checked 6 September 2026.

Two dates matter for anyone whose numbers changed without warning. Microsoft’s enforcement began on 5 May 2025 and moves non-compliant mail straight to rejection rather than to the junk folder. Google’s published guidance says that from November 2025 it escalates against non-compliant traffic with both temporary and permanent rejections, having previously leaned on 4.7.x deferrals.

Why are my cold emails going to spam when the copy is fine?

Because copy is cause number eleven. Below are the eleven causes ordered by what blocks you first, from a hard SMTP refusal at the top to content problems at the bottom. Work down the list, not up it. The first four account for most campaigns that stopped working after a provider policy change rather than after a copy change.

1. No DMARC record, or SPF and DKIM that do not align

This is a hard refusal at Outlook.com and a rate limit at Gmail. Alignment is the part people miss: SPF or DKIM passing is not enough on its own, the domain in your visible From: header has to match the SPF domain or the DKIM domain. Publish DMARC at p=none first, read the aggregate reports for two weeks, then tighten. Fix time is under an hour of DNS work plus DNS propagation.

2. Sending cold outreach from your primary company domain

Cold outreach generates complaints. Complaints attach to the domain. If that domain is the one your invoices, contracts and support replies go out from, a bad campaign takes your company’s real email down with it. Buy separate sending domains, point them at the main site, and keep the corporate domain out of outbound entirely. This is not reversible after the fact, which is why it sits at number two.

3. A spam complaint rate above 0.3%

Google and Yahoo both publish 0.3% as the ceiling, and Google’s own list of top sender issues advises staying below 0.1%. That is three complaints per thousand delivered messages at the hard limit and one per thousand at the safe one. Google has also stated that senders whose spam rates exceed 0.3% become ineligible for mitigation support, so you cannot appeal your way out of it. Monitor it in Postmaster Tools, which is free.

4. No warmup, or a ramp faster than the receivers tolerate

Google’s published guidance is to increase volume by 25% to 100% per day once mail is delivering, and to wait 15 minutes before retrying after a deferral. A new domain going from zero to a few hundred sends in week one is outside that guidance by a wide margin. Google also asks for consistent daily volume rather than spikes, which means a five-day-a-week campaign that goes silent on weekends is a pattern worth flattening.

5. Too much volume per mailbox

Google Workspace caps a paid user at 2,000 messages and 3,000 external recipients per day, and trial accounts at 500. Those are the provider’s hard caps, not deliverability targets. Reputation degrades far below them. Treat the cap as a ceiling you will never approach and size your mailbox count from your actual daily send target instead.

Daily sends you wantMailboxes at 30/dayMailboxes at 50/dayGoogle Workspace hard cap
3001062,000 msgs/day per user
60020122,000 msgs/day per user
1,20040242,000 msgs/day per user
2,50084502,000 msgs/day per user
The 30 and 50 per mailbox figures are operating choices, not published limits. The arithmetic holds whatever number you pick.

6. Missing or broken one-click unsubscribe

Bulk senders need both the List-Unsubscribe header and the List-Unsubscribe-Post: List-Unsubscribe=One-Click header, per RFC 8058. Google asks that requests be fulfilled within 48 hours and Yahoo within 2 days. A visible unsubscribe link in the body is separately required by Yahoo. Every unsubscribe you make hard to find converts into a spam complaint, which is cause number three.

7. List data that has never been verified

Guessed patterns like first.last@company.com produce invalid addresses, and invalid addresses produce hard bounces that damage domain reputation quickly. Catch-all domains accept everything and tell you nothing, so they need to be segmented and sent to separately. Recycled addresses that have become spam traps are the worst case, because they look like clean deliveries and quietly build a listing against you.

8. Shared IPs and shared sending domains

Google lists this explicitly among its top ten sender issues and advises against using the same IPs and domains across multiple senders. On a shared pool you inherit the worst sender in it. Anyone else’s list buying becomes your reputation problem, and you will not be told when it happens. Dedicated infrastructure costs more and is the difference between a fixable problem and an unattributable one.

9. An active blocklist listing

Spamhaus CSS lists IPs showing low-reputation sending behaviour, and its listings normally expire three days after the last spam detection. Self-removal is available through the Spamhaus reputation checker, but Spamhaus is explicit that an IP will be re-listed immediately if the underlying problem persists. Delisting is therefore the last step of a fix, never the fix itself.

10. Missing PTR records or no TLS

Google requires valid forward and reverse DNS, meaning a PTR record for your sending IP that resolves back to the hostname, and it requires TLS on the connection. Both are baseline requirements for all senders, not just bulk ones. On managed infrastructure these are usually already correct. On a self-hosted VPS they are usually the cause.

11. Content, formatting and misleading headers

Google names misleading display names and subject lines directly, including emoji used to imitate verification badges and a false Re: or Fwd: prefix on a first-touch email. Messages must follow RFC 5322 formatting. Beyond that, the content levers that matter are the ones that reduce complaints: relevance, a plain text-like structure, and a link footprint that does not point at a tracking domain with no reputation of its own.

How do I tell which cause is hitting me?

Read the SMTP response codes first, because the receivers tell you. A 550 5.7.515 from Outlook.com is an authentication failure and nothing else. Gmail’s 4.7.23, 4.7.27, 4.7.29, 4.7.30, 4.7.31 and 4.7.32 family of temporary errors point at authentication, TLS, DNS or DMARC problems and at rate limiting. Set up Google Postmaster Tools on the sending domain, which costs nothing and reports your spam rate, domain reputation and authentication pass rates directly.

If codes are clean and mail is still filtered, the problem is reputation or complaints rather than configuration. That is the point at which seed testing across Gmail, Outlook.com and a Microsoft 365 tenant tells you which receiver you are failing at, and warmup volume and list quality become the variables to change.

How long does it take to get out of spam once you are in it?

Authentication fixes take effect as soon as DNS propagates, usually within hours. Blocklist listings on Spamhaus CSS expire about three days after the last detection, assuming the cause is gone. Reputation recovery is the slow one, because it is a rolling average and the only way to move it is to send lower volume and cleaner lists for weeks. There is no expedite path, and Google states that senders above a 0.3% spam rate are not eligible for mitigation.

In practice, badly burned domains are usually retired rather than rehabilitated. New sending domains cost a few dollars a year and warm up in weeks. That trade is why campaign architecture with multiple sending domains matters more than any single fix on this list.

How LeadButton handles this

We treat sending infrastructure as the product, not as setup. Separate sending domains kept off the client’s corporate domain, SPF, DKIM and DMARC configured with alignment verified before the first send, a warmup ramp inside Google’s published guidance, per-mailbox volume held well under provider caps, Postmaster Tools monitored on every domain, and list verification before a campaign rather than after it. Launch is $1,500 a month for email, and Growth is $3,500 a month for email plus LinkedIn. Both include the infrastructure above; it is not a line item. Pricing is published in full on the LeadButton pricing section.

Sources

Leave a Reply

Back home

Discover more from leadbutton.io

Subscribe now to keep reading and get access to the full archive.

Continue reading