Blog · Deliverability

What Actually Drives Email Deliverability in 2026: Reputation vs. Authentication

If your SPF, DKIM, and DMARC all pass, you expect the email to land in the inbox. Sometimes it does not.

The gap between "authentication passes" and "email delivers" is where most practitioners get stuck. The reason: authentication tells receivers your email is technically authorized. Reputation tells them whether you have earned the right to land in the inbox.

This guide covers what actually drives email deliverability in 2026, what you can measure, and how DMARC aggregate reports surface the specific problems that auth checks alone will not show you.

Authentication Is the Baseline, Not the Destination

Think of SPF, DKIM, and DMARC as a background check. A clean background check does not guarantee entry. It only means you are not obviously disqualified.

SPF validates that the sending server is authorized for the domain. DKIM validates that the message was signed with the domain private key. DMARC validates that at least one of those aligns with the From domain the recipient sees. You can pass all three and still land in spam if your sending reputation is poor.

This distinction matters because practitioners who run auth check tools and see all-green results often cannot figure out why their legitimate transactional email still fails. The answer sits outside authentication entirely.

The Five Signals That Actually Drive Email Deliverability

1. Sender Reputation at Three Levels

Sender reputation is scored by receiving servers based on your sending behavior over time. It operates at three levels simultaneously:

IP reputation - tied to the specific IP addresses you send from. Shared IPs carry the reputation of the worst sender on that range. Dedicated IPs carry only your behavior.

Domain reputation - tied to your From domain. This accumulates based on how receivers have seen your domain behave over months of sending. A domain with no history starts at zero, which behaves similarly to poor reputation.

User engagement signals - opens, clicks, deletes without reading, spam complaints. Both Microsoft and Google use engagement heavily. Low engagement is a stronger spam signal than bad authentication.

A practical note: if you send from a shared IP pool and your deliverability is inconsistent, switching to dedicated IPs with clean history is one of the fastest reputation fixes available.

2. DMARC Alignment: The Difference Between a Pass and a Real Pass

SPF or DKIM passing without alignment is a partial pass. DMARC alignment means the domain that authenticated the message (via SPF or DKIM) matches the From domain the recipient sees.

When your From domain is example.com but your RFC5321.MailFrom is mail.example.com, SPF can pass without alignment. Many receivers treat this as a meaningful signal. A full DMARC pass - where SPF or DKIM aligns with From - is meaningfully stronger. This is why p=reject is the gold standard: it tells receivers to reject mail without genuine alignment.

3. Engagement-Based Filtering

Gmail and Microsoft Outlook both filter heavily on user engagement. Gmail in particular uses machine learning on engagement signals to determine inbox placement. If your recipients consistently delete your emails without opening them, Gmail may route your mail to spam regardless of how clean your authentication is.

You cannot see engagement signals from external receivers directly. What you can see: complaint rates. Microsoft SNDS shows complaint rates per IP. Google Postmaster Tools shows spam rates per domain. A complaint rate above 0.1% is a red flag for both platforms.

4. List Quality and Spam Trap Hits

Old lists with dead addresses generate hard bounces. Hard bounces hurt your reputation because they signal poor list hygiene. More damaging: spam traps. These are dormant email addresses that never opt in to any list. If you are hitting spam traps, your sending practices are being flagged as non-consensual.

Running your list against a verification service before a campaign removes most trap addresses and gives you a clean bounce rate to track over time.

5. Content Signals

Your email content triggers filtering independent of authentication. Common triggers: excessive links, mismatched text-to-image ratios, suspicious URL patterns, and certain keyword combinations associated with phishing. HTML email with mostly images and almost no text looks like phishing to most spam filters.

Content signals are the hardest to diagnose because they are not visible in authentication results. The only way to test them is through seed list testing or A/B subject line testing with inbox placement tools.

How to Diagnose Deliverability Problems Using DMARC Reports

Here is the part most articles skip. Your DMARC aggregate reports show you exactly what receivers see when they evaluate your mail. Without them, you are guessing. With them, you have evidence.

A DMARC aggregate report reveals:

  • Which IPs are failing authentication - not just whether your own systems pass, but who else is sending as your domain
  • Alignment failure rates - what percentage of your traffic fails DMARC alignment, meaning receivers see a technically unsigned or misaligned message
  • Hard fail patterns - whether failures are concentrated in specific subdomains, specific IPs, or spread across your entire sending infrastructure
  • Volume anomalies - sudden spikes in authentication failures that could indicate someone is spoofing your domain at scale

Without aggregate reports, spoofing of your domain damages your reputation silently. You see your own sending systems passing authentication perfectly while a third party sends as your domain to spam lists. That spoofed traffic generates complaints against your domain - complaints you never see because they land in the spoofed recipient's spam folder.

DMARCFlow collects and normalizes these reports automatically. The dashboard shows which domains are failing authentication, which IPs are generating complaints, and whether your alignment rate is healthy enough to support inbox placement. Without this view, you are managing deliverability blind.

How to Check Your Sender Reputation

Microsoft SNDS (Smart Network Data Services)

Free from Microsoft. Sign up with your sending IP addresses. You see complaint rates per IP, your IP categorization (Poor, Elevated, High Risk, Good), and volume anomalies. Updated daily. Start here if you send to Office 365 or Outlook.com addresses.

Google Postmaster Tools

Free from Google. Add and verify your domain. You see domain reputation (Bad, Poor, Medium, Good), authentication rates (should be above 99% for SPF and DKIM), and spam rates (should be below 0.1%). Updated daily with up to a 48-hour lag. The authentication rate metric is particularly useful for spotting alignment problems across your sending domain.

IP Blocklist Checks

Run your sending IPs against SORBS, Spamhaus ZEN, and UCEPROTECT level 3. If your IPs appear on any of these, your deliverability will be degraded across a significant portion of receivers. Delist promptly if found.

When Authentication Passes But Email Still Goes to Spam

This is the scenario practitioners hit most often. SPF passes. DKIM signs. DMARC passes alignment. Everything checks out. Spam.

Shared IP pool - if your marketing platform or ESP uses shared IPs, your reputation is tied to every other sender on that range. One bad actor can damage your deliverability.

Domain sending history - a domain that was dormant or previously used for bulk mail carries a zero or poor reputation until it earns trust through consistent legitimate sending over weeks to months.

Engagement collapse - if open rates dropped because subject lines changed or send frequency shifted, inbox placement may have degraded without any authentication changes. Check your engagement trends before touching your DNS records.

Silent alignment failures - without DMARC reports you may have systematic failures across a specific subdomain that are degrading your domain reputation without showing up in any public tool. This is the most common cause of "everything passes but mail still fails" and the easiest to fix once you have the data.

FAQ

Does passing SPF mean my email will deliver?
No. Passing SPF means the sending server is authorized for the domain. It says nothing about whether the receiving server considers the message trustworthy. SPF-only pass with no DKIM and no DMARC alignment is the weakest authentication result. Aim for a full DMARC pass where either SPF or DKIM aligns with your From domain.

What is a good sender score?
Microsoft SNDS uses categories: Poor, Elevated, High Risk, and Good. Google Postmaster Tools uses: Bad, Poor, Medium, and Good. Aim for Good on both. If your IP is categorized as Poor or High Risk on SNDS, start by checking your complaint rates - high complaints are the primary cause of poor IP categorization.

How do I read Google Postmaster Tools?
Watch three metrics: Domain Reputation (Good is the target - if it is Poor or Bad, your domain has a serious problem), Authentication Rate (should be above 99% for both SPF and DKIM; if it is lower, you have alignment problems), and Spam Rate (keep it below 0.1%). Low authentication rate on Postmaster Tools means a significant portion of your traffic is failing DMARC alignment.

Can a good domain reputation compensate for a bad IP reputation?
Partially. Google weights domain reputation more heavily than IP reputation. Microsoft uses IP reputation more directly. If you are on a shared IP with a poor reputation, moving to dedicated IPs with clean history is the most direct fix. Your domain reputation will transfer with you.

How long does sender reputation take to recover?
Removing yourself from blocklists takes hours to days. Recovering from high complaint rates or engagement problems takes weeks of consistent, wanted sending. Building reputation for a new domain with no history takes months of consistent legitimate traffic. There is no shortcut.

Next Steps

Start with your DMARC aggregate reports. If you are not receiving them at an RUA address, configure your DMARC record to include a reporting address today. The reports are the only direct view into how receivers are evaluating your authentication results.

If you already receive reports but never read them, the first thing to check is your alignment rate. If fewer than 99% of your messages pass DMARC alignment, that is the first problem to fix - because aligned mail is the only mail that can build real domain reputation.

DMARCFlow processes these reports automatically and surfaces the specific IPs, domains, and failure patterns that are hurting your deliverability. Authentication tells you whether your records are correct. DMARCFlow tells you what is actually happening to your mail in transit.