Skip to content
From the blog

Why do cold emails go to spam?

Cold emails go to spam for about ten reasons, and the likeliest is authentication that is missing, broken or unaligned, which one email header rules out in two minutes. The table ranks the rest; spam trigger words, the fix almost everyone tries first, come last. The ongoing discipline lives in our cold email deliverability guide.

By Kshitij Maheshwari, co-founder · Updated August 2026 · 13 min read

The ranking

The nine causes, ranked by how likely each is yours

Before you read a row, answer one question: has this mail never landed, or did it land for months and then stop?

Never landed points at rows 1, 2 and 6, which are all setup. Used to land and stopped points at rows 3, 4 and 5, which are all reputation. That fork halves the list. Row 10 is here because everyone asks about it, and it is not a cause.

# Cause How likely it is yours Confirm it in under 10 minutes Where the fix lives
1 Authentication missing, broken or unaligned Highest. The one documented pass or fail gate, and it fails silently. Mail a Gmail address you own, open Show original, and read SPF, DKIM and DMARC. All three should say PASS. The sender requirements
2 A new domain sending at campaign volume on day one Very high on a setup that has never landed. Compare the domain's registration date with your first real campaign. Under three weeks, or a first week that was your biggest, points here. Warmup tools
3 List quality: unverified addresses, bounces, traps High, and the usual answer when mail used to land. Read the hard bounce rate on your last three campaigns, then ask where the list came from. Bought or a year old plus a climbing rate is the answer. Verification tools
4 A complaint rate over the published line High once you are sending at volume. The only cause with a published number. You probably cannot see the number, so read every reply from your last 500 sends instead. The published line is three complaints per thousand. The deliverability guide
5 Volume, pattern, and being classified as bulk Medium to high. This is the lands at Gmail, junks at Outlook split. Split your last campaign's placement by recipient provider, and check whether sends spike on one day of the week. Infrastructure
6 Rented infrastructure carrying someone else's reputation Medium, and rising with every cheap bulk-inbox provider. Look the domain up in Spamhaus's own reputation checker, not a tool that queries a hundred registries. Then find out what it used to be. Infrastructure tools
7 The tracking layer: open pixels and wrapped links Medium, and inconsistent by design, so it gets misdiagnosed. Check whether open tracking is on, and whether links are rewritten to your tool's shared domain rather than a subdomain of your own. Sending tools
8 Message mechanics: HTML weight, images, attachments Medium to low. Documented as score nudges, not verdicts. Mail it to yourself and view the source. A first touch should look typed by a person: no template wrapper, no image header, no attachment. Copywriting
9 The recipient's own filter settings Medium as an explanation, zero as a lever. If placement is fine except at a handful of enterprise domains, stop debugging. Their administrator turned the dial up. Nothing on your side
10 Spam trigger words (not a cause) Lowest, and the first thing almost everybody changes. Nothing to check. No mailbox provider publishes a word list, and the evidence is further down this page. Nothing to fix

Sources: thresholds and requirements from Google's Email sender guidelines, Yahoo's sender best practices and Microsoft's Defender for Office 365 documentation, all checked August 2026. There is no public dataset of how often each cause is the real one in cold email, so this is a diagnostic order, not a measured frequency.

Rows 1 and 4 sit where they do because the mechanics are published; rows 2, 3, 6 and 7 are our judgment, and we would rather say that than invent a percentage.


The framework

Gates, ledgers, and nudges

A mailbox provider asks three questions in a fixed order, and that order is why the ranking looks the way it does.

Definition

Gates, ledgers and nudges names the three layers a filter applies in order: can I tell who you are, then what happened last time you sent, then what does this message look like.

Gates · rows 1 and 2

A published pass or fail

Fail one and nothing else matters: the message is judged before a human sees it. Free to check, and checkable by you.

Ledgers · rows 3 to 6

A running score on your domain

Built from how people react to you. Slow to build, slow to clear, and the reason a setup that landed stops landing.

Nudges · rows 7 to 10

A small penalty on the message

Structure, tracking and weight. Real, but it only bites once the ledger is already thin, which is why it ranks last.

Almost every list of spam causes presents nine equally weighted items. A filter checks the gate before it reads the ledger, and reads the ledger before it looks at your words.


The check

The ten-minute check that rules out half the list

Four lines of one email header settle the likeliest cause on the table, and no page ranking for this question tells you to start there.

Minute 1 · Send one

From the campaign mailbox

Send a normal message from the mailbox your campaigns run on to a Gmail address you control. Not a scoring tool, a real inbox.

Minute 2 · Show original

Read four lines

Open it, choose Show original from the three-dot menu, and read the header block: SPF, DKIM, DMARC, and the DKIM signature domain.

Minute 4 · Check the record

Then look for permerror

Paste your SPF record into any SPF checker. A record over the ten-lookup cap returns permerror, which evaluates as if you had published nothing.

Minute 10 · Split by provider

Gmail is not the whole market

Send the same message to Gmail, to Outlook.com and to a Microsoft 365 domain. Where it lands tells you which half of the table to read.

The tell nobody looks at

SPF and DKIM can both say PASS while DMARC still has nothing of yours to align to. Google Workspace signs your outgoing mail with its own key until you publish one, so the signature is valid and the domain in it is not yours: it ends in gappssmtp.com. An SPF checker never shows you that: it reads DNS and the problem is in the header.


The numbers

The numbers, and where each one comes from

Five figures do most of the work here, and four of them are published by the companies running the filters.

Five numbers, sourced
0.3% and 0.10%

Two Gmail spam-rate numbers, not one

Google's Email sender guidelines require a spam rate in Postmaster Tools below 0.3%, and separately recommend staying below 0.10%. Yahoo's sender best practices publish the same 0.3% line. Most pages collapse the two into one figure. Checked August 2026.

5,000 a day

Where bulk-sender status starts

Google's sender guidelines FAQ counts 5,000 messages a day to Gmail from one primary domain, subdomains included. Microsoft's high-volume sender rules set the same daily figure for Outlook.com, Hotmail and Live.com, enforced from 5 May 2025.

BCL 7, 6, 5

Microsoft's bulk dial, set by your recipient

Microsoft Learn scores every inbound bulk message on a Bulk Complaint Level from 0 to 9, junks at 7 by default and 6 under Standard, and quarantines at 5 under Strict. Your prospect's administrator picks it, and you never see it.

10 lookups

The SPF cap that quietly voids a record

RFC 7208, the SPF standard published in April 2014, limits DNS-querying terms to ten and returns permerror above that. Every sending tool you add spends one, which is how a working record breaks with nobody touching it.

2,000 a day

A lockout ceiling, not a safety line

Google Workspace stops an account sending for up to 24 hours past 2,000 messages a day. It is an account limit, it says nothing about placement, and it is not a per-mailbox cap. Nobody publishes one of those, us included.


The receipts

Spam trigger words: what the evidence says

This is the fix almost everybody tries first, and it is the least likely cause on the table.

What the listicles say

"Avoid FREE, ACT NOW and 400 other words, or your email goes straight to the spam folder."

  • Names no provider, quotes no documentation
  • Describes rules-based filtering from twenty years ago
  • Sends you to the subject line while DNS is broken
What the providers document

"Google and Yahoo publish no word rules, and Microsoft's one word setting targets offensive language and ships off."

  • Requirements cover authentication, DNS, TLS, spam rate
  • Hidden content is named by Google; words are not
  • Keyword scoring lives in one engine your prospects do not run
Five documents, one verdict
1
Google

Nothing about words at all

A full read of Google's Email sender guidelines in August 2026 turns up requirements on authentication, DNS, TLS, spam rate, message format, ramping and hidden content. No word list, and no mention of words.

2
Yahoo

Same structure, same absence

Yahoo's sender best practices ask for SPF or DKIM at a minimum, DMARC and alignment for bulk senders, a spam rate under 0.3%, one-click unsubscribe, and prompt removal of invalid recipients. No lexical rule appears in it.

3
Microsoft

One word setting, and it is not that one

Exchange Online Protection's Advanced Spam Filter carries a Sensitive words control: a dynamic but non-editable list of words associated with potentially offensive messages. That is profanity, not sales language, it is off by default, and Microsoft's own presets leave it off.

4
SpamAssassin

Where keyword scoring genuinely lives

Apache SpamAssassin does score keywords, and it scores them small: its highest keyword rule adds 2.910, against a default threshold of 5 its own docs call quite aggressive. No single word reaches it, and Gmail and Outlook do not run it.

5
The origin

The genre's own source has retracted it

HubSpot's list of roughly 400 spam trigger words, first published in March 2013, is still the most-linked page in the category. Its September 2025 update says filters look at authentication, sender reputation and engagement first.

Content is not weightless. Providers act on hidden text, tracking pixels, remote images and link reputation, and every one of those is documented. What is documented nowhere is a list of forbidden sales words.

Would you rather hand the whole sending setup to the two of us?

Book a Fit Check

The copy that costs you

The three things that actually generate complaints

Copy matters through complaints, not through a word list, and three habits produce most of them.

Don't

Invent a relationship, then hide

Great connecting last week! Following up on our chat about your pipeline.

  • Claims a conversation that never happened
  • Sends from a domain that matches nothing they can look up
  • Offers no way to stop it except reporting you
Do

Say who you are and why them

We have not spoken. You are hiring two SDRs in Berlin, which is why I am writing. Worth ten minutes?

  • Admits the cold open instead of faking history
  • Sends from a domain that resolves to a real company
  • Ends it in one click for anyone who wants out

Every complaint lands on your sender reputation, the honest reason to carry an unsubscribe line long before any rule requires one. M3AAWG has recommended opt-in processes only since its Sender Best Common Practices in 2015, and cold outbound sits outside that, so relevance and restraint are the only levers you own. The craft side lives in the cold email copywriting guide.


What we recommend

Running this check as a two-person team

Every step below runs on free tools, which is the honest answer at founder volume.

01

Before every campaign

One header check per sending domain, one SPF lookup count, and one seed send split across Gmail, Outlook.com and a Microsoft 365 address. Fifteen minutes, and it catches the top of the table.

02

Weekly

Read the hard bounce rate, then read the replies. Angry ones and "how did you get my address" are the visible tip of the complaint rate Google measures and you cannot see.

03

Monthly

A Spamhaus lookup on each sending domain, and a glance at Postmaster Tools. Google suppresses low-volume days to protect privacy, so expect it empty, and do not read empty as clean.

Change one thing, then wait a week. Six changes in an afternoon teach you nothing.

Key takeaways
4 points
  • 1 Read the header before you touch the copy.
  • 2 Split placement by provider before you change anything.
  • 3 At founder volume you are partly blind, so read replies.
  • 4 A burned domain or a blocklist is when you call someone.

Most people do not need a deliverability consultant, they need to read four lines of a header. The cases that genuinely warrant one, a burned domain or a blocklist entry, are covered in our roundup of deliverability agencies.


Not a spam problem

Four things people mistake for a spam problem

Some of what looks like a filtering failure is delivered mail, a lockout, or somebody else's policy.

The Promotions tab

Promotions is delivered mail. Since July 2026 Microsoft tags everything it identifies as bulk with a Promotions label in Outlook too. It means your mail reads as bulk, not that it was blocked.

A Workspace lockout

Past 2,000 messages a day Google Workspace stops the account sending for up to 24 hours. Nothing was filtered. You hit an account ceiling.

One strict gateway

Microsoft stamps "You don't often get email from" on any first message from a new sender, and quarantines bulk mail at BCL 5 under Strict. That is their administrator's dial.

Soft bounces read as rejection

A full mailbox or a temporary defer is not a verdict on you. Hard bounces are the loud signal about a bad list; soft bounces mean try again later.

!
Caution

Never run cold outbound from your company domain

Every other mistake on this page is repairable. The domain your invoices, contracts and support mail run on is not: burn its reputation on a campaign and you are repairing the mail everyone in the company depends on.

Do this instead
Send from separate domains with their own mailboxes and their own warmup, as set out in the cold email infrastructure guide.

FAQ

Questions founders ask

What is the number one reason cold emails go to spam?
Authentication, because it is the only cause that is a documented pass or fail at Google, Yahoo and Microsoft, and because it fails silently. Send one message to a Gmail address you control, open Show original, and read four lines: SPF, DKIM, DMARC, and the DKIM signature domain. All three checks should say PASS and the signature domain should be yours.
Why are my cold emails going to spam all of a sudden?
A setup that used to land and stopped points at reputation rather than setup: list decay and hard bounces, a jump in volume, or complaints from one bad segment. Look at what changed in the last thirty days before you touch DNS. Adding a new sending tool to your SPF record is the one setup change that can break an old domain overnight.
Do spam trigger words really send emails to spam?
No. Neither Google nor Yahoo publishes a word list in its sender requirements. Microsoft's only word-based control targets potentially offensive language and is off by default. Apache SpamAssassin does score keywords, but no single word reaches its threshold, and Gmail and Outlook do not run SpamAssassin: complaints and authentication carry the real score, not word choice.
How many cold emails can I send per day without going to spam?
Nobody publishes that number, including us. Google Workspace caps an account at 2,000 messages a day, but that is a lockout ceiling and it says nothing about placement. Every per-mailbox ramp schedule you have read is practice, not a rule. Google's own guidance is directional: start low, increase slowly, and avoid bursts.
Why do my emails land in Gmail but go to spam in Outlook?
Because Microsoft classifies bulk mail separately and the threshold belongs to the recipient. It junks at Bulk Complaint Level 7 by default, at 6 under the Standard preset, and quarantines at 5 under Strict. Microsoft's Advanced Spam Filter can also flag tracking pixels as high confidence spam, per tenant, which is why the same message lands at one prospect and junks at another.
Does a good spam checker score mean my email will land?
No. Those tools run SpamAssassin plus a set of DNS checks, and SpamAssassin is not the engine your prospects' providers use. No checker can see the reputation a provider holds on your domain, which is the thing actually deciding placement. Treat a score as a formatting check, not a forecast.
Kshitij Maheshwari, co-founder of Real Good GTM
About the author
Kshitij Maheshwari

Co-founder of Real Good GTM. He has been a first business hire and Chief of Staff at seed-stage B2B startups, building outbound pipeline before any playbook existed. Deliverability decides whether the rest of the work counts, so this is the order he works through when a founder says their mail stopped landing.

Connect on LinkedIn

Keep going

Once you know which row is yours

This page triages. These three own the fixes, the rules and the build.

Want outbound that lands without you watching the headers?

Book a fit check. We'll look at how your sending is set up, tell you which row of that table is yours, and say straight out if outbound is not the right motion for you yet.

Book a Fit Check

No hard sell. No fake numbers. Real good work speaks for itself.