Why Cold Emails Land in Spam: A One-Day Deliverability Audit
Cold emails hit spam for technical, behavioral, and content reasons. Here is a one-day audit protocol that works without paid tools.
Cold emails land in spam for three groups of reasons: technical (missing or misconfigured DNS records, a young or damaged sending domain), behavioral (sudden volume spikes, recipient complaints, dead addresses in the list), and content-based (one mass template, link shorteners, attachments). Almost always it is a combination rather than a single cause, which is why swapping a couple of words in the subject line never fixes anything.
You can run the diagnosis yourself in one working day, without paid deliverability monitoring. Western audit guides lean on seed-list services, but if you sell into Russia and the CIS, those tools have a blind spot: their seed networks barely include Yandex and Mail.ru, the two platforms that dominate business inboxes there. Your main instrument is a handful of your own test mailboxes on Yandex, Mail.ru and Gmail, a manual DNS check, and reading what the receiving mail servers actually answer. Below is the full protocol, step by step.
Three groups of causes: how the spam decision is made
The receiving platform decides a message's fate before a human ever reads it. It looks at three things: who the sender is (the technical layer), how the sender behaves (sending statistics), and what exactly is being sent (the content).
Technical causes
The first check is the sending domain's DNS records. SPF lists the servers allowed to send on the domain's behalf, DKIM signs the message with a cryptographic key, and DMARC tells the receiving side what to do with a message that fails verification. Since early 2024, Google and Yahoo require bulk senders to have all three configured, plus one-click unsubscribe and a complaint rate kept very low — in practice this has become the minimum standard for any domain used for outreach. Yandex and Mail.ru check signatures no less strictly, so a setup that passes Gmail can still fail where your Russian-market recipients actually read their mail.
The second technical cause is the domain itself: too young, with no history, or carrying a history of complaints. Filters treat it the way a bank treats a borrower with no credit history — not a fraudster, but zero trust. A separate classic mistake is sending outreach from your main corporate domain: if its reputation drops, your ordinary client correspondence starts landing in spam too.
Behavioral causes
Here the platform reads the statistics:
- volume spikes: yesterday the domain sent ten messages a day, today it sends three hundred;
- complaints: every "this is spam" click is a direct signal — rare on addressed business correspondence, frequent on impersonal mass sends;
- silence: messages unopened, unanswered, deleted unread;
- bounces: a high share of non-existent addresses tells the filter the list was bought or scraped, not built.
Behavioral reputation takes weeks to earn and weeks to burn. If the domain is already damaged, simply pausing sends is not enough.
Content causes
The "spam word" lists from older guides matter less today than people assume — filters have long been behavioral. But content still works as a marker of mass sending. Identical text sent to a thousand recipients is recognized as a template no matter how many synonyms you rotate in. Risk goes up with link shorteners, several links in a first touch, attachments, image-only messages, and heavy newsletter-style HTML.
There is also a legal watershed that happens to coincide with filter logic. If you email into Russia, know that local advertising rules treat unsolicited promotional email as advertising that requires the recipient's prior consent — and the practical consequence is simple: an impersonal mass blast both looks like advertising and is exactly what draws complaints, while a specific business proposal addressed to a particular company about its own line of work is a different category. On the data side, a person's name, title and work email count as personal data, so the safer practice is to write to corporate addresses like info@ or sales@, take contact data from open sources, keep an opt-out registry, and remove any contact on first request.
The one-day audit: protocol
| Step | What to do | What you should end up with |
|---|---|---|
| 1. DNS | Check SPF, DKIM, DMARC manually or with any free DNS checker | Exactly one SPF record including your sending service, a valid DKIM signature, a DMARC record at least in monitoring mode |
| 2. Test mailboxes | Create or locate mailboxes on Yandex, Mail.ru, Gmail, and a corporate server | 4–5 addresses across different platforms |
| 3. Control send | Send the real campaign email from the production domain, as-is | The message in its original form, no edits "for the test" |
| 4. Read the result | Check where the message landed and open the headers (Authentication-Results) | Per mailbox: inbox/spam/not delivered, plus pass/fail for spf, dkim, dmarc |
| 5. Bounce analysis | Read the error texts in bounce messages | The receiving servers' own wording |
| 6. Behavioral summary | Volumes and sending dynamics over the past 2–4 weeks, complaints, bounce share | A clear picture of whether there were spikes |
A few notes on the steps.
Step 1. There must be exactly one SPF record — two TXT records starting with v=spf1 break the check entirely. Verify DKIM not "in the service settings" but by the actual signature in the headers of a delivered message.
Step 3. The test is meaningless if you send "hi, this is a test." The filter evaluates a specific text from a specific domain, so send the production message.
Step 4. Message headers open in any web interface ("message properties", "show original"). The Authentication-Results line honestly shows which checks passed — the fastest way to spot a technical breakage.
Step 5. Yandex and Mail.ru write the blocking reason in plain language inside the bounce, with a code and an explanation. That is a ready-made field report: don't guess, read.
How to read the results
- Spam everywhere, including a fresh test mailbox that never complained — a technical problem: the records or the domain's overall reputation.
- Inbox on one platform, spam on another — reputation has dropped selectively; that is a behavioral history with a specific platform.
- Messages not delivered at all, with a bounce describing a block — the domain or IP is on the platform's block list; there is no spam folder anymore.
- The test message arrived, but the campaign is in spam — the problem is mass-ness: the template was recognized, or behavioral signals triggered at volume.
What to do next
Fix in the same order: technique → behavior → content. Configure the records, drop volume to dozens of messages a day and grow gradually (this gradual ramp-up is what warming a domain means), clean the list of dead addresses, and rewrite the email as addressed business correspondence: one recipient, one question, no attachments, minimal links. If the domain is burned to the ground, it is more honest to register a new one for outreach and not repeat the old mistakes — and the main corporate domain should stay out of cold sending entirely.
Keep the legal frame from the content section in mind as well: addressed sending is not only about filters, it is about the message not looking like unconsented advertising. For more on how we build outreach that survives these checks, see our other field notes.
FAQ
My emails land in spam only for some recipients. Why?
Reputation is computed at several levels: the domain overall, the domain in the eyes of a specific platform, and even the individual mailbox — if a person once clicked "this is spam" or, conversely, moved your messages to the inbox. A mixed picture of "inbox for some, spam for others" is normal when reputation sits on the borderline.
Should I buy the paid deliverability services from Western guides?
They are built on seed-list networks that barely include Yandex and Mail.ru — and for Russia-facing B2B those two platforms decide the outcome. Your own four test mailboxes give a more honest picture at zero cost. Paid monitoring makes sense only when a visible share of your recipients is on Gmail and Outlook.
Is it true that filters hunt for spam words in the subject line?
As a standalone mechanism, mostly a myth. Subject and body work through template recognizability and through recipient reactions. The same "catchy" subject blasted to thousands hurts not because of its words but because of its mass-ness.
Does a cold email need an unsubscribe link?
For bulk sending to Google and Yahoo, one-click unsubscribe is a hard platform requirement. In an addressed business email, an honest line along the lines of "if this is not relevant, tell me and I won't write again" is enough — but you must keep that promise: maintain an opt-out registry and remove the contact on first request.
How many emails a day can one domain send?
No platform publishes an exact limit; this is our estimate from practice: a working order of magnitude is dozens of messages per day per domain, not hundreds. The dynamics matter more than the absolute number — filters notice a sharp volume increase faster than a stable level.
If you want us to look at your situation, send us a sequence or a target list through the request form — we will find where the messages are being lost and tell you what to fix first. How this kind of engagement runs end to end is laid out in the unit protocol.
Get your sequence reviewed
Send the current emails and your target list — we return a written teardown.
Send us a sequence for a teardown
OT9