All articlesDeliverability

    The Email Deliverability Checklist (2026)

    A practical email deliverability checklist for 2026: the four numbers that tell you where you stand, the authentication records you must get right, sending domain structure, list hygiene rules, unsubscribe mechanics, content checks, monitoring cadence, and a 20-minute triage sequence for when inbox placement suddenly drops.

    The Email Deliverability Checklist (2026)
    Erin Moore
    Erin Moore
    August 25, 202610 min read
    Share:

    The Email Deliverability Checklist (2026)

    Email deliverability is whether your messages reach the inbox rather than the spam folder or nowhere at all. In 2026 it comes down to five things: authenticated sending domains, a DMARC policy, one-click unsubscribe, a complaint rate under 0.3%, and a list of people who actually want your mail. Work this checklist top to bottom.

    Start here: the four numbers that tell you where you stand

    Before you change anything, pull your last 90 days of sending and write down four figures. Everything else in this checklist is a response to one of them.

    MetricHealthy rangeAct ifWhat it usually means
    Hard bounce rateUnder 1%Above 2%Stale list or no email validation at signup
    Spam complaint rateUnder 0.1%Above 0.3%Weak consent, hidden unsubscribe, or wrong frequency
    Unique open rateRoughly 20–35%Below 15%Placement problem or dead segments
    Unique click rateRoughly 2–5%Below 1%Content mismatch, or opens are inflated by prefetching

    Track them per mailbox provider, not just in aggregate. A 22% overall open rate hiding a 4% Gmail open rate is a Gmail blocking problem wearing a disguise.

    1. Authentication: get all three records right

    This is non-negotiable in 2026. Google and Yahoo both require authentication for bulk senders, and Microsoft has tightened similar requirements. Unauthenticated bulk mail gets rejected outright, not filtered.

    • SPF — one TXT record on your sending domain listing every service allowed to send as you. Keep it under 10 DNS lookups or it fails silently. Never publish two SPF records on one domain.
    • DKIM — a cryptographic signature on every message. Use a 2048-bit key. The signing domain must align with your From domain; a valid signature from the wrong domain does not help you.
    • DMARC — a policy telling receivers what to do when SPF and DKIM alignment fail. Start at p=none with an rua= reporting address, read the reports for two to four weeks, then move to p=quarantine and eventually p=reject.
    • BIMI — optional, requires p=quarantine or stricter plus a verified mark certificate. It puts your logo in the inbox; it does not improve filtering by itself.

    IGSendMail configures SPF, DKIM, and DMARC automatically when you verify a sending domain, which removes the most common single point of failure on this list.

    2. Sending domain structure

    Never send marketing mail from your root domain. If a campaign goes badly, you do not want your password resets and your sales team's replies caught in the same reputation hit.

    1. Send marketing from a subdomain such as news.yourdomain.com.
    2. Send transactional and app mail from a separate subdomain such as mail.yourdomain.com.
    3. Keep the root domain for human-to-human email.
    4. Publish a DMARC policy at the organizational domain so subdomains inherit it, then override per subdomain if needed.
    5. Use a real, monitored reply-to address. noreply@ suppresses the reply signal that providers read as positive engagement.

    3. List quality: the biggest lever nobody wants to pull

    Most deliverability problems are list problems dressed up as technical problems. The fixes are unglamorous and they work.

    • Never buy, rent, or scrape a list. Purchased lists are dense with spam traps, and one trap hit can undo months of good sending.
    • Validate at the point of capture. Syntax check plus MX lookup on the domain stops typos and dead domains before they enter your database.
    • Use confirmed opt-in for cold or ad-driven sources. It costs you 10–25% of signups and saves you the traps and the complaints.
    • Suppress hard bounces immediately and permanently. Repeated sending to a hard bounce is one of the clearest bad-sender signals there is.
    • Sunset inactive contacts. If someone has not opened or clicked in 6–12 months, run one re-engagement sequence and then stop mailing them. Unlimited contacts on paid plans means keeping them costs nothing; mailing them costs plenty.
    • Watch for the honeypot pattern. A sudden batch of signups with no engagement and odd domains usually means a bot found your form. Add a honeypot field or a rate limit.

    4. Unsubscribe and consent mechanics

    The unsubscribe link is a deliverability feature, not a legal chore. Every person who unsubscribes instead of clicking "report spam" is a complaint you did not receive.

    • Include a one-click list-unsubscribe header (RFC 8058). Required by Google and Yahoo for bulk senders and it must process in under two days.
    • Make the visible unsubscribe link legible — real contrast, real font size, top or bottom of the email.
    • Do not require a login to unsubscribe. Ever.
    • Offer a preference center with a frequency-reduction option so "too much email" does not have to mean "gone forever."
    • Include a valid physical postal address, as CAN-SPAM requires.
    • Honor opt-outs across every list, not just the one they clicked from.

    Compliance framework note: GDPR, CAN-SPAM, and CASL each set different consent standards, and this article is general guidance, not legal advice — check your obligations with counsel if you operate across jurisdictions.

    5. Content and formatting

    Content filtering matters less than reputation, but it still breaks campaigns. The checks worth running:

    • Keep a reasonable text-to-image ratio. An email that is one giant image with three words of alt text is a classic spam signature.
    • Always include a plain-text alternative. Some filters score HTML-only mail down, and some readers genuinely prefer it.
    • Avoid URL shorteners and link redirects through unfamiliar domains. Link to your own tracked domain instead.
    • Match your link domains to your sending domain where possible — mismatched domains raise phishing heuristics.
    • Skip the ALL CAPS, the "!!!", the red 20px "ACT NOW", and the word "free" repeated six times.
    • Test rendering in the top five clients before every template change. A broken layout produces deletes, and deletes are a negative signal.

    Run every new template through the deliverability audit before it ships — it checks authentication alignment, blocklist status, content triggers, and header configuration in one pass, which is faster than diagnosing a failed campaign afterward.

    6. Sending behavior

    1. Keep volume steady. Providers read sudden 10x spikes as compromise or list purchase. Ramp over days, not in one send.
    2. Segment by engagement. Send most often to your most engaged tier and rarely to your least. This single change moves placement more than any content edit.
    3. Pick a cadence and keep it. Irregular sending erodes recognition; over-sending erodes patience. Weekly to biweekly suits most lists.
    4. Warm any new domain or IP. Two to six weeks, starting with your most engaged contacts.
    5. Split streams. Transactional and marketing should never share a subdomain or a sending identity.

    7. Monitoring: what to watch every month

    CheckFrequencyWhere
    DMARC aggregate reportsWeeklyYour rua= mailbox or a DMARC dashboard
    Google Postmaster ToolsWeeklyDomain and IP reputation, spam rate, authentication
    Microsoft SNDS / JMRPMonthlyOutlook complaint data and filtering status
    Blocklist statusMonthlySpamhaus, SURBL, Barracuda via a multi-list lookup
    Per-provider open ratesEvery campaignYour ESP reporting
    Seed-list inbox placementQuarterlyPlacement testing across major providers

    The 20-minute triage when placement drops

    1. Compare open rates by provider — is this Gmail-only, Microsoft-only, or everywhere?
    2. Check for a bounce-message change. SMTP rejection codes usually name the reason and often link to the provider's policy page.
    3. Run a blocklist lookup on your sending domain and IP.
    4. Verify SPF, DKIM, and DMARC still pass — DNS changes break authentication more often than anything else.
    5. Look at what changed in the last 30 days: a new list source, a new template, a volume jump, a new sending tool.
    6. If complaints spiked, identify the campaign and the segment, then suppress that segment and reduce frequency for two weeks.

    For the deeper background on how reputation, filtering, and authentication interact, the deliverability overview covers the mechanics behind each item in this checklist.

    Frequently asked questions

    What is a good email deliverability rate?

    Aim for 95% or better inbox placement, with hard bounces under 1% and spam complaints under 0.1%. Note that "delivered" in most ESP reports only means not bounced — it does not distinguish inbox from spam folder.

    Do I really need DMARC if SPF and DKIM already pass?

    Yes. Google and Yahoo require a DMARC policy for bulk senders, and without one you get no visibility into who is spoofing your domain. Start at p=none for reporting, then tighten once your reports are clean.

    How often should I clean my email list?

    Remove hard bounces automatically after every send, and review inactive contacts quarterly. Anyone with no opens or clicks in 6–12 months should get one re-engagement attempt and then be suppressed.

    Why are my emails going to spam only at Gmail?

    Gmail weights engagement heavily, so provider-specific spam placement usually means your Gmail subscribers are not opening or are marking mail as spam. Check Google Postmaster Tools for domain reputation and spam rate, then cut frequency to unengaged Gmail contacts.

    Does switching email providers fix deliverability problems?

    Only if the problem was the provider's infrastructure. Domain reputation and list quality follow you, so migrate for better tooling and support — but fix consent, hygiene, and authentication either way.

    Want authentication handled for you and a clean migration off your current provider? Launch on IGSendMail — automatic SPF, DKIM, and DMARC, 99% inbox deliverability, and a free 24-hour migration.

    Enjoyed this article?

    Get email marketing tips delivered to your inbox every week.