Tech Insights

Email Hosting & Deliverability

Email feels free and effortless, but landing in the inbox is now an engineering discipline with three DNS records, a reputation score, and a deadline that already passed.

Diagram of email authentication with SPF, DKIM and DMARC

TL;DR

Landing in the inbox is now an engineering discipline. Receiving servers check whether a message is authentic and wanted: SPF, DKIM and DMARC form the authentication handshake that Google and Yahoo have required of bulk senders since 2024, and sender reputation, built through clean lists and consistent sending, is the part you cannot fake.

On this page

The illusion of the send button

Most people think email is solved. You type an address, write a message, press send, and it arrives. That illusion holds right up until the day it doesn’t – the day your invoice never reaches a client, your password reset vanishes, or your carefully written newsletter quietly piles up in ten thousand spam folders. At that moment you discover that delivering email is not a button. It is an infrastructure problem, and in 2025 it is one with rules, scoring, and consequences.

The good news is that the problem is well-defined. Email deliverability is not luck or dark art. It is a small number of things done correctly, and once you understand what receivers are actually checking, the fog lifts.

What the receiving server is really asking

When a message arrives at Gmail or Yahoo or any serious mail provider, the server is not reading your prose. It is asking a sequence of cold, mechanical questions. Did this come from a server allowed to send for this domain? Has the message been tampered with since it was signed? Does the domain that authenticated match the name in the From: line that a human will see? Does this sender have a history of people wanting their mail, or deleting and reporting it?

Those questions map directly onto the technologies that now define email: SPF answers who may send, DKIM answers whether the message is intact, and DMARC ties the two together and asks the alignment question that actually stops spoofing. Behind all of them sits reputation – the running judgment, invisible to you, of whether your mail is wanted.

SPF, DKIM, DMARC: a trust handshake

It helps to stop seeing these three as bureaucratic checkboxes and start seeing them as a trust handshake your domain performs on every message.

SPF is a list, published in DNS, of the servers permitted to send on your behalf. It is simple and brittle: it authorizes an IP, nothing more, and it breaks the moment mail is forwarded. DKIM is stronger. Your server signs each message with a private cryptographic key, and the matching public key lives in DNS for anyone to verify. That signature proves the message genuinely came from you and arrived unaltered – and crucially, it survives forwarding.

DMARC is the policy layer that makes the other two meaningful. On its own, SPF passing tells a receiver almost nothing useful, because a spammer can pass SPF for their own throwaway domain all day long. DMARC demands alignment: the authenticated domain must match the From: address the reader sees. That single requirement is what turns authentication from a formality into actual anti-spoofing. And DMARC adds something the others lack – reporting. Publish a policy of p=none and receivers will mail you daily reports listing every system on earth sending as your domain. It is the closest thing to X-ray vision you will get into your own email.

The deadline that already passed

For years, all of this was best practice – strongly recommended, widely ignored. That changed in February 2024, when Gmail and Yahoo jointly began enforcing requirements for bulk senders, broadly anyone sending around five thousand messages a day to their users. The list is not exotic: have SPF and DKIM passing, publish a DMARC policy, keep authentication aligned with your From: address, support genuine one-click unsubscribe, maintain valid reverse DNS, and – the one that catches people – keep your spam complaint rate below 0.3 percent.

What makes this a turning point is the word enforce. These are no longer suggestions that improve your odds. Miss them and your mail is throttled or rejected outright. The thresholds, history suggests, only ever move downward, which is why the right posture even for a small sender is to meet the bulk-sender bar now and stop thinking of it as optional.

Reputation is the part you cannot fake

Here is the uncomfortable truth that authentication alone will not fix: you can have perfect SPF, DKIM, and DMARC and still land in spam, because authentication only proves who you are, not that anyone wants to hear from you. That second judgment is reputation, and it is earned slowly and lost quickly.

Reputation is why warmup matters – a brand-new sending domain has no history, and blasting volume from it looks identical to a hijacked account. It is why list hygiene matters – mailing people who never asked, or who stopped engaging months ago, drips poison into your score. And it is why the unsubscribe link matters more than it seems: a person who cannot easily leave will hit “report spam” instead, and that single click is the most expensive feedback you can collect. Watch your complaint rate above every other metric. Keep it under a tenth of a percent and most problems never form.

Treat it like infrastructure, because it is

The senders who reliably reach the inbox are not the ones with the cleverest content. They are the ones who treat email as the operational system it has become: records published and verified, policies tightened one careful stage at a time, DMARC reports read every week, blocklists checked the moment bounces spike. None of it is hard in isolation. The discipline is in doing it continuously, because reputations drift and rules tighten whether you are watching or not.

Email will keep feeling free and effortless to the people who receive yours. Making it feel that way is the work – and now you know exactly what the work is.

Key takeaways 5

  1. Email deliverability is infrastructure, not a send button.
  2. Receivers ask whether a message is authentic and whether it is wanted.
  3. SPF, DKIM and DMARC prove your domain authorized the email.
  4. Since 2024 Gmail and Yahoo require authentication for bulk senders.
  5. Reputation comes from engagement, low complaints and clean lists.

Watch & learn

Email Deliverability Experts: How They Work and How to Choose Them - Tutorial by MailtrapMailtrap · YouTube

Frequently asked questions

What are SPF, DKIM and DMARC?

SPF lists which servers may send email for your domain, DKIM adds a cryptographic signature to messages, and DMARC tells receivers what to do when SPF or DKIM checks fail and sends you reports.

Why are my emails going to spam?

Common causes are missing or misconfigured SPF, DKIM or DMARC, a poor sender reputation, high complaint rates, sending to old or purchased lists and spam-like content.

What did Gmail and Yahoo change for senders in 2024?

Bulk senders must authenticate with SPF and DKIM, publish a DMARC policy, offer one-click unsubscribe and keep spam complaint rates low.

Tech InsightsProjects & Practice#email-hosting#deliverability#spf-dkim-dmarc#dns#smtp

Comments

No comments yet. Start the conversation.

Comments are reviewed before they appear. Be kind; one link max.

Go deeper with the free masterclass

Workshop, PDF handbook and curated resources for “Email Hosting & Deliverability”.

Open AL Academy ↗
Keep reading

Related articles