Why your cold emails go to spam in 2026 (and how to fix it before you send)

Here is the mistake that quietly kills more cold campaigns than any subject line ever has. Opens sit near zero on day one, so the sender assumes the copy is weak, rewrites the subject, and sends again from the same domain. Then again. Each resend is going straight to spam, and each one teaches Gmail and Outlook a little more firmly that this domain is not welcome. By the time anyone checks the technical setup, the domain is already burned.

The uncomfortable part is that the campaign was probably fine. The setup was not. And in 2026 the setup rules stopped being suggestions.

This free skill runs the checks that decide inbox versus spam before you send a single message, and it runs them in the order that actually matters, so you are not tuning copy while the domain quietly burns. You paste it into Claude, ChatGPT or any assistant that reads a SKILL.md file, describe your sending setup, and it walks the audit with you and ends on a go or no-go with the fix for each failure.

The one thing it catches that almost nobody thinks about: a broken or missing one-click unsubscribe link is a deliverability problem, not just a compliance box. When someone cannot quietly opt out, a good share of them hit "report spam" instead. That single click counts against you far more than an unsubscribe would, and it is the fastest way to cross the line that gets a domain filtered.

What actually changed, with the current numbers

Gmail, Yahoo and Microsoft now enforce a shared set of sender requirements. For bulk senders, meaning 5,000 or more messages per day per domain to their inboxes, the current gates look like this.

Authentication is mandatory. SPF, DKIM and DMARC all have to be in place, DMARC set to a policy of at least p=none, and the visible From domain has to align with the domain that actually authenticated the mail. That last point trips people up constantly. Gmail now returns a hard error, 550-5.7.26, when DMARC alignment fails, rather than quietly filing the message away.

The spam complaint rate is the number that ends domains. Keep it below 0.3 percent, and target under 0.1 percent. At the ceiling that is about one complaint for every 1,000 delivered messages, and you want to be at one in a thousand or better. At cold-outreach volumes this is unforgiving: one bad batch to a list you did not verify can push you over 0.3 percent for the measurement window and get you filtered across the board.

Enforcement got harder, not softer. Gmail moved from temporary deferrals to permanent 550 rejections for non-compliant mail in late 2025. Microsoft spent 2025 tightening its own high-volume sender rules for Outlook and Hotmail, first routing non-compliant bulk mail to junk and then rejecting repeat offenders outright. Yahoo has mirrored Gmail since the original February 2024 changes. There is also a one-click unsubscribe requirement (RFC 8058, needing both the List-Unsubscribe-Post and List-Unsubscribe headers), which has to be honoured within two days, and providers now test whether the link actually works.

None of these are numbers you should take from memory, mine included. They move. The skill tells you to confirm each one against your own received headers and the current published guidelines before a high-stakes send, rather than trusting a dashboard that says everything is fine.

The skill

Copy everything in the block below into a file named SKILL.md, or paste it straight into your assistant and describe your sending domain, your volume and where your list came from. It will ask for the setup facts first, then score each check, then give you the verdict.

---
name: cold-email-deliverability-preflight
description: >-
  Run a pre-send deliverability audit on a cold outbound campaign so it lands
  in the inbox instead of spam. Use this before launching any cold email
  sequence, when reply rates suddenly collapse, when Gmail or Outlook start
  bouncing mail, or when someone asks why their cold emails go to spam. Checks
  sending domain setup, SPF, DKIM, DMARC, list hygiene, spam complaint math,
  and the one-click unsubscribe trap, then returns a go or no-go scorecard with
  the exact fix for each failure. Trigger phrases: "why do my cold emails go to
  spam", "check my cold email setup before I send", "deliverability audit",
  "cold email landing in spam", "SPF DKIM DMARC cold email", "is my domain
  ready to send", "my open rates dropped to zero".
---

Most cold campaigns do not fail because the copy is weak. They fail because the
mail never reaches a human. The sender launches, watches opens sit near zero,
assumes the subject line is wrong, rewrites it, and sends again from the same
poisoned domain. Every resend digs the hole deeper. This skill runs the checks
that decide inbox versus spam BEFORE the first send, in the order that actually
matters, and shows its working so the person can see exactly what will get them
filtered.

The rules changed and keep tightening. Gmail, Yahoo and Microsoft now enforce
sender requirements that used to be optional, and in late 2025 Gmail moved from
soft deferrals to permanent rejections. Treat every figure below as a hard gate,
not a nice-to-have.

This is operational guidance on email setup and reputation, not legal advice on
consent or data protection. Anything touching who you are allowed to email, and
under what basis, must be reviewed against the rules that apply to your list and
your market (see the refuse-and-flag section).

## Step 1: Capture the setup before checking anything

Ask for or confirm these facts. Do not proceed on assumptions; a wrong answer
here invalidates every later check.

1. The exact sending domain and the From address that recipients will see.
2. Whether that domain is the company's primary domain or a separate domain
   bought for outbound. This is the single biggest reputation decision.
3. Rough daily send volume per domain and per individual mailbox.
4. The sending platform or ESP, and whether mailboxes are Google Workspace,
   Microsoft 365, or something else.
5. Where the list came from and how the addresses were collected.
6. How old the domain and mailboxes are (bought last week or aged for months).

Write these back to the person as a short setup summary before scoring, so any
wrong assumption surfaces immediately.

## Step 2: Refuse to send from the primary domain for cold outbound

If cold volume is going out from the company's main domain, stop and flag it
first. A spam-complaint spike or a spam-trap hit on a cold campaign damages the
reputation of the domain that also carries invoices, password resets and warm
client mail. The standard safe pattern is a separate sending domain (often a
close variant of the brand), with its own mailboxes, forwarding to the main
site. Recommend this before anything else, because no amount of authentication
fixes a burned primary domain.

## Step 3: Verify authentication (SPF, DKIM, DMARC, PTR, TLS)

For bulk senders (5,000 or more messages per day per domain to Gmail, Yahoo or
Outlook) all of the following are now required, and Gmail applies most of them
to smaller senders too. Check each one and mark pass or fail:

1. SPF: a published SPF record that authorises the actual sending
   infrastructure. Fail if missing or if it still lists an old provider.
2. DKIM: messages signed with DKIM, key published in DNS. Fail if unsigned.
3. DMARC: a published DMARC record with a policy of at least p=none, and the
   visible From domain must align with the authenticated domain. Misalignment
   is a common silent killer; Gmail now returns a hard error on DMARC
   alignment failure.
4. PTR record: the sending IP must have valid reverse DNS. Required by all four
   major providers.
5. TLS: outbound mail sent over TLS. Required by Gmail and Microsoft.

How to verify without guessing: inspect the DNS records for the domain directly,
and send one test message to a mailbox you control, then open the raw headers
and confirm SPF, DKIM and DMARC each show a pass. Never mark this section green
from the platform's own dashboard alone; confirm from a received message.

## Step 4: Clean the list before the first send, not after

Bounces and spam traps do reputation damage that authentication cannot undo.

1. Verify every address before sending. Remove invalid, unknown and risky
   addresses.
2. Remove role accounts (info@, sales@, admin@) and obvious catch-all domains
   from a cold list; they inflate complaints and traps.
3. Keep the hard bounce rate under about 2 to 3 percent. Above that, providers
   throttle you across the board. Aim well under.
4. If the list is older than a few weeks, re-verify it; addresses decay.

Flag any list that cannot be verified this way as high risk and recommend
holding the send.

## Step 5: Check the spam-complaint math (the number that ends domains)

This is the gate people understand least. The recipient's own "report spam"
click is what counts, measured as a rolling rate.

1. Keep the spam complaint rate below 0.3 percent. Target under 0.1 percent.
   That is roughly one complaint per 1,000 delivered at the ceiling, and you
   want to stay at one per 1,000 or better.
2. At cold-email volumes this is brutal: a single bad batch to an unqualified
   list can push you over 0.3 percent for the window and get the domain
   filtered.
3. The non-obvious trap: a broken or missing one-click unsubscribe converts
   people who would have quietly opted out into spam complainers, which is the
   fastest way to blow past 0.3 percent. Fixing unsubscribe is a deliverability
   fix, not just a compliance one.

## Step 6: One-click unsubscribe and content compliance

1. Include a working one-click unsubscribe (RFC 8058). It needs both headers:
   List-Unsubscribe-Post: List-Unsubscribe=One-Click, and a List-Unsubscribe
   header with the unsubscribe URL. Providers now test whether the link
   actually works.
2. Honour every unsubscribe within two days (48 hours). Continuing to mail
   someone who opted out drives complaints straight back up.
3. Include a real physical postal address in the footer.
4. Keep the From name and From domain consistent and aligned with the
   authenticated domain.
5. Avoid the patterns filters punish: heavy images with little text, link
   shorteners, many links, all-caps or money-and-urgency subject lines, and
   large attachments on a first touch.

## Step 7: Return a go or no-go scorecard

Produce a table with one row per check from Steps 2 to 6: the item, pass or
fail, the current value where known (for example the measured bounce rate), and
the exact next action for any fail. Then give a single verdict:

- GO only if authentication passes end to end, the list is verified, bounce
  risk is under about 2 percent, a working one-click unsubscribe is in place,
  and the domain is a separate sending domain that has been warmed.
- NO-GO if any authentication check fails, the list is unverified, the primary
  domain is being used for cold volume, or unsubscribe is missing or broken.
  List what to fix and in what order.

Always show the working. State which figures came from the person's own setup
and which are the current provider thresholds, so the verdict can be checked
rather than trusted.

## Step 8: Set up monitoring after go

1. Enrol the sending domain in the free postmaster or sender dashboards the
   major providers offer, and watch the spam complaint rate daily for the first
   two weeks.
2. Ramp volume gradually from a warmed domain rather than blasting on day one.
3. If the complaint rate climbs toward 0.3 percent or opens fall off a cliff,
   pause and re-run Steps 4 to 6 before sending more.

## What this skill should refuse or flag

- Refuse to help send to purchased, scraped or non-consented lists without
  raising that this is a legal and reputation risk. Consent rules (for example
  GDPR-style rules in some markets, and anti-spam law such as CAN-SPAM or CASL
  in others) decide who may be emailed and on what basis. This skill does not
  determine legality; flag it for review against the rules that apply to the
  list and market, and say plainly that it is not legal advice.
- Refuse to mark any authentication check as passing on the person's say-so
  alone. If it has not been confirmed from a received message or DNS record,
  mark it unverified, not green.
- Flag, do not hide, a burned primary domain: if cold volume already went out
  from the main domain, say so and treat reputation recovery as a separate job.
- Flag deliberate evasion tactics (rotating throwaway domains purely to dodge
  filters, forged headers, hiding the real sender) as out of scope and against
  provider terms; recommend legitimate warm-up and list quality instead.
- When numbers matter (thresholds, dates, provider rules), state that these
  change and should be confirmed against the current published sender
  guidelines before a high-stakes send.

Where this stops

This is an operational check on setup and reputation. It does not decide whether you are allowed to email a given list. Consent and anti-spam rules vary by market, and the skill flags that for review rather than pretending to answer it. It is not legal advice. It also cannot rescue a primary domain that has already been used for cold volume and burned; that is a separate and slower job. And it assumes you want to send legitimate outreach from a real, warmed domain. If the plan is to rotate throwaway domains to dodge filters, no checklist will save that, and the providers are better at spotting it than you are.

Leave a comment: