Home / Articles / Automation
AutomationEmail that lands: deliverability for founder-led newsletters
SPF, DKIM, DMARC and the sending discipline that keeps your newsletter out of spam and in front of people.
TL;DR — Deliverability is not luck. Authenticate your domain (SPF, DKIM, DMARC), warm up new sending slowly, keep your list clean, watch engagement signals, and write mail that doesn’t look like spam. Do those five things and a self-hosted stack like Listmonk plus an SMTP relay will reliably land in the inbox.
You wrote a good newsletter. You hit send. Then a reader mentions they found it in spam — or worse, they never saw it at all. The content was never the problem. Mailbox providers like Gmail and Outlook decide where mail lands using signals that have almost nothing to do with how clever your subject line is. They ask: can we prove who sent this, does this sender have a track record, and do real people want to read it? Get those answers right and the inbox opens. Here’s the discipline that gets you there.
Authenticate the domain: SPF, DKIM, DMARC
This is the price of entry. In 2024 Gmail and Yahoo made authentication mandatory for anyone sending in volume — unauthenticated mail now gets rejected or buried, not delivered. Three records do the work:
- SPF (Sender Policy Framework) lists which servers are allowed to send for your domain. If your relay isn’t on the list, receivers treat the mail as forged.
- DKIM (DomainKeys Identified Mail) cryptographically signs each message. The receiver checks the signature against a public key in your DNS, proving the mail wasn’t tampered with and really came from you.
- DMARC ties the two together and tells receivers what to do when a message fails, plus where to send reports so you can see what’s being sent in your name.
Here’s what those records look like in practice for a domain sending through a relay:
; SPF — authorize your relay (replace with your provider's include)
example.com. TXT "v=spf1 include:relay.yourprovider.com -all"
; DMARC — start at none to observe, then tighten to quarantine/reject
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:[email protected]; fo=1"
Start DMARC at p=none so you can read the reports without bouncing legitimate mail, confirm SPF and DKIM both pass and align with your From domain, then move to p=quarantine and eventually p=reject. DKIM keys are generated by your relay or your sending tool — publish the public key as the TXT record they give you.
Authentication doesn’t get you into the inbox. It gets you considered for the inbox. Everything after this is reputation.
Warm up and protect your reputation
A brand-new sending domain or IP has no history, and providers distrust strangers who suddenly send thousands of messages. Warm up: start with a few hundred of your most engaged subscribers, then increase volume gradually over two to four weeks. Engaged opens early on teach the providers that your mail is wanted.
Reputation is fragile and shared. A few practical rules:
- Keep sending steady. A consistent weekly cadence reads as healthy; sudden spikes look like a compromised account.
- Use a subdomain for bulk mail (e.g.
news.example.com) so a marketing misstep can’t poison the domain you send invoices and replies from. - Set up feedback loops and monitor complaints. A spam-complaint rate above ~0.3% is a red flag; over 0.1% and you should already be worried.
- Honor unsubscribes instantly and include a one-click unsubscribe header. It’s required now, and a visible unsubscribe link beats people hitting “report spam.”
Clean lists and real engagement
Mailbox providers grade you on whether people actually open and read. Sending to dead addresses and disengaged contacts drags your whole list down.
Validate addresses at signup with double opt-in — a confirmation click — so you only ever mail people who asked. Then prune: remove hard bounces immediately, and sunset subscribers who haven’t opened anything in 90 to 180 days (ask them once if they want to stay, then drop the silent ones). A smaller list of people who open is worth far more than a big list that ignores you, because engagement is the signal providers weigh most.
Never buy lists or import contacts who didn’t opt in. Beyond the legal exposure under laws like CAN-SPAM and GDPR, those addresses include spam traps that wreck your reputation the moment you hit them.
Write mail that doesn’t trip filters
Once you’re authenticated and trusted, content can still sink you. Filters and human readers react to the same things, so the fixes overlap.
Keep a healthy text-to-image ratio — an email that’s one big image with no real text is a classic spam pattern. Always send a plain-text alternative alongside your HTML. Avoid the obvious triggers: ALL CAPS subject lines, walls of exclamation marks, “FREE!!!” and “ACT NOW,” and link shorteners that hide the destination. Use your own authenticated domain for links rather than bare redirectors. And test before you send — tools like mail-tester give you a score and flag broken authentication, risky phrases, or a missing plain-text part before your audience ever sees the mail.
The throughline: write like a person emailing people, not a billboard.
The takeaway
Deliverability is a system, not a trick. Set SPF, DKIM, and DMARC correctly and watch the DMARC reports until everything aligns. Warm up new sending, keep your cadence steady, and protect your reputation with a dedicated subdomain. Mail only people who opted in, prune the silent ones, and treat engagement as the metric that matters. Write honest, balanced messages and test them before they go out. A modest self-hosted stack — Listmonk driving an SMTP relay — will land in the inbox as reliably as any expensive platform, because the platform was never the deciding factor. The discipline was.
The engineering & R&D notebook of Hagumi Studio. We write what we learn building and self-hosting the tools behind our work.
HAGUMISTUDIO.COM · X · RSS