Email Deliverability Knowledge Base
Plain-language, MTA-agnostic reference on getting email delivered — authentication, provider requirements, list hygiene, compliance, and ESP operations.
Foundations & Strategy
- Foundations of Email Deliverability — the wanted/expected principle and how providers measure it.
- The Seven-Step Delivery Model — the campaign lifecycle loop tying KB topics together, with the recipient-issues taxonomy and marketer-vs-platform responsibility split.
- Two Worlds of Email Deliverability — working with vs. against mailbox providers; why gaming fails; the "less is more" economics.
Mailbox Provider Requirements & Postmaster Pages
- Gmail Sender Requirements — bulk-sender rules, spam-rate thresholds, enforcement timeline.
- Gmail SMTP Troubleshooting — full Gmail reply-code catalog with fixes.
- Yahoo Sender Requirements · Yahoo Complaint Feedback Loop · Yahoo SMTP Error Codes · Yahoo Performance Feeds
- Microsoft / Outlook.com Sender Requirements — postmaster policies, the May 2025 high-volume mandate, error codes.
- Microsoft Filtering Internals — reading X-Forefront-Antispam-Report headers, SCL/BCL scales, compauth, Tenant Allow/Block List.
- Gmail Filtering Internals — Gmail's ML/categorization from Google's own research; what actually moves placement.
- Apple iCloud Mail — bulk-sender requirements and escalation path.
- GMX / WEB.DE / mail.com — United Internet requirements, CSA.
- Comcast / Xfinity — error codes, rate limits, FBL (archived-source provenance noted).
- B2B Gateway Deliverability — Proofpoint, Mimecast, Barracuda: how secure email gateways filter, delist, and rewrite links.
Provider Escalation & Remediation
- Cross-Provider Escalation & Mitigation Channels — the Google/Yahoo/Apple/Microsoft support-and-unblock map, with evidence to gather first.
- Microsoft Escalation Channels — the delist portal, delist@microsoft.com, Outlook.com sender support, SNDS/JMRP prerequisites.
Postmaster Tools (sender-facing dashboards)
- Google Postmaster Tools — enrollment, all dashboards, Gmail FBL (Feedback-ID).
- Microsoft SNDS & JMRP — per-IP data, thresholds, feedback loop.
Authentication
- SPF — RFC 7208: syntax, evaluation, lookup limits, pitfalls.
- DKIM — RFC 6376 + 8301 + 8463: signatures, keys, canonicalization, risks.
- DKIM Key Rotation — M3AAWG cadence, selector schemes, two-live-keys workflow, delegation.
- DKIM Replay — the replay attack, why l=/x= don't fix it, mitigations and ESP impact.
- DKIM2 — the IETF DKIM redesign (per-hop chained signatures); WG status, not yet a standard.
- DMARC (introduction) — what it does, alignment, the record, policy choices.
- DMARC Deployment — operational tag reference, failure modes, rollout path, tooling.
- DMARC Standard (RFC 9989 / DMARCbis) — the spec that obsoletes RFC 7489; Tree Walk, tag changes.
- DMARC Aggregate Reports (RFC 9990) · DMARC Failure Reports (RFC 9991)
- ARC — RFC 8617: surviving forwarding.
- Authentication-Results Header — RFC 8601: reading receiver verdicts.
- BIMI — logo display: prerequisites, record, SVG/VMC requirements, provider support.
Transport Security
- MTA-STS · TLS-RPT · DANE for SMTP
- SMTP TLS Practice — STARTTLS, opportunistic security, implicit TLS, REQUIRETLS, TLS 1.0/1.1 deprecation.
- TLS Baseline — the M3AAWG industry TLS floor (versions, ciphers, encrypted access).
- NIST SP 800-177 — the US federal Trustworthy Email reference and its recommendation matrix.
Core Email RFC Digests
- SMTP (RFC 5321) · Message Format (RFC 5322) · Email Architecture (RFC 5598)
- ESMTP Extensions — SIZE, PIPELINING, CHUNKING, DSN (NOTIFY/RET/ENVID).
- MIME & Encoding — multipart structure, quoted-printable/base64 pitfalls, malformed-MIME filtering.
- SMTPUTF8 / EAI — internationalized addresses and headers, no-downgrade rule.
- Greylisting (RFC 6647) — tuple mechanics, timing, what senders must do to pass.
- Auto-Replies (RFC 3834) — Auto-Submitted, null return-path, loop prevention.
List Management & Bounce Handling
- Consent Methods — the opt-in quality spectrum from double opt-in to harvested lists, with complaint-risk profiles.
- Address Acquisition — legitimate acquisition vs harvesting/scraping/purchase, and why acquisition method is the root of list quality.
- List-Unsubscribe & One-Click (RFC 2369 / 8058)
- Complaint Feedback Loops (RFC 6449)
- Enhanced Status Codes (RFC 3463)
- Delivery Status Notifications (RFC 3464)
- Backscatter & BATV — misdirected bounces, accept-then-bounce, prvs= tagging.
IP & Domain Reputation Management
Operations
- Metrics & Benchmarks — thresholds and corrective actions.
- List Hygiene & Sunset Policies
- Sending Infrastructure Practices — dedicated vs shared IPs, subdomain strategy, domain warm-up.
- MTA Delivery Tuning — queue theory, per-destination concurrency/rate shaping, adaptive backoff, scheduler fairness.
- Per-Provider Tuning Baselines — community-maintained shaping values (connection/rate limits) per provider, dated.
- Reputation Monitoring — blocklists, seed testing, dashboards, recovery.
- Reputation Incident Recovery — the post-compromise/collapse runbook: secure, purge, rebuild, re-warm, replace-vs-rehabilitate.
- Content & Design for Deliverability — spam-word myths, links, images, tabs.
- Tracking & Measurement Distortion — how MPP, Safe Links, and scanners break open/click metrics, and which signals still hold.
- Open & Click Tracking Mechanics — how opens and clicks are actually counted, and what each metric does and doesn't tell you.
- Placement Measurement Methodology — seed lists vs panel vs pixel, where each lies, and Postmaster Tools' blind spots.
- Delivery Troubleshooting Playbooks — symptom→hypothesis→test→fix for not-delivered / delayed / spam / bounced, per provider.
- Delivery Events & Diagnostics — the delivery-event taxonomy an MTA emits and the engagement-quality signals beneath the playbooks.
- Non-Human Interactions — M3AAWG's study of security-scanner bot clicks and the resulting metric inflation.
- Mandated & Regulatory Email — sends that must reach whole databases (breach notices, recalls): risk mitigation, provider pre-notification, sequencing.
- IPv6 Sending — why receivers impose stricter rules on IPv6 mail, and what it means for senders.
- IPv6 Reverse DNS — why per-address PTR breaks at IPv6 scale, RFC 8501's five approaches, receiver expectations.
ESP Operations (running the platform)
- Abuse Desk — role addresses (RFC 2142), report intake, triage priorities, remediation workflow, staffing.
- Outbound Monitoring — the continuous-monitoring stack: pre-send scanning, behavioral baselines, watchers, alert design, response ladder.
- Customer Vetting — the M3AAWG Vetting BCP: questionnaires, red flags, test-send methodology, ongoing triggers.
- Transactional-Account Vetting — why API/transactional senders need a different playbook, and the controls that keep the transactional/marketing boundary enforceable.
- Vetting Automation — the third-party signal-vendor landscape and how to compose it into onboarding gates, progressive trust, and continuous re-scoring.
- Compromised Accounts — detection, containment, remediation of account takeover and outbound abuse.
- Subscription Bombing — signup-form abuse weaponizing confirmation mail; detection and layered defenses.
- Spam-Trap Incident Response — working a trap-hit: confidentiality, customer notification, acquisition audit, escalation.
- Multi-Tenant Architecture — IP pools, per-tenant reputation isolation, promotion/demotion, automated enforcement.
- Suppression-List Architecture — global vs account vs tenant vs stream scopes, auto-suppression triggers, precedence, retention.
- Customer Domain Authentication — how ESPs implement customer domain auth: on-behalf models, CNAME-delegated DKIM, custom MAIL FROM, link branding.
- Account Enforcement — AUP structure, the review/pause/reinstatement state machine, and the exact bounce/complaint thresholds that auto-pause an account.
- Avoiding Blocklistings — the Spamhaus 3-phase ESP playbook (set up, monitor & educate, protect) plus anti-fraud-signup controls.
- IP Acquisition Diligence — vetting IP space before sending: reputation history, WhoWas/RDAP, the transfer-market abuse risk.
- Pool Recovery — the disaster runbook for a shared IP pool poisoned by a bad tenant: isolate, contain, delist, evacuate clean tenants, rehabilitate vs retire.
- Customer Offboarding — winding down a departing customer on good terms: drain mail, relinquish IPs, retire subdomain/DKIM, reconcile suppression vs GDPR erasure, revoke access.
Industry Best Practices
- M3AAWG Senders BCP — the industry-consensus baseline.
- M3AAWG Email Authentication BCP
- M3AAWG Sending Domains BCP — subdomain segmentation, header-domain consistency, the three DNS delegation models, migration mechanics.
- M3AAWG Document Index & FBL Ecosystem
- Word to the Wise Best Practices
Reference
- Glossary — deliverability terms of art, cross-linked to the deep articles.
- Email Abuse Taxonomy — the classification layer: each abuse type → victim → ESP-side signals → response article.
- Blocklists & Spamhaus — DNSBL mechanics, zones, listing/delisting.
- Spamhaus Listings Deep Dive — per-list criteria, escalation, return codes, delisting workflows.
- Spam Traps — pristine/recycled/typo traps and what they signal.
- URL & Content Filtering — SURBL URL reputation and rspamd fuzzy hashing; link-domain implications.
- Sender Certification Programs — Validity Certification and CSA: criteria, thresholds, who honors them, when they pay off.
- Cold-Email Position — the industry stance on unsolicited outreach; definition, tactics, detection.
- Deliverability Testing Tools — the free diagnostic tool catalog.
- Community Expert Resources — where practitioners track current events.
- Brand Protection: Domain Management — domain portfolio security, defensive registrations, lookalike-domain triage, parked-domain records.
- Routing Security & IP Hijacking — BGP/IP hijacking as a spam vector, transfer-market abuse research, RPKI as mitigation.
- OECD Anti-Spam Toolkit — the cross-border policy/enforcement framework and ISP/sender responsibilities.
- Deliverability Benchmarks — quantitative industry data: inbox-placement rates by provider/country/vertical, per-industry engagement, sender-adoption surveys (dated and attributed).
Legal Compliance
- North America: CAN-SPAM (US) · CAN-SPAM Rulemaking · CASL (Canada) · Enforcement Cases
- Europe: EU ePrivacy & GDPR · ESP Processor Obligations · UK PECR · Germany UWG · France CNIL · Netherlands & B2B Rules
- Asia-Pacific & Americas: Australia Spam Act · Brazil LGPD · APAC Email Laws (Japan, NZ, Singapore, Korea)
- Cross-cutting: Right to Object & Erasure · GDPR & Suppression Lists · Consent Record-Keeping · Minors & Email Marketing · Consent Guidance Updates
- See compliance/README.md for the jurisdiction index and the not-legal-advice disclaimer.