Google Postmaster Tools
What Google Postmaster Tools provides — enrollment, every dashboard (compliance, spam rate, reputation, feedback loop, authentication, encryption, delivery errors) and how to interpret each.
Operational6 min read
Who it is for Senders, ESP operators
Applies to senders on any platform
ContentsOn this page — 4 sections
If you send to Gmail users, Google Postmaster Tools shows you how Gmail sees your mail. It is Google's free monitoring console for senders, at https://postmaster.google.com/ (you need to sign in with a Google account). Once you verify that you own a domain, you get dashboards on spam rate, IP and domain reputation, authentication success, encryption, delivery errors, feedback loop data, and compliance with the Gmail sender requirements.
All data covers mail to personal Gmail accounts only (@gmail.com and @googlemail.com), not recipients on Google Workspace.
Enrollment
Prerequisites: a Google or Google Workspace account. The domain you add must be the DKIM d= domain or the SPF (Return-Path) domain that authenticates your mail.
- Add the domain: sign in at postmaster.google.com, click Add, and enter the authentication domain.
- Verify ownership: copy the TXT record you are given into the domain's DNS, then click Verify. Verification is usually instant, and takes up to ~10 minutes. Dashboards show no data until the domain is verified.
- Grant access (optional): go to Manage Domains > More > Manage > Add a Google email address. You can share read access, but the person you grant it to is not notified automatically.
Common issues: verification fails because of DNS propagation delay or a mistyped record (retry, or generate a new string); the person you grant access to must have a Google account; and missing dashboard data usually means your volume is too low to pass the privacy threshold.
Data characteristics
- The data is updated daily, typically within 24 hours. Compliance status can take up to 7 days to reflect changes.
- Timestamps are in UTC.
- You can select ranges of 7, 30, 60, 90, or 120 days.
- Days with low volume are left out to protect user privacy, so a gap does not mean zero.
- Google tries to exclude forwarded messages from the data, but some may still appear in the dashboards.
- Unauthenticated mail is largely invisible: most dashboards cover only mail that passed SPF or DKIM for the verified domain.
Dashboards
Compliance status
This dashboard checks each requirement of the Email Sender Guidelines and rates it Compliant, Needs work, or No data found (not enough volume).
- For all senders, it checks SPF and DKIM authentication, DNS (PTR) records, message formatting, TLS encryption and the user-reported spam rate.
- For bulk senders (~5,000+/day), it also checks DMARC, support for one-click unsubscribe, and whether unsubscribes are honored.
Compliance is displayed for the primary domain, but traffic from both the primary domain and its subdomains feeds the calculation. Allow up to 7 days after a fix for the status to change.
Spam rate
This is the percentage of your delivered mail that Gmail users mark as spam themselves, for each day. Stay below 0.10%, and never reach 0.30% (threshold details).
One caveat is critical for reading this number: the denominator is mail delivered to the inbox. As Google puts it, "if Gmail automatically sends a significant number of your messages to spam, the rate shown in the dashboard might seem low." You can therefore have a low spam rate and poor inbox placement at the same time, so read this dashboard together with reputation.
IP reputation and Domain reputation
Both dashboards use the same scale of four tiers:
| Tier | Meaning |
|---|---|
| High | Very low spam rate; complies with Gmail's sender guidelines; mail rarely filtered |
| Medium | Known to send legitimate mail with occasional low-volume spam; fair deliverability |
| Low | Significant history of sending spam; mail likely marked as spam |
| Bad | High spam volume; mail nearly always marked as spam or rejected at SMTP time |
Domain reputation covers only messages authenticated with the exact DKIM or SPF domain you verified. Recovering reputation takes time and sustained sending that follows the rules; there are no shortcuts. The two dashboards separate problems with infrastructure (IP) from problems with the brand or content (domain). See advanced IP segmentation for how to use this separation deliberately.
Feedback loop (FBL)
Gmail's FBL is aggregate, not per message: it does not return individual complaint reports. Instead, senders add a Feedback-ID: header, and Postmaster Tools reports the average spam rate for each identifier, each day, plus the volume of unique identifiers flagged.
Header format:
Feedback-ID: a:b:c:SenderId
SenderId(the rightmost field) is mandatory, 5–15 characters, and unique and consistent for each sender.a,bandcare up to three optional custom fields (for example, campaign, customer or mail stream). Data is aggregated for the first 4 fields separated by colons, counted from the right.- Do not reuse the same identifier value in different fields, because the aggregates would mix. Do not use values unique to each message, such as a Message-ID, because each identifier needs enough daily volume and enough distinct spam reports to produce data.
To get FBL data, your traffic must be DKIM-signed by a domain you control, that domain must be verified in Postmaster Tools, and your sending IP addresses must be in the SPF record with valid PTR records. The dashboard can show data by From: header domain, or by all DKIM signing domains. FBL data covers @gmail.com recipients only.
The main use is to pinpoint which campaign, customer or stream drives complaints. This matters especially for ESPs whose customers share domains.
Authentication
This dashboard shows, for each day, the percentage of attempted mail that passed SPF, DKIM and DMARC. Correctly configured senders typically reach ≥95% success for DKIM and DMARC. SPF rates are naturally lower, because delivery through third parties and forwarding breaks SPF, which checks the path (see DMARC). Domains that do not send mail show no results.
To debug a low rate:
- For DKIM, check the formatting of the TXT record, that the key is correct, and the DNS TTL and expiration.
- For SPF, check the record syntax, and that every authorized sending IP address or service is listed.
- For DMARC, make sure SPF or DKIM passes first, and consider relaxed alignment.
Encryption
This dashboard shows the percentage of traffic sent over inbound TLS (your mail arriving at Gmail over TLS) and outbound TLS. TLS is a hard requirement of the sender guidelines, so this should be at or near 100%.
Delivery errors
This dashboard shows the percentage of authenticated mail that was rejected or failed temporarily, compared with all authenticated mail, broken down by the reason for the error:
| Error reason | Typical cause | Action |
|---|---|---|
| Rate limit exceeded | Suspiciously high sending rate | Pause, then resume slowly (warm up again) |
| Suspected spam | Message classified as likely spam | Usually low reputation; if it persists on compliant mail, escalate through the bulk sender form |
| Email content is possibly spammy | Content flagged | Review the content; use the escalation form if needed |
| Bad or unsupported attachment | Blocked file type | Send only attachment types that Gmail supports |
| DMARC policy of the sender domain | Your own DMARC policy (p=reject or quarantine) is rejecting your mail |
Check the DMARC aggregate reports; consider p=none while you fix alignment |
| Low IP reputation, or low domain reputation | Poor reputation tier | Fix the root cause and rebuild reputation |
| IP in one or more public RBLs, or domain in RBLs | Listing on a public blocklist | Request delisting from the blocklist operator |
| PTR record missing | No reverse DNS | Add a PTR record (verify it with the Dig tool in Google Admin Toolbox) |
Temporary failures are throttling. Google's advice is to "completely stop sending for a short period of time, then resume sending at a slower rate." Gmail troubleshooting lists the specific SMTP codes.
Fit in a deliverability workflow
- Enroll every authentication domain (the DKIM d= domains and the SPF Return-Path domains) before problems occur, because there is no data for the period before you enroll.
- Every day: watch the spam rate against 0.10% and 0.30%, and both reputation tiers.
- For each campaign: use
Feedback-IDand the FBL to attribute complaints to streams, customers or campaigns. - When delivery incidents happen: match the reasons in Delivery Errors against your SMTP logs, and check the Authentication and Encryption dashboards for regressions.
- For compliance: check every item in Compliance Status. Only compliant senders with a spam rate <0.3% over 7 consecutive days qualify for mitigation from Google.
Google's recommendations on list hygiene that go with these tools: send only to recipients who opted in, confirm addresses at signup (confirmed opt-in), ask periodically whether people are still interested, stop mailing people who do not engage, and make unsubscribing very easy.
Yahoo offers similar facilities. See Yahoo complaint feedback loop and Yahoo performance feeds.
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
All 2 in Postmaster Tools →