emailmarketing.net

Deliverability Glossary

Alphabetical one-stop definitions of the deliverability terms of art used across this knowledge base, with links to the deep articles.

Reference13 min read

Who it is for Senders, ESP operators

Applies to senders on any platform

ContentsOn this page — 20 sections

When you meet a deliverability term you do not know, look it up here. Each entry gives a short working definition and a link to where the topic is covered in depth. The glossary covers deliverability terms only, not the vocabulary of email design or copywriting.

A

Acceptance rate (delivery rate): the percentage of sent messages that receiving servers accept (SMTP 250). Acceptance is not inbox placement, because an accepted message may still go to the spam folder. See Reputation Monitoring.

Allowlist (safelist): a list kept on the recipient's side of senders (addresses, domains or IP addresses) whose mail bypasses some filtering. The opposite of a blocklist. Asking recipients to add your sending domain to their safelist is a stopgap for critical mail, not a deliverability strategy. Formal allowlisting programs run by ISPs are largely historical, although CSA certification still exists (see GMX and WEB.DE).

Apple Mail Privacy Protection (MPP): an Apple Mail feature that fetches images in advance through a proxy. It fires open-tracking pixels without anyone reading the message, and hides recipients' IP addresses. It is a main reason open rates are inflated and clicks should be given more weight. See Metrics and Benchmarks.

ARC (Authenticated Received Chain): the RFC 8617 protocol that lets intermediaries (forwarders, mailing lists) preserve earlier authentication results, so that mail that legitimately breaks SPF or DKIM in transit can still be evaluated. See ARC.

ARF (Abuse Reporting Format): the RFC 5965 message format that complaint feedback loops use to report a recipient's "this is spam" action back to the sender. See Complaint Feedback Loops.

Authentication-Results header: the RFC 8601 header that the receiver adds to record its SPF, DKIM and DMARC verdicts (and related ones) for a message. It is where you can read how a receiver actually judged your authentication. See Authentication-Results Header.

B

Bayesian filter: a spam filter that classifies messages statistically, from the frequency of tokens learned from known spam and legitimate mail (ham), rather than from fixed rules. It is one of many content-analysis layers modern providers run. See Content and Design for Deliverability.

BIMI (Brand Indicators for Message Identification): a standard for displaying a brand logo next to authenticated messages. It requires DMARC at enforcement (quarantine or reject) and, at most providers, a Verified Mark Certificate. See BIMI.

Blocklist (DNSBL or RBL): a list, queried through DNS, of IP addresses or domains suspected of sending spam. Receivers use blocklist data as one input alongside their internal metrics, and Spamhaus carries the most weight. See Blocklists & Spamhaus.

Bounce: a delivery failure returned to the sender. Hard bounces (5.X.X) are permanent, such as an invalid address or a policy rejection. Soft bounces (4.X.X) are temporary, such as a full mailbox or a deferral. See Metrics and Benchmarks and Enhanced Status Codes.

Bounce rate: bounced messages as a percentage of messages sent. Common operating targets: under 2% is healthy, investigate above 5%, and never exceed 10%. See the threshold table.

Bulk sender: a sender that exceeds a provider's volume threshold (at Gmail, about 5,000 messages a day to Gmail), which triggers stricter requirements such as authentication, one-click unsubscribe and complaint-rate ceilings. See Gmail Sender Requirements.

C

CAN-SPAM: the US law (2003) that governs commercial email. It requires truthful headers and subject lines, a physical address, and a working opt-out honored within 10 business days. It is based on opt-out, unlike CASL and GDPR. See CAN-SPAM.

CASL: Canada's Anti-Spam Legislation. It requires express or implied consent before commercial electronic messages are sent, and sets requirements for identification and unsubscribing. See CASL.

Complaint (spam report): a recipient marking a message as spam. It is the most damaging single reputation signal, and some providers report it back to senders through feedback loops. See Complaint Feedback Loops.

Complaint rate: complaints as a percentage of delivered mail. Aim for below 0.1%. Gmail and Yahoo enforce a ceiling of 0.3% that you must never reach. See Metrics and Benchmarks.

Consent (express vs. implied): express consent is an explicit opt-in that is recorded. Implied consent is inferred from an existing business relationship. Which one is enough, and for how long, depends on the jurisdiction (CASL puts time limits on implied consent). See Compliance.

CSA (Certified Senders Alliance): a German sender certification program whose allowlist is honored by GMX and WEB.DE and other European receivers. See GMX, WEB.DE and mail.com.

D

DANE for SMTP: a mechanism based on DNSSEC (TLSA records) for authenticating a receiving server's TLS certificate. It closes the downgrade gap in opportunistic STARTTLS. See DANE.

Dedicated IP: a sending IP address used by a single sender, which gives full control over its reputation and full responsibility for it. It is only worthwhile above a sustained minimum volume, because a sender with low volume keeps a dedicated IP too "cold" to build reputation. See Basic IP Allocation.

Deferral (greylisting or throttling response): a temporary 4XX refusal that tells the sender to retry later. Rising deferrals at one provider often mean throttling, the step before blocking. See Reputation Monitoring.

Delivery vs. deliverability: delivery means the receiving server accepted the message. Deliverability is about where it landed afterward: the inbox, a tab, the spam folder, or dropped without notice. See Reputation Monitoring.

DKIM (DomainKeys Identified Mail): the RFC 6376 cryptographic signature over selected headers and the body, verified with a public key published in DNS. It proves that a domain takes responsibility for the message, and that the message was not altered in transit. See DKIM.

DMARC: Domain-based Message Authentication, Reporting and Conformance. A domain publishes a policy (none, quarantine or reject) for mail that fails aligned SPF or DKIM, and receives reports. See DMARC and DMARC Deployment.

DMARC alignment: the requirement that the domain in the visible From header matches (exactly, or at the organizational level) the domain that SPF or DKIM validated. Authentication without alignment does not pass DMARC. See DMARC.

Double opt-in (confirmed opt-in): a signup flow in which the address is not mailed until the subscriber clicks a confirmation link. It eliminates bounces from typos, blocks malicious sign-ups, and proves consent. See List Hygiene.

DSN (Delivery Status Notification): the RFC 3464 machine-readable bounce message that reports delivery failure, delay or success, with status codes for each recipient. See Delivery Status Notifications.

E

Email harvesting (scraping): collecting addresses without consent, typically by crawling websites. Harvested lists are full of spam traps and invalid addresses, so never mail them. See List Hygiene.

Email validation: checking before sending that an address is syntactically valid, has working MX records and (through verification services) an existing mailbox. Done at signup, it prevents hard bounces later. See List Hygiene.

Engagement: the recipient interactions that providers use to score senders, such as opens, clicks, reading time, replies, deletion without reading, and moving messages out of spam. It is the statistical basis for judging whether mail is "wanted and expected". See Foundations.

Enhanced status codes: the RFC 3463 three-part codes (for example, 5.1.1 means a bad destination mailbox) that let software parse SMTP replies to classify bounces. See Enhanced Status Codes.

Envelope sender (MAIL FROM, Return-Path, 5321.MailFrom): the address given in the SMTP MAIL FROM command, where bounces are sent. It is separate from the visible From header. SPF is evaluated against this domain. See SPF and SMTP.

F

False positive: a legitimate message wrongly classified as spam. Providers weigh this cost against the cost of missing spam, and it is why a good engagement history can rescue borderline mail.

Feedback loop (FBL): a provider mechanism that reports recipients' spam complaints back to the sender (usually in ARF format), so that the sender can suppress complainers immediately. See Complaint Feedback Loops.

FCrDNS (forward-confirmed reverse DNS): the PTR record of the sending IP address resolves to a hostname that resolves back to the same IP address. Most major providers treat it as a basic infrastructure requirement. See Sending Infrastructure Practices.

Feedback-ID header: Gmail's FBL mechanism. The sender supplies a header, and Gmail aggregates its identifiers into spam-rate statistics for each campaign in Postmaster Tools (without revealing individual complainers). See Google Postmaster Tools.

From header (5322.From): the author address displayed to recipients, defined by RFC 5322. DMARC alignment is anchored on this domain. See Message Format.

G

GDPR: the EU's General Data Protection Regulation. For email marketing, it requires a lawful basis (usually explicit consent), respect for the rights of data subjects, and an easy way to withdraw consent. It is broader than an anti-spam law. See compliance overview.

Google Postmaster Tools: Google's free dashboard for senders. It shows domain and IP reputation, spam rate, authentication pass rates, and delivery errors for mail to Gmail. See Google Postmaster Tools.

Greylisting: a receiver technique that temporarily rejects mail from unknown sources and accepts it when it is retried. It works because much spam software does not retry. Senders see it as deferrals. See SMTP.

H

Hard bounce: a permanent delivery failure (5.X.X), such as an address or domain that does not exist, or a policy rejection. Remove the address immediately and never send to it again. See List Hygiene.

Honeypot: a decoy. It is either a pristine spam-trap address planted to catch people who harvest addresses, or a hidden form field that only bots fill in, used to block signups by bots. See Spam Traps.

I

Inbox placement rate (IPR): the percentage of delivered mail that reaches the inbox rather than the spam folder, usually measured for each provider through seed testing. See Reputation Monitoring.

IP warming (warm-up): gradually increasing volume on a new IP address (or domain) so that receivers can build a reputation history. Suddenly sending full volume from a cold IP address triggers filtering. See IP Warm-Up.

L

List churn: the rate at which addresses leave a list through unsubscribes, bounces and abandonment. Marketing databases degrade by roughly 22% per year, so hygiene is continuous work, not a one-off task. See Reputation Monitoring.

List hygiene: the ongoing practice of removing invalid, bouncing, complaining and unengaged addresses, to keep healthy the metrics that providers score. See List Hygiene and Sunset Policies.

List-Unsubscribe header: the RFC 2369 header that advertises unsubscribe endpoints (mailto or HTTPS), which mail clients show as a built-in unsubscribe control. See List-Unsubscribe & One-Click.

M

Mailbox provider (MBP or ISP): the organization that runs recipients' mailboxes (Gmail, Yahoo, Microsoft, corporate servers). The terms "mailbox provider" and "ISP" are used interchangeably for the receiving side.

MTA, MSA, MDA, MUA: the roles that handle mail. The Mail Transfer Agent relays mail between servers, the Mail Submission Agent accepts mail from clients, the Mail Delivery Agent files mail into the mailbox, and the Mail User Agent is the recipient's client. See Email Architecture.

MTA-STS: a policy mechanism, published over HTTPS, by which a receiving domain requires authenticated TLS for inbound SMTP. It defeats STARTTLS downgrade attacks without DNSSEC. See MTA-STS.

MX record: the DNS record that names the servers receiving mail for a domain. It is checked during address validation, and a domain needs one (or an A record as fallback) to receive bounces.

O

One-click unsubscribe: defined by RFC 8058. A List-Unsubscribe HTTPS URI together with a List-Unsubscribe-Post header lets the recipient unsubscribe with a single POST request, without a landing page. It is mandatory for bulk senders under the 2024 requirements of Gmail and Yahoo. See List-Unsubscribe & One-Click.

Open rate: the percentage of delivered messages whose tracking pixel fired. Apple MPP and image prefetching inflate it, so treat it as approximate and give more weight to clicks and conversions. See Metrics and Benchmarks.

Opt-in and opt-out: opt-in means the recipient explicitly asked for the mail (the consent model of CASL and GDPR). Opt-out means mail may be sent until the recipient unsubscribes (the CAN-SPAM model). See Compliance.

P

PECR: the UK Privacy and Electronic Communications Regulations, consent-based rules for electronic marketing in the UK that apply alongside the UK GDPR. See UK PECR.

Postmaster: the role responsible for a domain's mail system. postmaster@ is a reserved address that must accept mail. Providers publish their sender requirements on "postmaster pages" (see, for example, Gmail Sender Requirements).

Preference center: a page where subscribers can change frequency, topics and channels instead of unsubscribing completely. It turns people who might have complained into subscribers who stay, at a lower frequency. See List Hygiene.

Q

Quarantine: in DMARC, the policy that asks receivers to treat failing mail with suspicion (typically by putting it in the spam folder) rather than reject it. More generally, a filter holding suspect mail. See DMARC.

R

Re-engagement (win-back) campaign: a last-chance message to inactive subscribers, asking them to confirm they are still interested before a sunset policy removes them. See List Hygiene.

Reverse DNS (PTR record): the DNS mapping from an IP address back to a hostname. Sending IP addresses need a PTR record that is not generic and that forward-confirms (see FCrDNS). Many providers reject mail from IP addresses without one. See Sending Infrastructure Practices.

S

Seed list: a panel of monitored test mailboxes at different providers, used to measure where a given message lands (inbox, tab, spam folder, or missing). Seed results tend to look worse than reality, because seed mailboxes have no engagement history. See Reputation Monitoring.

Sender reputation: the scores that receivers attach to your sending IP addresses and domains, computed from complaints, bounces, engagement, spam-trap hits, volume patterns and authentication. It decides whether mail reaches the inbox, is throttled or is blocked. See Reputation Monitoring.

Shared IP: a sending IP address whose reputation is shared by many senders. It is appropriate below the volume at which a dedicated IP makes sense, and the trade-off is exposure to how the other senders behave. See Basic IP Allocation.

SMTP: Simple Mail Transfer Protocol (RFC 5321), the transport for email between servers. Its reply codes are the raw material of bounce handling. See SMTP.

SNDS (Smart Network Data Services): Microsoft's sender dashboard, by IP address, for mail to its consumer domains. It shows volume, filter verdicts, complaint rate and trap hits, and is paired with JMRP, Microsoft's complaint feedback loop. See Microsoft SNDS & JMRP.

Soft bounce: a temporary delivery failure (4.X.X), such as a full mailbox, an unavailable server or throttling. It is retried automatically. Suppress addresses that keep soft-bouncing. See Metrics and Benchmarks.

Spam trap: an address that damages your reputation when you mail it. Pristine traps never belonged to a person, and can only be reached through bought or scraped lists. Recycled traps are abandoned real addresses turned into traps. Typo traps catch careless handling of signups. See Spam Traps.

SpamAssassin: a widely deployed open-source content filter that scores messages against sets of rules. Its scores appear in the headers of some receivers and in seed-test reports. See Deliverability Testing Tools.

SPF (Sender Policy Framework): the RFC 7208 DNS record that lists the hosts authorized to send mail for a domain, evaluated against the envelope sender. It is limited to 10 DNS lookups, and forwarding breaks it. See SPF.

Spoofing: forging a sender's identity (usually the From header) to impersonate a trusted party. SPF, DKIM and DMARC exist to counter it. See DMARC.

Sunset policy: rules that first reduce how often you mail addresses that stop engaging, then suppress them, before they decay into hard bounces or recycled spam traps (after about 12 months of inactivity). See List Hygiene and Sunset Policies.

Suppression list: the do-not-mail list of addresses that unsubscribed, hard-bounced or complained. Suppression protects your reputation, so never bypass it. See Reputation Monitoring.

T

Throttling: a receiver limiting how much mail it accepts from a sender per unit of time, which shows up as deferrals. The term also covers rate limiting on the sender's side to stay under those limits. See Metrics and Benchmarks.

TLS-RPT: a reporting channel (RFC 8460) through which receivers tell a domain about TLS negotiation failures for its inbound mail. It complements MTA-STS and DANE. See TLS-RPT.

Tracking pixel: an invisible remote image whose download registers an "open." It is the mechanism behind open metrics, and proxies that fetch images make it unreliable. See Metrics and Benchmarks.

Transactional email: mail triggered by a recipient's own action (a receipt, a password reset, a notification). It is generally exempt from marketing consent rules and from marketing suppression, but not from deliverability concerns, so keep it separate from marketing streams. See Advanced IP Segmentation.

U

Unsolicited commercial email (UCE): commercial mail sent without the recipient's permission. It is spam in the operational sense, and often in the legal sense.

Unsubscribe rate: unsubscribes as a percentage of delivered mail (healthy: under about 0.3%). An unsubscribe is a much less costly negative signal than a complaint, so make unsubscribing easy. See Metrics and Benchmarks.

V

VMC (Verified Mark Certificate): a certificate that attests ownership of a logo (usually a trademarked one). Gmail and others require it to display a BIMI logo. See BIMI.

Topics
glossary, reference, terminology
Maturity
Stable

Sources

  1. Definitions consolidated and reconciled with the existing articles of this knowledge base