Here's a conversation I've had more times than I can count.

An owner tells me his list has gone cold. Open rates slid from the high thirties to the low teens over a couple of months. He's already decided the fix is new content. New lead magnet, new subject lines, maybe a new designer for the template.

I ask him to send one email to a Gmail address and forward me the raw message.

Three lines in the header tell the whole story. His email platform passes one check and his domain fails the other two. Gmail is quietly shoving a big chunk of his list into spam and bouncing some of the rest. His list isn't cold. His list never saw the emails.

It's usually an afternoon to fix. Opens typically come back within a few weeks.

I'm telling you this because I'd bet real money a big percentage of you have the same problem right now and don't know it. And the next three months are the worst possible time to find out, because Q4 is when everybody sends the most email of the year and the filters get the least patient.

What changed

For years, the big inbox providers had rules for bulk senders and mostly enforced them with a stern look. That era is over.

Google and Yahoo announced their requirements in late 2023. Microsoft followed with its own rules for Outlook in 2025. Then, starting in November 2025, Gmail stopped warning people and started rejecting mail that didn't meet the standard, both temporarily and permanently.

Here's what they want, in plain English.

SPF. A DNS record that lists which services are allowed to send email for your domain. Think of it as the guest list at the door.

DKIM. A digital signature on every email that proves it really came from you and wasn't tampered with on the way. The wax seal on the envelope.

DMARC. A record that ties the first two to the address people see in the From line, and tells inboxes what to do if an email fails. This is the one most small businesses are missing.

One click unsubscribe. A real unsubscribe that works in one click, and opt outs honored within two days.

A low spam complaint rate. Google's hard line is 0.3 percent. The number you actually want to live under is 0.1 percent, which means one complaint per thousand emails.

The official rules are written for senders pushing more than 5,000 emails a day to Gmail. Don't let that number make you comfortable. Inbox providers increasingly treat a missing DMARC record as a bad sign no matter how small you are, and your invoices, proposals, and appointment reminders go through the same domain your newsletter does. If your newsletter drags your domain's reputation down, your invoices go to spam with it.

The ninety minute fix

This is the exact order I run it in. You don't need to be technical. You need access to wherever your domain lives (GoDaddy, Namecheap, Cloudflare, Squarespace, whoever), and the admin login for every tool that sends email for you.

Step one: find everything that sends as you. Ten minutes.

This is the step that breaks everything when people skip it. Make a list of every service that sends email with your domain in the From line.

Your regular inbox, usually Google Workspace or Microsoft 365. Your newsletter platform. Your CRM. Your invoicing tool. Your scheduling tool. Your ecommerce platform. Your help desk. Your review request software. That form on your website that sends you a notification.

Most service businesses find between five and nine. Every one of them needs to be authenticated, or it'll fail the moment you tighten the rules.

Step two: see where you stand. Fifteen minutes.

Go to MXToolbox and run the free SPF, DKIM, and DMARC lookups on your domain. Then send a normal email from each of your sending tools to a Gmail address you control. Open it, click the three dots, choose Show original. Near the top you'll see three lines. You want all three to say pass: SPF, DKIM, and DMARC.

If any of them say fail, softfail, or none, write down which tool sent that email. That's your fix list.

Step three: clean up SPF. Fifteen minutes.

You're allowed exactly one SPF record per domain. A shocking number of businesses have two, because two different setup wizards told them to add one. Two SPF records is the same as zero. Merge them into one record that includes every sending service from step one.

It'll look something like this: v=spf1 include:_spf.google.com include:[your CRM's value] include:[your invoicing tool's value] ~all

Each tool publishes its own include value in its help docs. There's also a hidden limit of ten DNS lookups inside that record. If you're over, the whole record fails. MXToolbox will tell you your count.

Step four: turn on DKIM everywhere. Twenty minutes.

Every sending tool has a setting, usually called something like domain authentication, custom sending domain, or DKIM. It'll give you two or three records to paste into your DNS. Paste them in, go back to the tool, click verify.

Do this for every tool on your list. Not just the newsletter. The invoicing tool is the one everyone forgets, and it's the one that costs you actual money when it goes to spam.

If you're on beehiiv, it walks you through the custom domain setup in a couple of screens. If you're on Go High Level, set up a dedicated sending domain inside the email services settings instead of using the shared one. Shared sending domains mean you're borrowing a reputation from strangers, some of whom are terrible.

Step five: publish DMARC, gently. Five minutes.

Add one TXT record at _dmarc.yourdomain.com that looks like this: v=DMARC1; p=none; rua=mailto:[email protected]

The p=none part means "watch, don't punish yet." You're collecting reports for a few weeks to make sure every legitimate sender passes before you tell the world to reject anything that fails. Jumping straight to a strict policy is how people accidentally block their own invoices.

Two to four weeks later, if the reports look clean, move to p=quarantine. A few weeks after that, p=reject. Put both dates on your calendar right now or it won't happen.

Step six: split your streams. Fifteen minutes.

Your one to one email, your marketing email, and any cold outreach should never share the same reputation.

Keep your main domain for normal human email. Send marketing from a subdomain like news.yourdomain.com or mail.yourdomain.com. And if you do cold outreach, do it from a completely separate domain. Not a subdomain. A different domain. Cold email generates complaints by nature, and you don't want those complaints anywhere near the address your clients use to reach you.

Step seven: turn on the dashboard. Ten minutes.

Sign up for Google Postmaster Tools and verify your domain. It's free and it shows you, straight from Gmail, your spam complaint rate and your domain reputation. It takes a few days to populate. After that, you check it once a week for two minutes, and you'll know about a problem long before your open rates do.

That's the whole technical side. Ninety minutes, maybe two hours if your DNS is a mess.

Now clean the list

Authentication gets you through the door. Your list is what keeps you in the room.

The fastest way to wreck your reputation is sending over and over to people who never open. Inbox providers watch engagement. When a big share of your list ignores you, they conclude your email probably isn't wanted, and they start filtering it for the people who do want it.

Here's the rule I use.

Sunset anyone who hasn't clicked in 120 days.

Notice I said clicked, not opened. Apple Mail Privacy Protection preloads emails and fakes an open on a big chunk of iPhone users, so open data is inflated and mushy. Clicks are real.

Before you remove anyone, give them one chance. At ninety days of no clicks, drop them into a short re-engagement sequence. Two or three emails. Plain, honest, a little funny. "Still want these? Click here to stay on the list. If not, no hard feelings, I'll stop showing up." Anyone who clicks stays. Anyone who doesn't gets suppressed at day 120.

You can automate the whole thing. In most platforms it's a segment and a workflow. If your tools don't talk to each other, Make.com can watch for the no click condition and move people between lists without you touching it.

Yes, your list gets smaller. Your revenue from email almost always goes up. A list of 4,000 people who want to hear from you beats a list of 11,000 where 7,000 are dragging your whole domain into the spam folder.

A few more hygiene rules while you're in there.

Remove hard bounces immediately. Most platforms do this for you. Check that yours does.

Remove role addresses you added manually, like info@, admin@, and sales@. They rarely belong to a real person who asked for your email.

Use double opt in on your lead magnets. It costs you a few percent of signups and saves you from typos, bots, and spam traps that quietly poison your list.

Write like a person

Spam filters are much smarter than they used to be, but a few habits still raise flags.

Emails that are one giant image with almost no text. Link shorteners, which spammers love because they hide the destination. Six different links to six different domains. Attachments in marketing email. A From name that changes every week.

Write emails that look like they came from a human. Mostly text. A couple of links, all to your own domain or well known sites. Same From name every time. If you want a gut check before a big send, ChatGPT is pretty good at spotting phrasing that reads like a sales flyer. Paste the email in and ask it what a skeptical reader would flag.

Don't blast your list on Black Friday

This one's timely, so pay attention.

Every year, somebody with a list of 9,000 people who they've emailed twice since spring decides to send three promotional emails in four days over Thanksgiving weekend. Their complaint rate spikes, their reputation tanks, and their January emails go to spam.

Inbox providers like consistency. If you normally send twice a month, you can't suddenly send eight times in two weeks to your whole list without paying for it.

If you're planning a Q4 push, ramp up now. Start sending on a steady weekly rhythm in October. When the promo goes out, send it to your most engaged segment first, people who clicked in the last sixty days. Watch complaints for twenty four hours. Then widen it.

Your Q4 inbox calendar

This week. Run the ninety minute fix. Publish DMARC at p=none.

October 12. Set up Postmaster Tools if you didn't already. Build the re-engagement sequence.

October 19. Run the re-engagement sequence on everyone past ninety days without a click.

October 26. Review your DMARC reports. If every legitimate sender passes, move to quarantine.

November 16. Suppress the non responders. Move DMARC to reject if the reports are still clean.

Thanksgiving week. Send to engaged segments first. Watch complaints. Widen carefully.

The kit

I've fixed this for enough clients now that I stopped doing it from memory. So I built the whole thing into one working document.

The Inbox Fix Kit has the full audit checklist, the exact DNS record templates with the common include values already filled in for the tools most service businesses use, a DMARC rollout schedule with the dates to move from none to quarantine to reject, the sunset automation built out step by step, three re-engagement emails ready to paste, a weekly two minute monitoring scorecard, and a troubleshooting table that tells you what the most common Gmail and Outlook bounce codes actually mean and what to do about each one.

It's the document I open when a client tells me their list went cold. Most of the time, it didn't.

Talk Soon,

Dan

Dan Kaufman

Founder, Dead Simple Growth and Pinnacle Masters

P.S. Reply with INBOX and I'll send you The Inbox Fix Kit. If you paste the three lines from your Show original header (SPF, DKIM, DMARC) into the same reply, I'll tell you exactly which one is breaking and where to fix it.

Keep Reading