Every message you send is judged before a human ever sees it. In the fraction of a second between your server opening a connection and the receiving server deciding what to do, an algorithm asks one question: do we trust this sender? The answer is your sender reputation, and it is the largest single variable in whether your campaigns reach the inbox.
Reputation is not a setting, a certification, or something you can buy. It is a rolling verdict on your past behaviour, recalculated continuously, and it can be dismantled by a single careless campaign far faster than it was built. This guide explains what actually feeds that verdict, how to see it, and how to repair it when it breaks.
Sender reputation is a trust score that mailbox providers assign to the entities you send from — your domain, your subdomains, and the IP addresses your mail leaves through. It is derived from how recipients have historically responded to you: whether they opened, replied, deleted without reading, or reached for the spam button.
Three properties make it behave differently from most marketing metrics, and misunderstanding them causes most of the mistakes in this area.
There is a fourth property worth naming because it frustrates teams new to the discipline: reputation is not fair. Providers optimise for their own users' inbox experience, not for your campaign calendar. A legitimate sender with a technically clean setup can still be filtered if recipients consistently ignore the mail.
Senders often treat these as one thing. They are not, and the distinction determines what you can and cannot fix.
| Domain reputation | IP reputation | |
| What it is attached to | Your sending domain and subdomains | The specific server IP address that connects |
| Who it follows | You — it travels with you between platforms | The infrastructure — it stays behind when you migrate |
| Primary weight at | Gmail, Yahoo, Apple, and increasingly Microsoft | Microsoft and traditional spam filters |
| Time to build | Weeks to months | Days to weeks with consistent volume |
| Can you escape a bad one? | Only by burning the domain — expensive and disruptive | Yes, by moving to a new IP or pool |
| Main lever | Recipient engagement and complaint behaviour | Volume consistency, bounces, and trap hits |
| Who owns the fix | Marketing — list and content decisions | Operations — sending patterns and infrastructure |
The practical implication is that domain reputation is the one to protect. IP reputation is recoverable — worst case, you move to a new IP and warm it. A burned domain is a different problem entirely, because rebuilding means either a long remediation period or abandoning a domain your brand is attached to.
This is also the argument for subdomain separation. Sending marketing from news.yourbrand.com and transactional mail from mail.yourbrand.com means reputation largely accrues at the subdomain level. A campaign that generates complaints damages the marketing subdomain, while password resets and receipts continue to arrive from an untouched one.
Providers do not publish their weightings, but years of observed behaviour and their own published guidance make the inputs clear. They fall into four groups, roughly in order of impact.
When a recipient presses "report spam", it is the strongest negative signal available to a provider, because it is a direct human judgement rather than an inference. Google and Yahoo ask senders to stay below 0.10% and treat 0.30% as the threshold that triggers filtering.
Those numbers are smaller than they look. At 0.30%, three complaints per thousand delivered messages is enough to damage you — a rate most teams would never notice in a campaign report. Treat 0.10% as your ceiling and investigate anything above 0.05%.
Positive recipient behaviour is what builds reputation rather than merely avoiding harm. Opens matter least, because privacy protection features inflate them. Clicks, replies, forwards, adding you to contacts, and — most powerfully — moving a message out of the spam folder all tell the provider its filtering was wrong.
The inverse is also weighed: deleting without opening, and prolonged silence, both drag your score down. This is why sending to a large dormant segment is actively harmful rather than merely inefficient. The messages that never get opened are not neutral.
Hard bounces indicate you are sending to addresses that do not exist, which suggests your list was bought, scraped, or simply never cleaned. Keep hard bounces below 0.5% per send and remove them immediately.
Spam traps are worse. Pristine traps are addresses that never belonged to a person and exist solely to catch senders using scraped or purchased data. Recycled traps are abandoned real addresses that a provider has reactivated to catch senders who never clean their lists. A single pristine trap hit can produce a blocklist entry; recycled traps are the reason a sunset policy is not optional.
Providers build a model of your normal sending pattern. Sudden departures from it read as compromise. A domain that sends 5,000 messages weekly and then abruptly sends 200,000 looks like a hijacked account, regardless of your intent.
Authentication consistency matters in the same way. SPF, DKIM and DMARC that pass on 99% of messages and fail intermittently on the rest signal a misconfiguration somewhere in your sending estate — usually a forgotten third-party tool sending under your domain without authorisation. Your DMARC aggregate reports will name it.
Since no provider exposes its score directly, monitoring means triangulating from several sources. None of these is sufficient alone; together they give a reliable picture.
| Tool | What it shows you | Cost | Best for |
| Google Postmaster Tools v2 | Compliance pass/fail across 8 requirements, user-reported spam rate, delivery errors, authentication success | Free | Every sender — this is the single most important dashboard |
| Microsoft SNDS | Filter status (green/yellow/red), complaint rate bands, spam trap hits, sending volume per IP | Free | Anyone sending to Outlook, Hotmail or Live addresses |
| DMARC aggregate reports | Every source sending under your domain, with SPF and DKIM alignment results | Free (a parser is usually paid) | Finding unauthorised or misconfigured senders |
| Sender Score (Validity) | A 0-100 rating of a sending IP, on a rolling 30-day window | Free lookup | A rough external sanity check on IP health |
| Blocklist monitoring | Whether your domain or IP appears on Spamhaus, SURBL, Barracuda and others | Free lookups; paid alerting | Catching a listing before your next campaign |
| Seed / inbox placement testing | Actual folder placement across providers, from a panel of seed accounts | Paid | The only way to see inbox vs spam placement directly |
Set these up before you have a problem. Postmaster Tools and SNDS both report on a delay and only accumulate data from the point of registration, so a sender who registers during a crisis has no baseline to compare against and no history to diagnose from.
For years, the domain and IP reputation charts in Google Postmaster Tools were the closest thing senders had to a published reputation score, graded from Bad through Low and Medium to High. Google deprecated those charts on 30 September 2025 and retired the legacy interface the following month.
Postmaster Tools v2 replaced the gradient with a Compliance Status dashboard reporting a straightforward pass or fail against eight requirements — six technical, covering SPF and DKIM authentication, From-header alignment, DMARC, TLS, valid DNS records and one-click unsubscribe, and two behavioural, covering the user-reported spam rate and whether unsubscribes are honoured within 48 hours. The API gained date-range queries, batch lookups across multiple domains, and a dedicated compliance status method.
The change is worth understanding correctly. Google did not stop scoring reputation; it stopped showing you the gradient. Reputation still governs filtering exactly as before. What senders lost is early warning — the slow slide from High to Medium that used to give you weeks of notice. What remains is the user-reported spam rate, which is now your primary leading indicator, and the compliance flags, which are binary.
In practice this raises the value of two things: watching your spam rate daily rather than weekly, and running seed tests, since inbox placement testing is now the only way to observe placement directly.
Reputation usually degrades gradually. Blocklists are the exception — a listing is a step function, and mail can stop arriving overnight. Spamhaus is the most consequential operator, and its lists work differently from one another.
| List | What triggers a listing | How you get delisted |
| CSS (Combined Spam Sources) | Automated detection of poor list hygiene, compromised accounts and weak marketing practice. This is the list ordinary senders hit most often. | Automatic — stop the sending pattern and it clears on its own |
| SBL (Spamhaus Blocklist) | Manually researched spam sources, snowshoe sending, malware and phishing | Manual — contact Spamhaus and demonstrate the abuse has stopped permanently |
| XBL (Exploits Blocklist) | Individual IPs showing signs of compromise: malware, hijacked hosts, stolen SMTP credentials | Self-service once the compromise is cleaned; listings also auto-expire |
| PBL (Policy Blocklist) | Consumer and end-user IP ranges that should never send mail directly to a recipient's mail server | Self-removal where policy allows, but the real fix is to send through an authenticated relay |
| DBL (Domain Blocklist) | Domains associated with phishing, malware, fraud, or hijacked legitimate domains | Automated — remove the offending content or activity and the listing clears |
Most legitimate senders who get listed land on CSS, and the good news is that CSS delisting is automatic: stop the pattern that triggered it and the listing clears. The bad news is that it will re-list if the behaviour resumes, so treating the symptom without fixing the list hygiene underneath simply produces a cycle.
One rule is absolute across every reputable blocklist: delisting is free. Any service offering to remove a Spamhaus listing for a fee is a scam, and paying it changes nothing.
There is no single reputation. You hold a separate one with each provider, and they weigh the inputs differently enough that your placement can be excellent at one and poor at another. A drop confined to a single provider is diagnostically useful, because it narrows the cause immediately.
Gmail leans hardest on the authenticated domain and on recipient engagement, and it is the most responsive to positive signals — a genuinely engaged audience recovers faster at Gmail than anywhere else. It is also where the user-reported spam rate is most visible to you, through Postmaster Tools.
Microsoft retains more weight on IP reputation than the others, which is why SNDS remains relevant and why a shared IP pool can hurt you at Outlook while causing no visible problem at Gmail. Microsoft is also the least forgiving on volume spikes from unfamiliar IPs.
Yahoo publishes requirements closely aligned with Google's and behaves similarly, though it offers senders far less diagnostic visibility. In practice, Yahoo placement tends to track Gmail placement, so fixing Gmail usually fixes Yahoo.
Apple provides almost no sender-facing tooling, so its behaviour is inferred rather than observed. It broadly follows the same authentication expectations and weighs engagement heavily, with Mail Privacy Protection making open data from Apple recipients unreliable as a signal for your own analysis.
If placement drops everywhere simultaneously, look at authentication or a blocklist. If it drops at one provider, look at reputation and at what that provider's audience segment has been receiving.
Validity's Sender Score is the best-known commercial reputation metric, rating a sending IP from 0 to 100 on a rolling 30-day window. Above 80 is considered good, 70 to 80 fair, and below 70 poor. It draws on five inputs: complaint rates ranked against other IPs, sending volume, external reputation data including blocklists, mail sent to unknown users, and rejected messages.
It is a useful sanity check, and a sharp drop is a genuine warning worth acting on. But its limits should be stated plainly.
Use it as one input among several. Do not use it as a target, and be sceptical of any vendor that presents it as the definitive measure of your health.
A new domain or IP has no reputation, which is not the same as a good one. Unknown senders are treated cautiously by default, and the way you behave in the first six weeks sets a baseline that is hard to change later.
Warm up gradually. Begin with a few hundred messages a day to your most engaged subscribers — the people most likely to open, click and reply. Roughly double every two to three days, and hold at each step until complaint and bounce rates confirm the previous increase was absorbed cleanly. Expect four to six weeks to reach full volume.
Send your best content first. Warm-up sends should be the campaigns with your highest historical engagement, because you are actively teaching the provider what response your mail generates. Starting with a broad promotional blast teaches the wrong lesson.
Authenticate before the first send, not after. Publish SPF, DKIM and DMARC at p=none, and verify alignment on a test message before any volume goes out.
Be honest about automated warm-up tools. Gradual volume ramping is legitimate and necessary. Warm-up networks that exchange artificial replies between pools of seed accounts are a different thing, and providers have become good at recognising that traffic pattern and discounting the engagement it manufactures — sometimes penalising it.
If placement has dropped and you have confirmed authentication is clean, this sequence rebuilds trust. It requires holding your nerve on volume, which is usually the hardest part organisationally.
If placement has not improved measurably by the end of week six, the problem is unlikely to be reputation alone. Re-examine authentication alignment, check whether a third-party service is sending under your domain, and consider whether the content itself is generating complaints.
Sender reputation is the accumulated record of how people have responded to your mail, and it is the mechanism by which mailbox providers decide whether to trust you tomorrow. It cannot be bought, and it cannot be argued with — it can only be earned by sending mail that people want, to people who asked for it, at a rhythm they expect.
The practical programme is unglamorous and effective: authenticate properly and keep it passing, watch your complaint rate daily rather than weekly, segment by engagement and let dormant subscribers go, warm new infrastructure patiently, and register for the free provider dashboards before you need them. Do that consistently and reputation stops being something you fix and becomes something you simply have.
Q1. What is sender reputation in email marketing?
Sender reputation is the trust score mailbox providers assign to your sending domain and IP address based on how recipients have historically responded to your mail. It is calculated from complaints, bounces, spam trap hits, engagement and authentication consistency, and it is the single largest factor in whether your campaigns reach the inbox or the spam folder.
Q2. What is a good sender reputation score?
There is no single number, because each provider maintains its own private score. As external proxies, a Validity Sender Score above 80 is considered good and below 70 is poor, while a green filter status in Microsoft SNDS and a full pass in Google Postmaster Tools indicate a healthy sender. Treat all of these as directional rather than definitive.
Q3. Can I still see my domain reputation in Google Postmaster Tools?
No. Google deprecated the colour-graded IP and domain reputation charts on 30 September 2025 and retired the legacy interface in October 2025. Postmaster Tools v2 replaced them with a Compliance Status dashboard that reports a pass or fail against eight specific requirements, alongside the user-reported spam rate.
Q4. Does sender reputation follow my domain or my IP?
Both, but they behave differently. Domain reputation travels with you when you change sending platforms, which is why a damaged domain is expensive to fix. IP reputation stays with the infrastructure, so migrating to a new IP resets it, though you then have to warm the new IP from scratch.
Q5. How much does one bad campaign hurt my reputation?
More than most senders expect. Complaint rates are measured over rolling windows rather than per campaign, so a single send that pushes you above the 0.30% line can suppress inbox placement for several weeks after the campaign is over. Recovery takes disciplined sending, not time alone.
Q6. How long does it take to repair a damaged sender reputation?
Plan for four to eight weeks. Because reputation is calculated over rolling windows, providers need a sustained run of low-complaint, high-engagement sends before the score moves. There is no way to accelerate this, and attempting to by increasing volume makes it worse.
Q7. Should I just move to a new domain if my reputation is bad?
Almost never as a first move. A fresh domain has no reputation at all, which means starting a warm-up from zero while carrying over the list and habits that caused the original problem. Fix the underlying cause first; a new domain is a last resort after remediation, not instead of it.
Q8. Do third-party reputation scores affect whether Gmail delivers my mail?
No major mailbox provider has publicly confirmed using Validity's Sender Score or similar commercial scores in its filtering decisions. They are useful external indicators, but you can hold a perfect score and still land in spam, because these tools cannot see the engagement and content signals the providers actually weigh.
Every provider requirement, threshold and date in this article was verified against the sources below. Re-check them before publication if more than a quarter has passed, since mailbox provider rules continue to change.
