What deliverability means
Delivery means the receiving server accepted a message. Inbox placement asks where it landed. A campaign can show as delivered and still appear in spam or a secondary tab.
Five foundations
- Send only to people with an appropriate reason and permission to hear from you.
- Authenticate the sending domain with SPF, DKIM, and DMARC.
- Remove hard bounces and suppress unsubscribes immediately.
- Use a recognizable sender and consistent domain.
- Send content that earns positive behavior over time.
Diagnose problems in order
Check authentication, bounce codes, complaint patterns, list sources, recent volume changes, and the reputation of linked domains. Don't begin by rewriting one “spammy” word.
A 30-day repair plan
Pause questionable imports, verify records, send to the most engaged permission-based segment first, simplify the template, and expand only after healthy response. Reputation is rebuilt through consistent behavior.
Why law firm emails land in spam
The most common causes
- Old, purchased, scraped, or unclear-permission lists
- Missing or misaligned domain authentication
- A sudden increase in volume
- High bounces, complaints, or disengagement
- Inconsistent sender identity
- Link shorteners or domains with poor reputation
- Messages that are mostly images or difficult to read
Start with evidence
Review bounce messages, authentication reports, complaint data, and list-source history. Ask whether the issue affects one provider, one campaign type, or the whole domain.
What won't solve it
Changing “free” to “complimentary,” adding more decorative text, or repeatedly resending to non-openers won't repair a permission or reputation problem.
A safer recovery sequence
Correct authentication, remove invalid and unpermitted addresses, narrow to engaged subscribers, send useful plain content, and increase volume gradually. Document the repair so the same shortcuts don't return.
SPF, DKIM, and DMARC without the alphabet soup
The three records
SPF
Lists the systems allowed to send mail for a domain. Keep one valid record and include every legitimate sender.
DKIM
Adds a cryptographic signature so the receiving server can verify the message was authorized and not altered in transit.
DMARC
Checks alignment, tells receivers how to handle failures, and can send reports that reveal unauthorized use.
Alignment
The domain visible to the reader should align with authenticated domains. That connection is what DMARC evaluates.
A careful rollout
- Inventory every system that sends as the firm.
- Configure SPF and DKIM with each provider.
- Publish DMARC in monitoring mode.
- Review reports and find forgotten senders.
- Tighten the policy gradually after legitimate traffic passes.
Why firms should care
Authentication supports deliverability and reduces domain impersonation risk. It isn't a complete security program, but it's foundational infrastructure for client-facing email.
