Delivery is not dependent on authentication

All too often folks come to me with delivery problems and lead off with all of the things they’ve done to send mail right. They assure me they’re using SPF and DKIM and DMARC and they can’t understand why things are bad. There is this pervasive belief that if you do all the technical things right then you will reach the inbox.

Getting the technical bits right is an important part of demonstrating you’re a legitimate sender but it’s not, on its own, sufficient to reach the inbox. All you need to do is look at some of the mail in your junk folder to see that even companies with full DMARC can sometimes reach the spam folder (the Uber example, again).

To put it another way, spammers regularly get all the technical bits right and implement best practices, often in better ways than actual companies. Their mail still goes to the spam folder because, well, it’s spam. They even do things like pass lists through data hygiene companies and sometimes even pay attention to engagement on some levels.

What really drives delivery, particularly at the consumer mailbox providers, is engagement.

pie chart showing more than 80% of inbox is dependent on reengagement, with 10% attributed to technical practices and 10% attributed to authentication practices.

The big drivers of engagement are having permission to send email and sending mail users want to receive and interact with.

pie chart showing 75% of engagement is about the content you send, with 25% being about what kind of permission you have.

Authentication is there so that the filtering engines know what mail is actually from you. It allows them to be really harsh on spam forging your domain or sent without your authority and still delivering your legitimate mail to the inbox. If your mail is fully authenticated and still going to the bulk folder, then the problem is related to your email. Something you’re doing, whether it’s a permission problem or an engagement problem or whatever, is making the filters think your mail isn’t wanted.

Fixing authentication isn’t going to fix delivery problems caused by authenticated email.

Related Posts

Phishing and authentication

This morning I got a rather suspicious message from a colleague on LinkedIn.

Read More

The many meanings of opt-in

An email address was entered into our website

An email address was associated with a purchase on our website.

Read More

TWSD: Using FOIA requests for email addresses

Mickey has a good summary of what’s going on in Maine where the courts forced the Department of Inland Fisheries and Wildlife to sell the email addresses of license purchasers to a commercial company.
There isn’t permission associated with this and the commercial company has no pretense that the recipients want to receive mail from them. This is a bad idea and a bad way to get email addresses and is no better than spammers scraping addresses from every website mentioning “fishing” or “hunting.”

Read More