An email that is successfully sent has not necessarily been delivered anywhere a person will see it. Between the send and the inbox sits a filtering decision made in milliseconds.
Authentication establishes who is sending
Receiving systems first check whether the sending server is authorised to send for that domain, and whether the message has been altered in transit. These checks use published domain records.
Messages failing authentication are heavily penalised, because forgery is the main technique behind phishing. Correct configuration is a prerequisite rather than an advantage.
A domain owner can also publish a policy telling receivers what to do with failures. That policy applies to everyone sending in the domain's name, including legitimate third-party tools.
Reputation attaches to the sender
Receivers build a reputation score for each sending domain and address, based on history. Complaint rates, bounce rates and engagement all feed it.
Reputation is slow to build and quick to damage. A single large send to a stale list can undo months of consistent behaviour within a day.
Because reputation travels with the sending identity, moving to a new domain or address does not reset it favourably. New identities start with no history, which is treated cautiously.
Recipient behaviour is the strongest signal
Opens, replies, deletions without reading and marking as spam all inform the filter. Consistent engagement from a list pushes messages toward the inbox.
Sending to unengaged addresses works against this directly. Each ignored message is a small negative signal, and volume amplifies it across the whole list.
This is why shrinking a list can improve total delivered volume. Removing recipients who never engage raises the average signal for those who remain.
List acquisition determines the ceiling
Purchased and scraped lists contain addresses that never requested contact, including inactive addresses maintained specifically to catch such sending.
Hitting those addresses damages reputation quickly and can result in blocking at the network level. Recovery from that state is slow and sometimes not possible.
Consent requirements also differ by jurisdiction, with distinct rules on opt-in, record keeping and unsubscribe handling. Compliance has to be assessed against the recipient's location rather than the sender's.
Volume patterns matter as much as content
Sudden increases in sending volume from an address with little history look like a compromised account. Filters respond by throttling or rejecting.
Warming a new sending identity means increasing volume gradually while engagement stays high. The process takes weeks, and shortcuts tend to produce exactly the reputation damage being avoided.
Steady, predictable patterns are read as legitimate operation. Irregular bursts, even of wanted mail, attract scrutiny that consistent sending never encounters.