Prompt
How do I stop password reset emails going to spam?
Latest observation
To reduce password reset emails landing in spam, focus on authentication, sending quality, and email content:
1) Authenticate your domain properly
Make sure these are all set up and passing:
- SPF
- DKIM
- DMARC (start with
p=none, then tighten later)
Also ensure the From domain matches your authenticated sending domain.
2) Send from a reputable, consistent address
Use a stable sender like:
no-reply@yourdomain.comsecurity@yourdomain.com
Avoid changing sender domains or “From” names often.
3) Use a trusted email provider
If you’re sending via your own server, consider moving password reset emails to a dedicated transactional provider like:
- SendGrid
- Mailgun
- Postmark
- Amazon SES
These usually have better deliverability for system emails.
4) Keep the email simple and expected
Spam filters dislike marketing-style formatting in reset emails. Keep it:
- Plain and concise
- One clear CTA button or link
- No excessive images, attachments, or tracking pixels
- No sales language like “limited offer” or “urgent reward”
5) Make the content clearly transactional
Use subject lines like:
- “Reset your password”
- “Password reset request”
Avoid:
- ALL CAPS
- Too many punctuation marks
- Suspicious wording like “verify immediately”
6) Make sure your links are safe and consistent
- Link to your own domain
- Use HTTPS
- Avoid URL shorteners
- Don’t use mismatched or redirect-heavy links
7) Keep complaint and bounce rates low
If people are marking the messages as spam:
- Review send logs
- Remove invalid addresses
- Check for retry loops or duplicate sends
- Ensure reset emails only go to users who requested them
8) Set up a good domain reputation
- Warm up a new sending domain/IP gradually
- Use a dedicated subdomain for transactional email, e.g.
mail.yourdomain.com - Monitor reputation in Gmail Postmaster Tools and Microsoft SNDS if applicable
9) Check your inbox placement with major providers
Test at:
- Gmail
- Outlook/Hotmail
- Yahoo
- iCloud
Use seed tests or tools like GlockApps / Mail-Tester to see what’s failing.
10) Avoid common spam triggers
Examples:
- “Free”, “winner”, “urgent”, “act now”
- Too many images
- Large HTML templates
- Broken HTML
- Hidden text
- Attachments
If you want, I can also give you a deliverability checklist or help you review your SPF/DKIM/DMARC records.