Prompt
My password reset emails are going to spam
Latest observation
That usually means one or more of your email deliverability signals is weak or misconfigured. For password reset emails specifically, inbox providers are especially strict because they’re high-risk transactional messages.
Here’s a practical checklist to fix it:
1) Make sure authentication is set up correctly
You should have all of these on your sending domain:
- SPF
- DKIM
- DMARC
Best practice:
- SPF includes your sending service
- DKIM is enabled and signing with your domain
- DMARC exists and aligns with SPF/DKIM
If these are missing or broken, spam placement is much more likely.
2) Send from a dedicated subdomain
Use something like:
no-reply@notify.example.comsecurity@example.com
This keeps password reset mail separate from marketing mail and protects your main domain reputation.
3) Check your email content
Password reset emails should be:
- Plain and clear
- Free of spammy words like “urgent!!!”, “act now”, “free”
- Not image-heavy
- Not overly formatted
- Include your brand name and why the email was sent
A good reset email should say something like:
- “You requested a password reset”
- “If you didn’t request this, you can ignore this email”
4) Make sure links are clean
Bad link practices can trigger spam filters:
- Avoid link shorteners
- Don’t use mismatched domains
- Ensure the reset link domain matches your sending domain or your trusted app domain
- Use HTTPS
5) Warm up your sending reputation
If this is a new domain, new subdomain, or new provider:
- Start with lower volume
- Increase gradually
- Avoid sudden spikes
6) Keep complaint and bounce rates low
Even transactional mail gets penalized if:
- Too many messages bounce
- Users mark them as spam
- You send to invalid addresses
7) Verify your DNS and mail settings
Check:
FromdomainReturn-Path- DKIM signing domain
- DMARC alignment
Misalignment between these can hurt delivery even if authentication technically exists.
8) Separate transactional from marketing
Do not send password resets from the same infrastructure as newsletters/promos if possible. Transactional mail should have:
- Separate IP or sender stream
- Separate subdomain
- Separate reputation
9) Test with deliverability tools
Use tools like:
- Mail-Tester
- GlockApps
- Postmaster tools from Google/Microsoft
- Your email provider’s deliverability dashboard
These can show:
- Authentication failures
- Content issues
- Blacklist problems
- Reputation issues
10) Check if your provider is the problem
Some ESPs are better than others for transactional mail. If you’re using a shared IP pool, another sender’s behavior may be hurting you. A dedicated IP or better transactional provider may help.
Quick diagnosis order
If you want the fastest path:
- Confirm SPF/DKIM/DMARC pass
- Send from a subdomain
- Simplify the email content
- Check sender reputation/postmaster tools
- Move transactional mail to a separate stream or IP
If you want, I can help you troubleshoot this step by step. If you share:
- your sending provider
- your sending domain/subdomain
- whether SPF/DKIM/DMARC are set up
- a sample of the email headers
…I can tell you what’s most likely causing the spam placement.