Skip to content
Mailwel
Theme
Foundations · updated 2026-10-02

Signal Flow

See how signals move between senders, receivers, and mailbox providers to shape inbox decisions.

Every email you send gives off signals: clues that a mailbox provider uses to decide whether to trust it. This article follows those signals from you, to the provider, to the reader, and back again. Once you see the loop, you can see why one bad send hurts the next ones, and why recovery takes time.

Three parties, one flow

Three parties shape every inbox decision:

  • You, the sender. Your setup and your email give off the first signals.
  • The mailbox provider (the company that hosts the reader’s inbox, such as Gmail or Outlook.com). It reads the signals and decides where the email goes.
  • The reader. What they do with your email becomes a signal for next time.

No single check decides the result. The provider adds up signals from every stage.

Stage 1: what you send out

Before your email reaches the provider, you have already sent many signals.

Your servers

  • The IP address (the internet address of the server that sends your email) and its history.
  • Reverse DNS (a record that turns the IP address back into a name, like mail.shop.example).
  • TLS (encryption of the connection between your server and theirs).
  • The HELO name (the name your server introduces itself with when it connects). It should be a real name that matches your reverse DNS.

Your authentication

Authentication proves an email really comes from the domain it claims.

  • SPF (a DNS record that lists the servers allowed to send email for your domain). The provider checks whether the sending IP address is on that list.
  • DKIM (a digital signature on each email). It proves your domain sent it and nobody changed it on the way.
  • DMARC (a DNS record with your policy). It asks: does SPF or DKIM pass for the domain in the From address? If not, it tells the provider whether to deliver, send to spam, or reject.
  • ARC (extra headers added when an email is forwarded). They record that the email passed checks before a forwarding service changed it.

The email itself

  • The From, Reply-To and Return-Path addresses, and whether they use the same domain.
  • The subject line, such as shouting in ALL CAPS or fake urgency.
  • How the HTML is built, and whether it is mostly images.
  • The links, and the reputation of the domains they point to.
  • Attachments.
  • A List-Unsubscribe header (a hidden line that lets the reader’s app show an unsubscribe button).

Perfect IP reputation won’t save an email with a broken DKIM signature. More good signals give a better score.

Stage 2: how the provider checks it

When your email arrives, the provider runs it through several checks.

Connection IP, blocklists Authentication SPF, DKIM, DMARC Content links, layout Reputation domain, IP Engagement this reader Bad IP: rejected you get a 5xx bounce Each check raises or lowers the score One combined score inbox, spam folder or dropped
Each check adds to or lowers one score. A bad sending server can be turned away before the rest even run.
  1. Connection. The provider’s receiving server checks your IP address against blocklists (public lists of servers known to send spam, such as Spamhaus). It also checks reverse DNS and how fast and how often you connect. A server with a very bad reputation is rejected right away with a 5xx error, which you see as a bounce.
  2. Authentication. It checks SPF, DKIM and DMARC and writes the results into an Authentication-Results header. A failure doesn’t always mean rejection. It usually lowers the score.
  3. Content. It scans the body, headers and links. Modern filters look for patterns learned from huge amounts of mail, not single “spammy” words. An email built like typical spam scores badly even if the words are harmless.
  4. Reputation. It adds your history: how your domain, your IP address and your links have behaved over weeks and months. On a shared IP address (one many senders use), the other senders’ behaviour counts too.
  5. Engagement prediction. It guesses how likely this reader is to want the email. It uses the reader’s past reactions to you, the kinds of email they usually read, and how similar readers treat similar emails.

The last step is why the same email can reach one person’s inbox and another person’s spam folder.

You can see the authentication results yourself. Paste an email’s headers into the header analyzer, or send one to the test inbox.

Stage 3: how the reader reacts

After the email is filed, the reader’s actions become new signals.

  • Good signs: opening it (especially soon after it arrives), clicking, replying, forwarding, moving it out of spam, adding you to contacts.
  • Bad signs: marking it as spam (the strongest bad signal), deleting it unread, ignoring your emails again and again.
  • Mild signs: an unsubscribe shows lost interest, but it is much better for you than a spam report.
  • Silence: if someone never opens or clicks your emails for months, the provider decides your emails don’t matter to them.

The feedback loop

These three stages form a loop. Each send changes how the next one is judged.

1. You send a newsletter, a receipt… 2. Provider scores it inbox, spam or dropped 3. Readers react open, ignore, complain 4. Reputation updates rises or falls Every send shapes how the next is judged
Readers' reactions update your reputation, and that reputation shapes the next send.

Momentum

Good results build on each other. Readers engage, so the provider trusts you more. More of your next emails reach the inbox, so more people can engage.

Bad results build on each other too. Fewer emails reach the inbox, so fewer people engage, so trust drops further. That is why problems speed up. Watch for early warnings, like falling opens or more soft bounces (temporary delivery failures). Act before they turn into a slide.

Delay

Providers don’t update your reputation instantly. A send with many complaints on Monday may only hurt your placement days later. If you keep sending in the meantime, you add to the damage. Each provider updates at its own speed, and none publishes exactly how fast.

Slow up, fast down

Trust Time Slow climb weeks of good sending One bad campaign fast drop Slow recovery weeks again
Trust builds over weeks but can fall in one send. Recovery is slow again.

Building trust is slow. Losing it is fast. Providers do this on purpose, because protecting their users matters more to them than any one sender.

  • One campaign with many complaints can drop your reputation.
  • Earning it back usually takes weeks of clean, steady sending.
  • Getting off a blocklist can take days or weeks, even after you fix the cause.

Preventing damage is always cheaper than repairing it.

Which signals matter most

Providers keep their exact formulas secret. Testing across the industry shows a rough order, from strongest to weakest:

  1. Spam complaints, spam traps and engagement. A spam trap is an address that exists only to catch senders with bad lists.
  2. Reputation, authentication and bounces. Bounces are emails sent back as undeliverable.
  3. Sending patterns, link reputation and how you collected your list.
  4. Subject wording, HTML quality and image-heavy design.

What you do as a sender counts far more than the words in your email. The signal game covers this order in detail.

What you can and can’t see

Most signals are hidden from you.

You can see:

  • Bounce and rejection messages from receiving servers.
  • Feedback loops (complaint reports some providers send when a reader marks your email as spam).
  • DMARC aggregate reports (daily reports of which servers sent email as your domain, and whether they passed).
  • Google Postmaster Tools (Gmail’s free dashboard showing your spam rate and authentication results).
  • Microsoft SNDS (Microsoft’s free data on how your IP addresses behave at Outlook.com).

You can’t see:

  • How each reader’s behaviour is scored.
  • The details of the content score.
  • The exact limits that trigger spam placement.
  • Silent drops (emails accepted and then deleted, with no bounce).
  • Whether an email went to spam, unless you test with real inboxes.
  • How much each provider weighs each signal.

This gap is why you need inbox placement tests. Without them, you can’t tell where your emails actually land.

What to do next

  • Authenticate everything. Set up SPF, DKIM and DMARC. They don’t guarantee the inbox, but failing them almost guarantees spam. Check them with DNS lookup.
  • Watch engagement. Track opens, clicks and complaints for each send, list segment and provider.
  • Respect the loop. When engagement drops, send less, and send to your most active readers first. Don’t push harder.
  • Test placement directly. Delivery rates don’t show spam placement. Use the test inbox or seed tests (test emails to your own accounts at each provider).
  • Allow for delay. Improvements show up slowly. Act fast on damage.
  • Change gradually. Sudden changes in volume, content or audience make providers defensive.