Mail stopped arriving. Working back to the cause

Open rates have halved, or a customer has told you their mail's in junk, or a provider has started rejecting outright. The instinct is to clean the list, and the list is only one of four possible causes.

Order matters here more than effort. You can fix an authentication problem in an afternoon. A reputation problem takes weeks. Cleaning a list when the real fault is a broken DKIM record wastes both the money and the weeks.

The order the work happens in

  1. Read a bounce message before theorising

    The rejection text usually names the reason and sometimes links to the provider's page about it. It's the cheapest diagnostic available and the one people skip most.

  2. Check authentication first

    SPF, DKIM and DMARC, against the domain that is actually sending. Gmail and Yahoo have required authentication from bulk senders since 2024, and a failure here rejects mail regardless of how clean the list is.

  3. Check the blocklists next

    Your sending IP and domain against the major lists. A listing explains a sudden collapse better than anything gradual does, and the remedy is a delisting process rather than a data project.

  4. Look at what changed in the sending pattern

    A volume spike, a new sending domain, a new provider or a big import. Deliverability rarely degrades for no reason, and the reason's usually sitting on a calendar.

  5. Then verify, and only send to the engaged

    Once the first four are settled, cut back to the people who opened something recently and rebuild volume slowly. Verification belongs here rather than at the start.

What each result means here

The same four results and their flags, read against this job. A catch-all worth keeping in one situation is one to exclude in another.

ResultWhat to do with it
ValidThe rebuild segment, but only where these addresses have also engaged recently.
InvalidRemove. During recovery the tolerance for bounces is lower than usual.
Catch-allExclude entirely until the numbers are healthy. You cannot confirm these and recovery is the wrong time to gamble.
UnknownExclude for now. Re-test a sample after a few clean weeks.
Role flagExclude during recovery. Role addresses generate a disproportionate share of complaints.
Disposable flagRemove permanently. There is no version of recovery in which these help.

How you know it is finished

Authentication passes on the sending domain, no blocklist shows an entry, and three consecutive sends to the engaged segment land with a normal open rate. Volume goes back up after that, not before.

What this does not fix

During recovery you should be sending to a fraction of the list, so the check is small: the engaged segment of a 200,000-contact database is frequently under 20,000 addresses, which is $25 of credits.

Questions people ask

Why did deliverability drop suddenly rather than gradually?

A sudden collapse usually means a blocklist entry or an authentication change. Gradual decline points at list decay or falling engagement, and the two need completely different work.

How long does recovery take?

Authentication fixes take effect within a day. Reputation recovery runs over weeks of consistent low-volume sending to people who engage, and there is no way to buy speed there.

Should I switch to a new sending domain?

Rarely, and never as your first move. A new domain has no reputation at all, and that frequently performs worse for you than a damaged one while you rebuild from zero.

Try it on the file in front of you

100 free checks a month, no card. Addresses we could not get an answer on come back labeled as unknown, and those are not billed.