Why Recruitment Emails Land in Spam — and What Actually Improves Deliverability
Poor reply rates do not always mean poor copy. Your messages may be rejected, delayed or filtered before the recipient seriously considers them. Here is how authentication, recipient complaints, address quality, sending patterns and UK marketing rules affect recruitment email deliverability.
There is an uncomfortable possibility behind a weak outreach campaign: the recipient may never have seen the message.
Some emails are rejected before delivery. Others are accepted by the receiving server but placed in junk. Some arrive in an inbox category the recipient rarely checks. Others are delivered perfectly well and simply ignored.
These are different problems, and reply rate alone cannot tell you which one you have.
Before rewriting every subject line, examine whether your messages are being authenticated, accepted and delivered—and whether the people receiving them have a reasonable reason to welcome them.
Email deliverability is not a trick for defeating spam filters. It is the result of appearing to mailbox providers and recipients like a legitimate, responsible and relevant sender.
Why recruitment outreach is vulnerable
Recruitment agencies rely heavily on email. A consultant may contact candidates, hiring managers, former clients and prospective clients throughout the working day.
That activity can produce some of the same warning signals mailbox providers associate with unwanted email:
- A sudden increase in sending volume
- Similar messages sent to many people
- Messages sent to old or invalid addresses
- Recipients deleting emails without engaging
- People marking messages as spam
- Repeated sending after an opt-out
- New domains or mailboxes beginning at high volume
- Sending systems that are not properly authenticated
A filter cannot assess whether a consultant had good intentions. It can assess technical authentication, sending behaviour and recipient feedback.
Google warns that frequent spam reports can reduce a domain's reputation and make future messages more likely to be classified as spam. It advises senders to monitor domain and IP reputation rather than treating each campaign as an isolated event.
That cumulative effect is what makes deliverability commercially important. A badly targeted campaign can affect later messages, including relevant emails sent to people who genuinely want to hear from you.
Delivery is not the same as reaching the inbox
Email reporting can give a false sense of certainty.
A message marked as "sent" has normally left your system. That does not necessarily mean it reached the recipient's primary inbox.
Possible outcomes include:
- Delivered to the inbox: The message reached a visible inbox location.
- Delivered elsewhere: The provider accepted it but placed it in junk, spam or another filtered category.
- Deferred: The receiving server temporarily delayed the message, often because of rate or reputation concerns.
- Soft bounce: Delivery failed temporarily, perhaps because the mailbox was full or the receiving server was unavailable.
- Hard bounce: Delivery failed permanently, commonly because the address or domain does not exist.
- Rejected: The receiving provider refused the message because of authentication, policy, reputation or infrastructure problems.
A useful outreach platform should preserve these distinctions. Treating every unsuccessful delivery as the same kind of "bounce" makes diagnosis harder.
Start with email authentication
SPF, DKIM and DMARC are often described collectively as tools that prove an email came from your domain. That is broadly their purpose, but each performs a different function.
SPF
SPF publishes a DNS record identifying which systems are authorised to send email using your domain in the message envelope.
It helps a receiving server check whether the sending infrastructure is permitted. However, SPF alone does not necessarily verify that the envelope domain matches the address the recipient sees in the visible "From" field. It can also be affected by some forwarding arrangements.
DKIM
DKIM adds a digital signature to the message. The receiving server uses that signature to check that important parts of the email have not been altered and that it was signed by a domain controlling the relevant cryptographic key.
DMARC
DMARC builds on SPF and DKIM by checking whether an authenticated domain aligns with the domain shown in the visible "From" address.
It also allows a domain owner to publish instructions describing what receivers should do when authentication fails and to receive reports about the use of the domain.
A simple way to think about them is:
- SPF checks whether the sending system is authorised.
- DKIM checks the message's signature and integrity.
- DMARC checks whether authentication aligns with the domain presented to the recipient.
They should be configured together and tested against every legitimate service that sends using your domain, including Microsoft 365 or Google Workspace, your CRM, marketing tools and any transactional-email provider.
Authentication is foundational, but it does not guarantee inbox placement. A properly authenticated message can still be filtered when recipients do not want it or the domain has developed a poor reputation.
Provider requirements are becoming stricter
Mailbox providers have made authentication, complaint and unsubscribe standards increasingly explicit.
Google requires all senders to personal Gmail accounts to use SPF or DKIM. Senders delivering approximately 5,000 or more messages a day to Gmail accounts must use SPF, DKIM and DMARC, meet domain-alignment and infrastructure requirements, keep reported spam rates below its stated limits and support one-click unsubscribe for applicable marketing and subscribed messages.
Google recommends keeping the spam rate shown in Postmaster Tools below 0.1% and avoiding a rate of 0.3% or higher. This means that even a relatively small number of complaints can become significant at scale.
Yahoo also expects bulk senders to authenticate their email, make unsubscribing easy and keep complaint rates below 0.3%.
These are bulk-sender requirements, not targets. Sending fewer than 5,000 messages does not make authentication, relevance or complaint rates unimportant.
Who you email matters more than filtering tricks
One of the strongest deliverability controls available to an agency is the quality of its recipient list.
Old recruitment data creates several risks at once:
- People have left the employer connected to the address.
- Corporate mailboxes have been closed.
- Domains have changed.
- A personal address has been abandoned.
- The recipient no longer has any reasonable connection to the subject.
- Someone previously asked not to be contacted, but the objection was not retained.
Invalid addresses generate bounces. Irrelevant messages generate deletions, unsubscribes and spam complaints. Repeatedly sending to either group tells mailbox providers that the sender is not controlling its data carefully.
Good list hygiene therefore means more than running addresses through a verification service before a large campaign.
It includes:
- Suppressing hard-bounced addresses immediately
- Investigating repeated soft bounces
- Retaining a suppression record for people who opt out
- Screening newly imported lists against existing suppressions
- Removing duplicate contacts
- Recording when an address was last verified or successfully used
- Avoiding purchased or indiscriminately collected lists
- Selecting recipients because the opportunity or service is genuinely relevant
Google advises senders not to buy email addresses and warns against repeatedly sending to people who did not request the messages, because those recipients are more likely to mark them as spam.
UK law may permit some forms of relevant business-to-business outreach without prior consent. That does not mean mailbox providers must place the email in the inbox, and it does not make an untargeted list good practice.
Legal permission and deliverability are separate tests.
Do not delete every record of an opt-out
When someone unsubscribes, the correct response is usually not to erase every trace of the address.
You normally need to retain a minimal suppression record so the person is not accidentally added to a future campaign through a new import or data-enrichment process.
The ICO recommends using a suppression list rather than simply deleting the person's details. New marketing lists can then be checked against it, reducing the risk that someone who has opted out is contacted again.
A recruitment CRM should make that suppression apply across every sending route. An opt-out recorded in one campaign should not be ignored because another consultant emails the same person from a different sequence.
What warming up should mean
Email warm-up is often presented as a fixed programme: send a prescribed number of messages for a certain number of days and the mailbox will then be safe for high-volume outreach.
Mailbox providers do not offer such a guarantee.
Google recommends increasing legitimate sending volume gradually, maintaining a consistent rate, beginning at a low volume with engaged recipients and monitoring server responses, spam rates and reputation as volume rises. It warns against sudden spikes and recommends reducing volume when messages begin bouncing or being deferred.
A more accurate description is controlled ramp-up.
That means:
- Configure authentication before outreach begins.
- Start below the intended campaign volume.
- Send at a steady rate rather than in bursts.
- Begin with the most relevant and reliable recipients.
- Monitor bounces, deferrals, complaints and replies.
- Increase gradually only while the signals remain healthy.
- Slow down or stop when rejection or complaint rates deteriorate.
There is no universal safe number such as 20, 50 or 100 messages a day. Appropriate volume depends on the age and reputation of the domain, its normal email activity, recipient quality, infrastructure and the response generated.
Nor should simulated opens and artificial replies be confused with earning a genuine sending reputation. Provider guidance focuses on gradual volume, wanted messages, real recipient feedback and active monitoring—not manufactured engagement.
Multiple mailboxes do not remove the risk
Using several connected mailboxes can be operationally useful.
It can:
- Assign outreach to the appropriate consultant
- Prevent one mailbox from carrying an entire team's workload
- Help maintain sensible per-mailbox sending schedules
- Preserve recognisable human senders
- Distribute replies to the people responsible for them
But mailbox rotation should not be treated as a method for multiplying volume without consequence.
Sending the same campaign through six mailboxes does not correct a stale list, reduce recipient complaints or fix missing authentication. Gmail considers traffic at domain level when determining bulk-sender status, so dividing the activity between several addresses on the same domain does not necessarily divide the underlying reputation risk.
Mailbox providers also evaluate domain, IP and behavioural signals. Microsoft describes authentication as only one part of its assessment and says that reputation, sender history, recipient history and behavioural analysis can also influence how incoming email is treated.
Rotation should therefore be a sending-control feature, not an evasion strategy.
Creating several lookalike domains and immediately sending high volumes from each does not build trust. Each new domain begins without an established sending history, while the underlying relevance and recipient-response problems remain.
Separate provider limits from deliverability limits
A sending limit and a deliverability limit are not the same thing.
Your email provider may technically allow a mailbox to send a particular number of messages each day. That does not mean sending that number as unsolicited outreach will produce good delivery.
Provider limits primarily protect infrastructure and prevent obvious abuse. Deliverability depends on how receiving systems evaluate the traffic.
A mailbox could remain within its Microsoft 365 or Google Workspace sending allowance while still generating enough complaints, invalid-address traffic or suspicious patterns to damage the domain's reputation.
The useful question is therefore not:
How many messages will the system let us send?
It is:
How many relevant messages can we send while keeping authentication, bounce, complaint and response signals healthy?
Content matters, but there is no universal percentage
Technical setup, reputation, recipient selection, sending patterns and content all interact. Their relative importance varies between senders and campaigns, so it is misleading to describe content as a fixed percentage of deliverability.
Content-related risks can include:
- A misleading sender name or subject line
- Links to domains with a poor reputation
- Large numbers of links or redirects
- Unexpected attachments
- Image-only or badly formed HTML messages
- Attempts to disguise the purpose of the email
- A message whose content bears little relation to the recipient
- Missing or difficult unsubscribe options
However, there is no dependable list of individual "spam words" that explains every filtering decision.
A plain-text message can still be spam. A well-designed HTML email can still reach the inbox. The decisive question is not whether the email contains a particular phrase; it is whether the complete sending pattern appears legitimate and recipients respond as though the message was wanted.
For recruiter outreach, clear and restrained emails are usually preferable for another reason: they are easier for the recipient to understand.
Use a recognisable sender, explain why the message is relevant, make the request clear and provide an easy way to stop further contact.
Do not diagnose deliverability from open rates alone
Open tracking is increasingly unreliable.
Some email clients protect users by loading images in ways that can create false opens. Others block tracking images and create false negatives. Google also states that it does not track open rates and cannot verify open-rate figures reported by third parties.
Open rates can still provide a directional campaign metric, but they should not be treated as proof that a message reached the primary inbox or that a named person read it.
A better deliverability dashboard considers:
- Accepted, deferred and rejected messages
- Hard- and soft-bounce categories
- SMTP response codes
- Spam-complaint rates
- Unsubscribe and objection rates
- Domain and IP reputation
- DMARC reports
- Replies
- Meetings or other meaningful outcomes
- Changes after volume, infrastructure or targeting adjustments
For domains sending enough volume to Gmail users, Google Postmaster Tools can provide information about authentication, spam rates and domain or IP reputation.
The UK compliance position
Deliverability guidance does not replace data-protection and electronic-marketing law.
For UK business-development email, the rules depend partly on the legal status of the organisation being contacted.
The PECR consent rule for electronic marketing does not apply to corporate subscribers such as limited companies and limited liability partnerships. A recruiter can therefore send B2B marketing email to a person at a corporate body without obtaining prior consent under PECR.
However, the sender must not conceal its identity and must provide a valid way to opt out. Where the email address identifies an individual, UK GDPR also applies: the agency needs a lawful basis, must provide appropriate privacy information and must respect the individual's right to object to direct marketing.
Sole traders and some ordinary partnerships are treated as individual subscribers. Marketing email to them generally requires consent unless the requirements of the soft opt-in are satisfied. When it is unclear whether an address belongs to a corporate or individual subscriber, treating it as an individual subscriber is the safer approach.
Legitimate interests may provide a UK GDPR lawful basis for some direct marketing, but it does not apply automatically. The organisation must identify a legitimate purpose, show that the processing is necessary and balance its interests against the person's rights and reasonable expectations.
People also have the right to object to their personal data being used for direct marketing.
This means that "it is B2B" is not a complete compliance assessment.
It also means a lawful email can still be unwanted, reported as spam and filtered. Compliance is the minimum requirement, not an inbox-placement strategy.
A practical deliverability checklist for agencies
Authentication and infrastructure
- Confirm SPF covers every legitimate sending service.
- Enable DKIM for every relevant domain.
- Publish DMARC and monitor its reports.
- Confirm the visible From domain aligns correctly.
- Check that third-party outreach systems are authenticated.
- Review SMTP errors rather than recording only "failed."
- Use a reputable sending provider and understand whether its IPs are shared.
Recipient data
- Suppress hard bounces immediately.
- Retain and enforce opt-out records.
- Screen imports against existing suppressions.
- Investigate repeated soft bounces.
- Remove obvious duplicates.
- Avoid purchased or indiscriminate lists.
- Select recipients for a clear and defensible reason.
Sending behaviour
- Begin new sending streams at low volume.
- Increase gradually rather than creating sudden spikes.
- Send at a consistent rate instead of large bursts.
- Do not use mailbox rotation merely to multiply total volume.
- Pause or reduce sending when deferrals, bounces or complaints rise.
- Avoid repeatedly contacting people who have shown no interest.
Message and process
- Use an identifiable sender and accurate subject line.
- Explain why the message is relevant.
- Keep links and attachments proportionate.
- Include a visible and functional opt-out.
- Process objections across the whole CRM, not just one campaign.
- Monitor replies and complaints, not only opens.
Where ATSpro fits
ATSpro's outreach and email tools connect campaign activity directly to candidate and contact records.
Multiple connected mailboxes can be used to distribute sending sensibly between consultants, while scheduling and volume controls prevent an entire campaign being released at once. Bounce and reply detection write outcomes back to the relevant CRM records, allowing invalid addresses to be flagged and future sends suppressed.
That integration matters because deliverability and database quality are the same operational problem viewed from different sides.
A bounced address should not remain available for the next consultant to select. An opt-out should apply across every campaign. A reply should stop unnecessary follow-ups.
These controls support responsible sending. They do not override Gmail, Yahoo or Microsoft requirements, repair a poor domain reputation or make an irrelevant recipient list safe.
The takeaway
When outreach underperforms, do not assume the answer is simply better copy or more volume.
Check whether the domain is authenticated. Examine hard bounces, soft bounces and server deferrals separately. Monitor complaint rates and domain reputation. Suppress invalid addresses and opt-outs across the entire CRM. Increase new sending streams gradually and resist the temptation to treat extra mailboxes as extra permission to send.
Most importantly, send messages that have a credible reason to reach the person receiving them.
The sustainable route to the inbox is not finding a way around provider safeguards. It is giving providers—and recipients—fewer reasons to distrust you.
**Sources: Google, *Email sender guidelines*; Google, *Email sender guidelines FAQ*; Google, *Postmaster Tools dashboards*; Microsoft, *Email authentication in Microsoft Defender for Office 365*; Yahoo, *Sender best practices*; Information Commissioner's Office, *Business-to-business marketing*; Information Commissioner's Office, *Respect people's preferences*; user per month.*.**