Skip to main content
← Back to all posts
Developers · 13 min read

Why transactional emails end up in spam.

A developer's guide to fixing password resets, receipts, and confirmation emails that quietly land in junk. SPF alignment, DKIM signing, IP warming, and the role of From-address consistency - written for the engineers who actually wire up sending.

By EmailSheriff · · 13 min read · Developer

1. Why transactional is different from marketing

Transactional email - password resets, order confirmations, receipts, account verifications - gets treated as "obviously safe" by most engineering teams. It's the email no one thinks about until a customer says "I never got the password reset link."

Here's the bad news: transactional email actually has stricter deliverability requirements than marketing email, because spam filters know that legitimate transactional senders care about every single message. A marketing campaign with 80% inbox placement is acceptable. A password reset email with 80% inbox placement means 20% of your users can't log in.

The good news: transactional email is also easier to fix than marketing email, because you control the entire sending infrastructure. No marketing team negotiating subject lines, no list-cleaning debates. Just code and DNS.

2. SPF alignment - the silent killer

Most transactional email passes SPF in the technical sense - but fails SPF alignment, which is what DMARC actually checks.

Here's the trap: SPF authenticates the Return-Path domain (also called envelope-from), not the visible From address. When you send through SendGrid:

Default SendGrid configuration · headers
Return-Path: [email protected] From: [email protected]

SPF passes (because em1234.sendgrid.net is authorized to send for itself). But DMARC requires the SPF-authenticated domain to match the From domain. sendgrid.net ≠ yourdomain.com, so DMARC alignment fails. If your DMARC policy is p=quarantine or p=reject, your password reset goes to spam.

Fix: set up custom Return-Path domain. In SendGrid this is "Domain Authentication" - they generate CNAME records pointing em.yourdomain.com to their infrastructure. Once configured, Return-Path becomes [email protected], which aligns with yourdomain.com via the "relaxed alignment" rule.

3. DKIM signing the right domain

Same alignment principle for DKIM. Default ESP configuration signs with their domain (d=sendgrid.net). DMARC requires the DKIM-signing domain to match (or align with) the From domain.

Every major transactional ESP supports custom DKIM signing - it's a standard feature. The setup is two CNAME records pointing your selectors at their signing infrastructure. After setup, your DKIM signature reads d=yourdomain.com, which aligns properly.

Authenticated transactional headers · target state
Return-Path: [email protected] From: [email protected] DKIM-Signature: v=1; d=yourdomain.com; s=s1; ... Authentication-Results: spf=pass; dkim=pass; dmarc=pass

4. From-address consistency

Stop using [email protected] for transactional email. Three reasons:

  1. Inbox providers downgrade no-reply addresses. Gmail and Outlook both pattern-match for noreply, no-reply, donotreply in the From local-part and apply a small but measurable spam-score increase. The pattern correlates with low-trust senders historically.
  2. Replies bounce, signaling broken sender. When a recipient hits reply on a noreply@ address, their server tries to deliver and fails. That bounce is logged by their provider and counted against your reputation.
  3. Customer service signal. Treating customer-facing email as one-way ("don't reply, we don't read it") is a brand-damaging pattern that inbox providers explicitly downgrade.

Use a real address: [email protected], [email protected], [email protected]. Configure it to forward to your support inbox or auto-respond with helpful guidance.

Pro tip from real-world testing

Switching from noreply@ to a real From address typically boosts inbox placement by 3-5 percentage points overnight, with no other changes. It's the single highest-ROI deliverability fix that costs nothing and takes 10 minutes.

5. Shared IP reputation traps

If you send via SendGrid, Mailgun, or AWS SES on a shared IP pool, your deliverability is partially controlled by other customers on the same IPs. When they send to dirty lists or generate spam complaints, the IP's reputation drops - and so does yours.

This shows up as inconsistent deliverability that you can't explain. Same code, same templates, same recipients - but Tuesday's batch goes to inbox and Thursday's goes to spam. The variable is the IP, not your sending.

Mitigation strategies:

  • Postmark aggressively curates their shared IPs and kicks bad senders. Slightly more expensive but consistent. Good default for transactional.
  • AWS SES has improved over the years, but still has noisy neighbors. Use only with custom warming and dedicated IPs above 50K/month.
  • SendGrid Pro tier has cleaner shared pools than free tier. Worth the upgrade if you're seeing inconsistency.

6. IP warming for higher-volume senders

If you're moving to a dedicated IP (or your provider auto-assigns one), you must warm it slowly. New IPs have zero reputation; sending high volume immediately triggers spam filters.

Standard warming schedule:

DayVolumeRecipients
150Most-engaged users only
2-3100/dayMost-engaged users
4-7500/dayEngaged users
8-142,000/dayRecently active users
15-215,000/dayAll active users
22-2820,000/dayFull active list
29+Full volumeFull list

Skip steps and you'll see spam-folder rates spike. Reputable providers handle warming automatically if you use their warming service - worth using.

7. Content traps specific to transactional

Marketing email content advice mostly applies. Two transactional-specific traps to know:

Subject lines that pattern-match phishing

Bad: "Reset your password immediately", "Urgent: confirm your account", "Security alert". These match phishing patterns spam filters watch for. Better: "Your password reset link", "Welcome to Acme - confirm your email", "Your order #1234 is on its way".

Image-only emails

Some teams build transactional emails as a single image (the receipt, the confirmation page) wrapped in HTML. Spam filters specifically flag image-only messages because it's a classic spam-evasion technique. Always include a meaningful HTML body alongside any images.

8. Monitoring transactional deliverability

You can't fix what you don't measure. For transactional email specifically:

  1. DMARC reports - set up rua=mailto:[email protected] and review weekly. Aggregate reports show what % of your transactional mail is passing authentication.
  2. Per-template engagement metrics - track open rate by transaction type. Password reset opens at 12% means 88% are going to spam (these should open at 60%+).
  3. Synthetic monitoring - set up automated test sends to seed inboxes at Gmail, Outlook, Yahoo. Run hourly. Alert when placement drops.
  4. Customer support signal - track tickets like "I didn't get the email." Spike in these is the loudest deliverability alarm.
Audit your transactional sending domain

Run a full audit on the domain you send from. We check SPF alignment, DKIM signing, DMARC enforcement, and the four common ESP misconfigurations - graded A-F with specific fixes ranked by impact.

Run the audit →

9. Frequently asked questions

Why do my password reset emails go to spam?
Password reset emails go to spam most often because of: (1) shared sending IP reputation - if you're on a transactional ESP (SendGrid, Postmark, etc.), other customers' bad behavior can drag down your IP. (2) Missing SPF/DKIM alignment with your domain. (3) Generic "noreply@" From addresses. (4) Subject lines that look like phishing ("Reset your password immediately"). Set up authenticated sending domain, use a real From address, and write subject lines like normal humans.
Should I use a dedicated IP for transactional email?
Only if you send more than ~50,000 emails/month consistently. Below that volume, dedicated IPs hurt rather than help - you don't generate enough signal for inbox providers to build reputation. Stay on shared IPs from a reputable provider (Postmark, AWS SES with good config, SendGrid Pro tier) until volume justifies dedication. Dedicated IPs require careful warming over 4-6 weeks.
Why do my emails work but their replies don't?
This is almost always because your From address is "[email protected]" but your domain has no MX record (or rejects mail). When recipients hit reply, their message bounces. Even worse - some inbox providers downgrade messages from no-reply addresses to spam preemptively because they recognize the pattern as low-trust. Use a real, monitored From address.
+ Related tools
Full Audit
All 6 deliverability checks on a domain in 30 seconds, graded A-F.
DNS Checker
SPF · DKIM · DMARC · MX with plain-English explanations.
Header Forensics
Paste raw email headers - see exactly which authentication checks failed and why.