Start with authentication, not wording
People blame spam filtering on subject lines and trigger words, but for a domain that sends real mail the usual cause is missing or broken authentication. If receivers cannot prove a message is really from you, they discount it - and spoofers dragging down your domain's reputation make it worse.
The three records that decide this are SPF, DKIM and DMARC. Getting all three right is the single biggest lever you have over deliverability.
The three records that matter
SPF lists which servers may send mail as you. If your real sending platform is not in the record, its mail fails SPF. DKIM signs each message so receivers can verify it was not forged or altered, and it keeps working even after forwarding.
DMARC ties the two together and tells receivers what to do with mail that fails - and asks them to report who is sending as you. A domain with all three aligned and passing looks trustworthy; one missing them looks like every phisher who never bothered.
Work through the fixes
In order of impact:
- Publish one correct SPF record that includes every service you actually send from, ending in -all or ~all.
- Turn on DKIM signing in your mail provider and publish the selector record it gives you.
- Publish a DMARC record, starting at p=none with a reporting address, then tighten it once your senders pass.
- Warm up new domains and dedicated IPs gradually instead of blasting a large first send.
- Keep lists clean - remove hard bounces and people who never engage, since spam complaints and dead addresses hurt reputation.
Then look at the message itself
Once authentication is solid and the domain still struggles, check the content signals: a working unsubscribe link, a sensible text-to-image ratio, no link shorteners hiding the destination, and a From address on a domain you actually control.
But authentication comes first. No amount of subject-line tweaking rescues mail that fails SPF, DKIM and DMARC - fix the records, then refine the content.