In short
  • Set up SPF, DKIM and DMARC, then move DMARC to enforcement.
  • Remove bounces and complainers automatically.
  • Keep cold outreach off your newsletter domain.
  • Read open and click data with care, especially for business audiences.

Authentication: prove the mail is really yours

  • SPF. A DNS record listing the services allowed to send mail for your domain.
  • DKIM. A cryptographic signature on every message, published as a DNS key. Use a strong key length.
  • DMARC. A policy telling mailbox providers what to do with mail that fails SPF and DKIM. Start by monitoring, then move to quarantine once your legitimate mail passes consistently.
  • BIMI. Shows your logo next to your emails in supporting inboxes. It requires DMARC enforcement, and some inboxes also require a verified mark certificate.

Large mailbox providers now expect authentication and easy unsubscribes from bulk senders, so treat these as requirements, not extras.

List hygiene: protect your reputation

  • Remove hard bounces immediately and suppress repeat soft bounces.
  • Remove anyone who marks you as spam, automatically.
  • Include a one-click unsubscribe and honor it right away.
  • Re-engage or remove readers who have not opened in months.
  • Never import purchased or scraped lists.

Sending habits

  • Send from a consistent domain and from-name on a predictable schedule.
  • Warm up new domains or platforms gradually.
  • Keep sponsor outreach and other cold email on a separate domain from your newsletter.
  • Screen subject lines and copy for spam-trigger wording before scheduling.

Measure what matters

Watch bounce and complaint rates on every send, along with inbox placement on the major providers. Be careful with open and click data: corporate security scanners can open and click links automatically, so engagement from business audiences can look higher than it really is.

Rule of thumb: if complaints or bounces jump on a send, pause and find out why before the next one. Reputation is quick to lose and slow to rebuild.

What most guides miss

Lessons from systems we have built and run, not the usual checklist.

Security scanners inflate B2B engagement

Corporate email security tools often open and click links before a person does. For business audiences, raw open and click rates can be far higher than real reading. Filter out machine activity before you judge a send or report to sponsors.

Opens are a weaker signal than they used to be

Privacy features in some mail apps load images automatically, which records opens that never happened. Weight clicks, replies and conversions more heavily.

Do not let your webhooks drop events

If you track delivery and engagement events yourself, a busy send produces a burst of them at once. Make sure your system can absorb that spike, or your bounce handling and reporting will quietly miss data.

Be careful with aggressive bot filters

Filters that flag signups or readers as bots can catch real people too. Review what they remove before deleting anyone for good.

How we do it

We set up authentication, automatic bounce and complaint handling, and monitoring as part of every system we build. See operations and our Resend infrastructure work.