Outbound Atlas

Atlas/Deliverability/How filtering works

How filtering works

Gmail and Microsoft decide inbox vs spam with ML classifiers fed by domain reputation, recipient behaviour and content; published bulk rules are a floor, and most B2B cold email is sent to recipients those rules do not even cover.

Deliverabilitymedium confidence8 minupdated 2026-10-0514 sources

Inbox placement is decided by a classifier, not a checklist. Gmail says its defences stop more than 99.9% of spam, phishing and malware and block nearly 15 billion unwanted emails a day (Google, October 2023). The published sender rules (SPF, DKIM, DMARC, 0.3% complaints, one-click unsubscribe) only decide whether a message is eligible for fair treatment. Whether it lands in the inbox depends on what the model has learned about the sending domain, the receiving user and the message.

The awkward fact for cold email is about scope. Google's own FAQ says its sender guidelines "don't apply to messages sent to Google Workspace accounts" and that enforcement applies "only when sending email to personal Gmail accounts". Microsoft's May 2025 rules cover Outlook.com consumer accounts. B2B cold email mostly goes to company domains hosted on Google Workspace or Microsoft 365. Those recipients are filtered by the same kind of engine, but with no published thresholds at all. Read Google and Yahoo sender rules and Microsoft rules: Outlook.com and Microsoft 365 limits as the visible part of the system. This page is about the part you can't see.

The four inputs

InputWhat the filter looks atWho controls it
Identity and authenticationSPF/DKIM/DMARC pass and alignment, PTR, TLS, RFC 5322 conformanceSender (see Authentication: SPF, DKIM, DMARC, BIMI, ARC and one-click unsubscribe)
ReputationHistory of the DKIM/From domain, sending IP, linked domains in the bodySender, slowly (see Reputation and blocklists)
Recipient behaviourSpam reports, "not spam" rescues, replies, deletes without reading, movesRecipients
ContentText classifiers, URLs, hidden HTML, deceptive headersSender (see Content and tracking)

1. Identity is the entry ticket

Since 2022 Gmail has required some form of authentication on all mail to Gmail addresses, and Google says that requirement cut unauthenticated messages to users by 75%. Authentication does not earn inbox placement. It makes the message attributable to a domain, so reputation can stick to it. Every cold-email platform gets this right by default today. It is table stakes, not a feature.

2. Reputation lives mostly on the domain now

Google says plainly that it "tracks volume, feedback, and limits per domain and IP address", that "DKIM and SPF quotas are specific to your domain", and that "the IP address quota is shared for all senders that use that IP address". A cold sender on Google Workspace or Microsoft 365 sends from the provider's shared IP pool. It cannot own its IP reputation, so its domain carries the history. This is why the cold-email industry runs on many cheap secondary domains rather than dedicated IPs (see Google vs Microsoft vs SMTP).

3. Recipient behaviour is the strongest signal you can move

Google's guidelines name the loop: "If messages from your domain are frequently reported as spam, future messages from you are more likely to be marked as spam. Over time, user spam reports can lower your domain's reputation." Recipients who mark mail "not spam" rescue future messages (Google). The complaint threshold is graduated. Rates above 0.1% already hurt bulk senders, and 0.3% or more removes mitigation.

Positive engagement matters too, but no mailbox provider publishes which signals count. Instantly's 2026 report asserts placement "is governed by engagement signals (opens, replies, reading)". That is a vendor's model of the filter, not Google's. Google itself says "Google doesn't track open rates" as a deliverability measure.

Engagement weighting is folklore

Practitioners treat replies as the most valuable positive signal and "deleted unread" as a negative one. That is consistent with Google's statements about spam reports and "not spam" rescues. No provider documentation found for this pass confirms how replies, reads or deletes are weighted.

4. Content is read by models built to resist evasion

Gmail's text classifier uses RETVec. Google says it lifted spam detection by 38% over baseline, cut false positives by 19.4% and cut TPU usage by 83%. It was built specifically to resist "homoglyphs, invisible characters, and keyword stuffing". That matters for Spintax and message variants. Character-level tricks that once defeated fingerprinting are exactly what the model was trained against. Google also bans deceptive patterns outright: fake "Re:"/"Fwd:" subjects, CSS-hidden content, and emoji or images that imply a verified sender (Google).

Microsoft is a different machine

Microsoft 365 recipients sit behind Exchange Online Protection and Defender. Two consequences:

Defender Safe Links also scans URLs "prior to message delivery, regardless of whether the URLs are rewritten". That is the source of the "bot clicks" that pollute cold-email click and open stats (see Content and tracking).

Many enterprise domains add a secure email gateway (Proofpoint, Mimecast, Barracuda) in front of either provider, with its own reputation feeds.

Recipient-side market share

No reliable 2026 figure was found for how B2B recipient domains split between Google Workspace, Microsoft 365 and gateway-fronted setups. That split decides which filter matters most for a given ICP. The best proxy is the sender side: Saleshandy says 44% of the cold email it saw in H1 2026 was sent via Google Workspace, 33% via Microsoft 365 and 23% via Zoho, Azure or custom SMTP (vendor data).

Rate limits are a filter too

Before content is judged, volume is. Gmail rate-limits per domain and per IP, and its guidance is explicit. Avoid bursts, increase slowly, and remember that "immediately doubling previously sent volumes suddenly could result in rate limiting or reputation drops". On the sending side, each Workspace user is capped at 2,000 messages and 3,000 external recipients a day. Exchange Online caps each mailbox at 10,000 recipients a day and 30 messages a minute. Cold senders stay far below these caps by design. See Volume math: what 10k and 100k emails a day cost for why the practitioner norm is 10–30 a day, not 2,000.

So what

The filter scores the domain's history with real recipients, not the message in isolation. Cold email's whole infrastructure model (many domains, few sends per mailbox, ESP matching, warmup) is an attempt to keep each domain's history too short and too clean for the model to condemn. That works until the provider clusters the domains together. See Provider crackdowns.

What the sender can actually see

Very little. Postmaster Tools v1's domain and IP reputation dashboards were retired on September 30, 2025. v2 focuses on compliance status and spam rate, and only for mail to personal Gmail accounts. Microsoft SNDS is IP-based and lost spam-trap counts and complaint samples in June–July 2026. A cold sender on shared Workspace IPs, mailing business recipients at 20 a day per mailbox, gets almost no first-party telemetry. Full detail is in Reputation and blocklists.

What this means for an entrant

  • Don't market "compliance" as deliverability. Every serious platform passes SPF/DKIM/DMARC. The filter's real inputs are reputation and recipient behaviour, which your product can only influence through targeting, volume discipline and reply quality.
  • Your users fly blind, and that is the opening. Mailbox providers removed or degraded the dashboards cold senders relied on in 2025–26. A platform that infers per-domain health from SMTP responses, bounce codes, reply-rate drift and seed placement fills a hole incumbents only half-fill with Inbox placement testing and Built-in warmup scores.
  • Treat Microsoft tenants as many filters, not one. Per-tenant BCL thresholds and SEGs mean per-recipient-domain analytics (which company domains junk you) beats aggregate "Outlook placement".
  • Design against content fingerprinting honestly. RETVec-class models defeat character tricks. Variation that changes meaning and structure (real personalisation) survives. Variation that changes glyphs does not. See AI personalisation.
  • Count the scope gap as a risk, not a loophole. Workspace and M365 business recipients sit outside the published rules today. Nothing stops Google or Microsoft from publishing thresholds for them tomorrow.
14 sources cited on this page · 9 domains
  1. stop more than 99.9% of spam, phishing and malware and block nearly 15 billion unwanted emails a day blog.google
  2. sender guidelines don't apply to messages sent to Google Workspace accounts support.google.com
  3. Outlook.com consumer accounts substrate.office.com
  4. tracks volume, feedback, and limits per domain and IP address support.google.com
  5. is governed by engagement signals (opens, replies, reading) instantly.ai
  6. lifted spam detection by 38% over baseline, cut false positives by 19.4% and cut TPU usage by 83% security.googleblog.com
  7. bulk complaint level (BCL) of 0–9; the default threshold is 7, and each tenant can move it learn.microsoft.com
  8. spam confidence level no longer holds the same meaning in cloud organizations and the same SCL value can appear on messages with different verdicts learn.microsoft.com
  9. prior to message delivery, regardless of whether the URLs are rewritten learn.microsoft.com
  10. 44% of the cold email it saw in H1 2026 was sent via Google Workspace, 33% via Microsoft 365 and 23% via Zoho, Azure or custom SMTP saleshandy.com
  11. 2,000 messages and 3,000 external recipients a day support.google.com
  12. 10,000 recipients a day and 30 messages a minute learn.microsoft.com
  13. domain and IP reputation dashboards were retired on September 30, 2025 twilio.com
  14. lost spam-trap counts and complaint samples in June–July 2026 postmastery.com