Inbox placement is decided by a classifier, not a checklist. Gmail says its defences stop more than 99.9% of spam, phishing and malware and block nearly 15 billion unwanted emails a day (Google, October 2023). The published sender rules (SPF, DKIM, DMARC, 0.3% complaints, one-click unsubscribe) only decide whether a message is eligible for fair treatment. Whether it lands in the inbox depends on what the model has learned about the sending domain, the receiving user and the message.
The awkward fact for cold email is about scope. Google's own FAQ says its sender guidelines "don't apply to messages sent to Google Workspace accounts" and that enforcement applies "only when sending email to personal Gmail accounts". Microsoft's May 2025 rules cover Outlook.com consumer accounts. B2B cold email mostly goes to company domains hosted on Google Workspace or Microsoft 365. Those recipients are filtered by the same kind of engine, but with no published thresholds at all. Read Google and Yahoo sender rules and Microsoft rules: Outlook.com and Microsoft 365 limits as the visible part of the system. This page is about the part you can't see.
The four inputs
| Input | What the filter looks at | Who controls it |
|---|---|---|
| Identity and authentication | SPF/DKIM/DMARC pass and alignment, PTR, TLS, RFC 5322 conformance | Sender (see Authentication: SPF, DKIM, DMARC, BIMI, ARC and one-click unsubscribe) |
| Reputation | History of the DKIM/From domain, sending IP, linked domains in the body | Sender, slowly (see Reputation and blocklists) |
| Recipient behaviour | Spam reports, "not spam" rescues, replies, deletes without reading, moves | Recipients |
| Content | Text classifiers, URLs, hidden HTML, deceptive headers | Sender (see Content and tracking) |
1. Identity is the entry ticket
Since 2022 Gmail has required some form of authentication on all mail to Gmail addresses, and Google says that requirement cut unauthenticated messages to users by 75%. Authentication does not earn inbox placement. It makes the message attributable to a domain, so reputation can stick to it. Every cold-email platform gets this right by default today. It is table stakes, not a feature.
2. Reputation lives mostly on the domain now
Google says plainly that it "tracks volume, feedback, and limits per domain and IP address", that "DKIM and SPF quotas are specific to your domain", and that "the IP address quota is shared for all senders that use that IP address". A cold sender on Google Workspace or Microsoft 365 sends from the provider's shared IP pool. It cannot own its IP reputation, so its domain carries the history. This is why the cold-email industry runs on many cheap secondary domains rather than dedicated IPs (see Google vs Microsoft vs SMTP).
3. Recipient behaviour is the strongest signal you can move
Google's guidelines name the loop: "If messages from your domain are frequently reported as spam, future messages from you are more likely to be marked as spam. Over time, user spam reports can lower your domain's reputation." Recipients who mark mail "not spam" rescue future messages (Google). The complaint threshold is graduated. Rates above 0.1% already hurt bulk senders, and 0.3% or more removes mitigation.
Positive engagement matters too, but no mailbox provider publishes which signals count. Instantly's 2026 report asserts placement "is governed by engagement signals (opens, replies, reading)". That is a vendor's model of the filter, not Google's. Google itself says "Google doesn't track open rates" as a deliverability measure.
Practitioners treat replies as the most valuable positive signal and "deleted unread" as a negative one. That is consistent with Google's statements about spam reports and "not spam" rescues. No provider documentation found for this pass confirms how replies, reads or deletes are weighted.
4. Content is read by models built to resist evasion
Gmail's text classifier uses RETVec. Google says it lifted spam detection by 38% over baseline, cut false positives by 19.4% and cut TPU usage by 83%. It was built specifically to resist "homoglyphs, invisible characters, and keyword stuffing". That matters for Spintax and message variants. Character-level tricks that once defeated fingerprinting are exactly what the model was trained against. Google also bans deceptive patterns outright: fake "Re:"/"Fwd:" subjects, CSS-hidden content, and emoji or images that imply a verified sender (Google).
Microsoft is a different machine
Microsoft 365 recipients sit behind Exchange Online Protection and Defender. Two consequences:
- Tenant admins tune the filter. Microsoft assigns a bulk complaint level (BCL) of 0–9; the default threshold is 7, and each tenant can move it. The same email can land in the inbox at one company and in Junk at the next.
- The verdict is getting harder to read. Microsoft's August 2026 documentation says the spam confidence level "no longer holds the same meaning in cloud organizations" and "the same SCL value can appear on messages with different verdicts". Header-reading diagnostics, the staple of placement tools, lose accuracy.
Defender Safe Links also scans URLs "prior to message delivery, regardless of whether the URLs are rewritten". That is the source of the "bot clicks" that pollute cold-email click and open stats (see Content and tracking).
Many enterprise domains add a secure email gateway (Proofpoint, Mimecast, Barracuda) in front of either provider, with its own reputation feeds.
No reliable 2026 figure was found for how B2B recipient domains split between Google Workspace, Microsoft 365 and gateway-fronted setups. That split decides which filter matters most for a given ICP. The best proxy is the sender side: Saleshandy says 44% of the cold email it saw in H1 2026 was sent via Google Workspace, 33% via Microsoft 365 and 23% via Zoho, Azure or custom SMTP (vendor data).
Rate limits are a filter too
Before content is judged, volume is. Gmail rate-limits per domain and per IP, and its guidance is explicit. Avoid bursts, increase slowly, and remember that "immediately doubling previously sent volumes suddenly could result in rate limiting or reputation drops". On the sending side, each Workspace user is capped at 2,000 messages and 3,000 external recipients a day. Exchange Online caps each mailbox at 10,000 recipients a day and 30 messages a minute. Cold senders stay far below these caps by design. See Volume math: what 10k and 100k emails a day cost for why the practitioner norm is 10–30 a day, not 2,000.
The filter scores the domain's history with real recipients, not the message in isolation. Cold email's whole infrastructure model (many domains, few sends per mailbox, ESP matching, warmup) is an attempt to keep each domain's history too short and too clean for the model to condemn. That works until the provider clusters the domains together. See Provider crackdowns.
What the sender can actually see
Very little. Postmaster Tools v1's domain and IP reputation dashboards were retired on September 30, 2025. v2 focuses on compliance status and spam rate, and only for mail to personal Gmail accounts. Microsoft SNDS is IP-based and lost spam-trap counts and complaint samples in June–July 2026. A cold sender on shared Workspace IPs, mailing business recipients at 20 a day per mailbox, gets almost no first-party telemetry. Full detail is in Reputation and blocklists.
What this means for an entrant
- Don't market "compliance" as deliverability. Every serious platform passes SPF/DKIM/DMARC. The filter's real inputs are reputation and recipient behaviour, which your product can only influence through targeting, volume discipline and reply quality.
- Your users fly blind, and that is the opening. Mailbox providers removed or degraded the dashboards cold senders relied on in 2025–26. A platform that infers per-domain health from SMTP responses, bounce codes, reply-rate drift and seed placement fills a hole incumbents only half-fill with Inbox placement testing and Built-in warmup scores.
- Treat Microsoft tenants as many filters, not one. Per-tenant BCL thresholds and SEGs mean per-recipient-domain analytics (which company domains junk you) beats aggregate "Outlook placement".
- Design against content fingerprinting honestly. RETVec-class models defeat character tricks. Variation that changes meaning and structure (real personalisation) survives. Variation that changes glyphs does not. See AI personalisation.
- Count the scope gap as a risk, not a loophole. Workspace and M365 business recipients sit outside the published rules today. Nothing stops Google or Microsoft from publishing thresholds for them tomorrow.