Outbound Atlas

Atlas/Deliverability/How filtering works

Reputation and blocklists

Cold-email reputation lives on domains, not IPs, and the first-party tools that used to show it (Postmaster v1 reputation, SNDS detail) were retired or degraded in 2025–26, leaving senders to infer health from bounces and replies.

Deliverabilitymedium confidence8 minupdated 2026-10-0512 sources

Reputation is the memory a receiving system keeps about a sender identity: a domain, an IP or a linked URL. For cold email the domain is the identity that matters. Senders on Google Workspace or Microsoft 365 share the provider's IPs. Google says the IP quota "is shared for all senders that use that IP address", while "DKIM and SPF quotas are specific to your domain". So everything a cold sender does well or badly ends up attached to the domain.

The bigger 2025–26 story is that the dashboards showing reputation went dark. Google retired Postmaster Tools v1, including the Domain Reputation and IP Reputation dashboards, on September 30, 2025. Microsoft overhauled SNDS in June 2026, removing complaint message samples and, from July 22, 2026, spam-trap hit counts. A cold sender's reputation is now mostly something you infer, not something you read off a screen.

Three layers of reputation

LayerWhat it attaches toCold-email relevance
DomainDKIM d= domain, From: domain, Return-PathHigh. This is the asset that burns.
IPSending server IPLow on Google/Microsoft mailboxes (shared). High on SMTP/"private infra" setups.
Linked domainsURLs and domains in the body and headers (tracking domains, website link)High and underestimated. One burned tracking domain contaminates every sender that uses it.

Spamhaus spells out the third layer. Its Domain Blocklist is meant to be checked against the rDNS domain, the HELO, the Mail From domain, and "domains appearing in the mail headers and body e.g., URLs". Your main website domain therefore carries risk even if you never send from it, simply because it appears in the signature. See Custom tracking domains.

Gmail: Postmaster Tools v2

Postmaster v2 is a compliance tool, not a reputation tool. Per a vendor guide from early 2026, it shows compliance status, spam rate, authentication, encryption (TLS), delivery errors and feedback loop data. Google teased "more useful and actionable information" by the end of 2025. The same vendor said in early 2026 that "nothing concrete has materialized".

Google's own sender-guidelines page still tells senders to "check your spam rate and your domain and IP address reputation with Postmaster Tools". That reads like a leftover from before the retirement.

The structural problem for cold email: Postmaster counts mail to personal Gmail accounts, and its spam-rate band is the 0.1% / 0.3% complaint threshold. A secondary domain sending 60 emails a day, mostly to company domains, generates too little personal-Gmail traffic to show any data. Prospeo says you need ~200+ daily emails to Gmail recipients for consistent data (vendor claim).

Small-number statistics

At 60 sends a day per domain, one spam complaint is a 1.7% complaint rate for that day, more than five times Gmail's 0.3% red line. Per-domain complaint rates in cold email are noise until aggregated across domains or days. Any tool that reports them per domain per day is mostly showing randomness.

Microsoft: SNDS and JMRP

SNDS reports on IPs you control. That makes it irrelevant to anyone sending from Microsoft 365 or Google Workspace mailboxes, and useful only for SMTP and dedicated-infrastructure senders (see Google vs Microsoft vs SMTP). The June 8, 2026 overhaul moved SNDS to a new portal with OAuth 2.0 aimed at desktop apps, 30-day expiring automated links, and ARF complaint reports without the full original message. Each of those makes automated monitoring by third-party tools harder.

For Microsoft 365 recipients, the reputation signal you can see is the bulk complaint level stamped in headers. Microsoft's scale runs 0 (not bulk) to 9 (many complaints), with a default action threshold of 7 that tenant admins can change.

Blocklists in 2026

ListStatusWhat it means for cold email
Spamhaus DBLActive; removals only via check.spamhaus.orgThe one that matters for domains. It covers domains used in unsolicited bulk email and "those with poor reputation based on a broad range of heuristics". Listing the tracking or website domain hits every message containing it.
Spamhaus ZEN (SBL/XBL/CSS/PBL)ActiveIP lists. They matter for SMTP/self-hosted infra, rarely for Google/Microsoft mailboxes.
Barracuda (BRBL)ActiveIP reputation used by Barracuda gateways. Relevant when prospects sit behind Barracuda.
SORBSShut down June 5, 2024 by owner Proofpoint, "after thorough consideration of various factors impacting the service's sustainability"Any tool still alarming on SORBS listings is out of date.
Spamhaus newly-registered-domain handling

Practitioners widely say Spamhaus treats freshly observed domains with suspicion (a "zero reputation" list) for their first hours. The Spamhaus ZRD page did not render for this pass, so the mechanism and timings are unverified. The practical upshot is still sound: age domains before sending from them. See Does warmup work?.

Blocklist checks are cheap commodity features. Every infra vendor and most sequencers already run them. They catch the catastrophic case (a domain on the DBL) but say nothing about the common case: a clean, unlisted domain that Gmail quietly routes to spam.

How reputation is actually measured in cold email today

With first-party dashboards gone or blind to this traffic, practitioners triangulate:

  1. SMTP responses. 4xx deferrals and 5xx rejections with provider-specific codes, such as Microsoft's 550 5.7.515 or Gmail's rate-limit and authentication codes listed in the sender FAQ.
  2. Seed/placement tests. Send to a panel of seed inboxes and read where they land (Inbox placement testing). This is biased: seeds don't behave like real prospects, and Google's AUP prohibits testing the service "to evade filtering capabilities".
  3. Warmup-network inbox rates (Built-in warmup). Biased the same way: the network's own accounts rescue mail from spam.
  4. Reply-rate drift by mailbox and domain. The only signal grounded in real recipients, and the slowest.
  5. Bounce rates. Instantly's 2026 report says to keep bounces under 2%. See Bounce protection and Email verification.
Reputation inference engine

No first-party source now tells a cold sender how a domain is doing. A platform that fuses SMTP response codes, per-recipient-domain reply and bounce rates, seed results and header verdicts into a per-domain health score could own the "why did my campaign die" moment. It should show its confidence level and refuse to report noise. Incumbents ship warmup scores and blocklist checks. None found in this pass publishes a statistically honest reputation model.

Recovery

Google's FAQ is specific about one recovery path. Bulk senders become eligible for mitigation again once their spam rate stays below 0.3% for 7 consecutive days. Beyond that, Google warns that "it can take time for improvements in spam rate to reflect positively on spam classification" (Google). The cold-email industry's answer is economic, not technical. Domains cost about $14 a year, so a burned domain is retired, not rehabilitated. That keeps the domain-churn treadmill running (see Volume math: what 10k and 100k emails a day cost).

What this means for an entrant

  • Domain health is your product's core state, not a settings page. Track each sending domain and linked domain (tracking, website) as a first-class object with history, and alert on response-code and reply-rate changes, not just blocklist hits.
  • Build for the post-Postmaster world. Don't promise Google reputation data you cannot get. Infer it and label the confidence. A fully honest "insufficient data" state is a differentiator in a market of green dashboards.
  • Shared tracking domains are shared liability. Default to per-customer custom tracking domains, or no link tracking at all (Content and tracking).
  • Drop SORBS checks and dead lists. It is a small but telling credibility signal to deliverability-literate buyers (agencies).
  • Microsoft's SNDS changes favour Microsoft-mailbox senders over SMTP senders. If you build on private SMTP infra (Infrastructure strategy: build or partner), budget for doing your own IP monitoring without SNDS trap data.
12 sources cited on this page · 11 domains
  1. the IP quota is shared for all senders that use that IP address support.google.com
  2. retired Postmaster Tools v1, including the Domain Reputation and IP Reputation dashboards, on September 30, 2025 twilio.com
  3. overhauled SNDS in June 2026, removing complaint message samples and, from July 22, 2026, spam-trap hit counts postmastery.com
  4. Domain Blocklist is meant to be checked against the rDNS domain, the HELO, the Mail From domain, and domains appearing in the mail headers and body e.g., URLs spamhaus.org
  5. compliance status, spam rate, authentication, encryption (TLS), delivery errors and feedback loop data prospeo.io
  6. 0.1% / 0.3% complaint threshold support.google.com
  7. 0 (not bulk) to 9 (many complaints), with a default action threshold of 7 that tenant admins can change learn.microsoft.com
  8. after thorough consideration of various factors impacting the service's sustainability theregister.com
  9. 550 5.7.515 substrate.office.com
  10. to evade filtering capabilities workspace.google.com
  11. keep bounces under 2% instantly.ai
  12. $14 a year mailforge.ai