Email Deliverability Best Practices
Ashby integrates with your team's Google Workspace or Microsoft 365 account to send emails directly from your inboxes, meaning your entire team has a hand in ensuring email deliverability. This guide covers best practices for factors that influence your email deliverability, including sender reputation, email content, and compliance with email authentication standards.
What is email deliverability?
Email deliverability refers to the ability of your emails to reach the intended recipients' inboxes without being marked as spam or rejected by email servers.
What influences email deliverability?
There are many factors that influence email deliverability; in this guide, we focus on Sender Reputation and Email Authentication. Other factors include:
- Content quality: The relevance, wording, and design of your email content, including avoidance of spam-like features.
- Recipient engagement: How recipients interact with your emails, such as opening rates and marking emails as spam.
- Email list health: Regular cleaning of your list to remove inactive or invalid addresses helps maintain a good sender reputation.
- Compliance with email regulations: Adherence to laws like the Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act, General Data Protection Regulation (GDPR), and Canadian Anti-Spam Legislation (CASL) is crucial for legal compliance and deliverability.
- Frequency and volume of emails: Consistent and balanced email sending practices help establish a stable sender reputation.
What are email deliverability best practices?
- Regularly update records: Keep your Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC) records up to date, especially when changing email service providers or server configurations.
- Monitor email deliverability: Regularly check if your emails are landing in inboxes and not spam folders. Tools like Google Postmaster can provide insights.
- Stay compliant with email standards: Ensure your email content and practices comply with standards like CAN-SPAM or GDPR, depending on your region.
- Educate your team: Make sure everyone involved in email campaigns understands the importance of these authentication methods.
- Seek professional help if needed: If you're unsure about setting up these protocols correctly, consider consulting with IT professionals specializing in email systems.
What are email authentication methods?
Email authentication is a technical method used to verify that an email message is from the sender it claims to be from. This process is crucial for preventing email spoofing and phishing attacks, where attackers might forge emails to seem like they come from legitimate sources. Though there are many, the best practice methods include SPF, DKIM, and DMARC.
What are email authentication best practices?
There are well-established best practices that your IT Administrators are likely already familiar with. As of February 2024, Google is enforcing the following best practices. Failure to comply will result in deferred and eventually rejected emails.
SPF (Sender Policy Framework)
This method allows the domain owner to specify which mail servers are permitted to send emails on behalf of their domain. When an email is received, the receiving server checks the SPF record in the Domain Name System (DNS) to verify if the email comes from an authorized server.
- SPF should be implemented by all senders.
DKIM (DomainKeys Identified Mail)
DKIM adds a digital signature to each outgoing email message. This signature is linked to the domain and is verified against a public cryptographic key in the domain's DNS records. It ensures that the content of the email has not been tampered with in transit.
- DKIM should be implemented by all senders.
DMARC (Domain-based Message Authentication, Reporting, and Conformance)
DMARC is a policy framework that utilizes both SPF and DKIM. It allows domain owners to indicate that their emails are protected by SPF and DKIM, and tells receiving mail servers what to do if neither of those authentication methods passes, such as rejecting the email or flagging it as spam. DMARC also includes reporting capabilities, enabling domain owners to receive reports on how their emails are being handled.
- DMARC should be implemented by senders who send 5,000+ emails per day.
How do I implement email authentication best practices?
Below are quick overviews of how to implement each of the best practices; check out the linked guides for more detailed information.
How to implement SPF
- Create an SPF record: This is a TXT record in your domain's DNS settings that lists all the mail servers authorized to send emails on behalf of your domain.
- Publish the record: Add this record to your domain's DNS settings. An example SPF record looks like v=spf1 include:_spf.google.com ~all.
- Test the SPF record: Use online tools to ensure your SPF record is valid and correctly implemented.
How to implement DKIM
- Generate a DKIM key: This is typically done through your email service provider and involves creating a public and private key pair.
- Publish the public key: Add the public key to your domain's DNS settings as a TXT record. Your email service provider will use the private key to sign your emails.
- Configure your email server: Ensure your email server or service provider is configured to sign outgoing emails with the DKIM key.
- Test your DKIM setup: Verify that your emails are being signed correctly using DKIM testing tools.
How to implement DMARC
- Create a DMARC record: This is a TXT record in your domain's DNS that defines your DMARC policy and uses SPF and DKIM to validate emails.
- Publish the DMARC record: Add this record to your domain's DNS settings. An example DMARC record is v=DMARC1; p=reject; rua=mailto:[email protected].
- Monitor reports: DMARC provides feedback on how your emails are processed by receivers, helping you identify and fix authentication issues.
What is a sender reputation?
Your company's email sender reputation is a numerical score (0–100) assigned by Internet Service Providers (ISPs) to each organization that sends emails. This metric is a critical factor in determining your email deliverability. A higher sender reputation score indicates to ISPs a higher level of trust in the legitimacy and quality of your email communications. Consequently, a high score increases the probability that your emails will be successfully delivered to the inboxes of recipients in the ISP's network. Maintaining a strong sender reputation is therefore essential for ensuring reliable and effective email delivery in a business context.
How do I check my sender reputation?
Many free tools can be used to check your sender reputation; we suggest one of the following:
FAQ
Why did Ashby send an email about email deliverability to our Google Workspace Admin?
In an effort to further curtail spam, Google and other email service providers have begun enforcing the use of best-practice email authentication methods. Ashby reached out to ensure your team is ready for this change so your team's emails continue to be delivered successfully. Read Google's blog post about Gmail security and authentication for more information about this change.
Why do Ashby emails include a “Report this email to Ashby” footer?
This footer gives candidates a direct way to report concerns about emails sent through Ashby. These reports help us protect candidates and maintain the security and reliability of Ashby’s email infrastructure.
Ashby includes the footer on all emails sent via the [email protected] address. It cannot be edited or removed. This footer's presence does not indicate a problem with your organization or a specific message.
Recipients can learn more on our webpage: Report Abuse