First check whether the passes align
SPF can pass for an ESP return-path domain and DKIM can pass for an ESP signing domain while neither aligns with the visible From address. In that case DMARC fails. Read Authentication-Results and compare the evaluated domains; do not treat two green words as the end of identity work.
If DMARC passes through aligned SPF or DKIM, move on. Authentication has established accountable identity, not a good relationship with the recipient.
Reputation and audience can overpower clean setup
Providers remember complaints, bounces, unusual volume, compromise, and the history of domains and IPs. They also observe whether people expect and interact with a sending stream. A purchased or long-dormant list remains risky after perfect DNS.
Use provider dashboards, complaint and bounce evidence, blocklists for actual sending assets, and repeated placement tests. There is no universal reputation number that explains every mailbox.
Links and message construction still matter
Compromised destinations, public shorteners, unfamiliar tracking domains, redirect chains, malformed HTML, hidden identity, and one-image templates can make the message harder to trust. Context matters more than a list of forbidden words.
Open final tracked links and make the message understandable without images. Change one meaningful issue and test through the same production route again.
Provider differences narrow the cause
If Gmail inboxes while Outlook filters the same authenticated message, investigate provider-specific data and history. Google Postmaster Tools and Microsoft SNDS answer different aggregate questions and have different eligibility limits.
Use provider-level seed rows instead of one average. A broad failure calls for identity, safety, audience, and infrastructure review; a one-provider failure deserves a smaller, better-targeted investigation.