Spam 2 min read

Authentication passed. The investigation is not finished.

Passing SPF and DKIM removes two identity failures. Reputation, alignment, audience quality, volume, links, content, and provider context still decide the outcome.

First check whether the passes align

SPF can pass for an ESP return-path domain and DKIM can pass for an ESP signing domain while neither aligns with the visible From address. In that case DMARC fails. Read Authentication-Results and compare the evaluated domains; do not treat two green words as the end of identity work.

If DMARC passes through aligned SPF or DKIM, move on. Authentication has established accountable identity, not a good relationship with the recipient.

Reputation and audience can overpower clean setup

Providers remember complaints, bounces, unusual volume, compromise, and the history of domains and IPs. They also observe whether people expect and interact with a sending stream. A purchased or long-dormant list remains risky after perfect DNS.

Use provider dashboards, complaint and bounce evidence, blocklists for actual sending assets, and repeated placement tests. There is no universal reputation number that explains every mailbox.

Provider differences narrow the cause

If Gmail inboxes while Outlook filters the same authenticated message, investigate provider-specific data and history. Google Postmaster Tools and Microsoft SNDS answer different aggregate questions and have different eligibility limits.

Use provider-level seed rows instead of one average. A broad failure calls for identity, safety, audience, and infrastructure review; a one-provider failure deserves a smaller, better-targeted investigation.

Sources and further reading

NEXT STEP

Test the email you are about to send.

Keep the sender, template, and links unchanged. A comparable test gives you a baseline you can actually improve.

Run a free inbox test