A domain can pass SPF, DKIM, and DMARC cleanly and still lose 30-40% of its sends to spam. Authentication is table stakes, not a deliverability guarantee — it's the entry ticket, not the score. We see this constantly when we onboard a new customer who "already has deliverability figured out": records are configured correctly, warmup was done by the book, and reply rates have still quietly dropped from 4% to under 1% over three months with no obvious cause. Nobody flipped a switch. A dozen small things drifted at once, and the aggregate effect is a domain that technically passes every check while landing mostly in Promotions or spam.
The fix isn't another round of subject line testing. It's a structured audit — the same one we run on every domain before it goes into active rotation, and again on a recurring basis for anything sending at volume. Below is the 12-point version, organized into the four layers that actually determine inbox placement: authentication, reputation, list quality, and sending behavior.
1. SPF, DKIM, and DMARC status. Not "is it published" — is it passing on every sending source touching the domain, with no permerrors from lookup limits. We cover the full mechanics in our SPF, DKIM, and DMARC setup guide, but the audit-specific check is drift: a marketing tool or CRM added six months after initial setup that silently created a second SPF record, or a DKIM selector that expired during a platform migration.
2. Domain and mailbox age. A domain under 90 days old, or a mailbox that skipped warmup and jumped straight to campaign volume, will get throttled by Gmail and Microsoft regardless of how clean everything else looks. Check actual send history against the warmup curve, not just the calendar date the domain was registered.
3. Subdomain isolation. Confirm prospecting traffic runs through a dedicated sending subdomain, separate from the root domain used for corporate or transactional mail. If a company's cold outreach and its billing receipts share a domain, a reputation hit from one bleeds into the other.
4. Blacklist status. Run the sending IP and domain through a multi-list blacklist checker (Spamhaus, Barracuda, SORBI, and the major ISP-specific lists) monthly, not just when something breaks. A domain can land on a minor list quietly and stay there for weeks before anyone notices open rates dropped.
5. Google Postmaster Tools and Microsoft SNDS data. These are the two direct signals mailbox providers give senders about their own reputation, and most teams never look at them. Postmaster Tools shows spam rate, domain reputation trend, and IP reputation separately — a domain can have "good" reputation while a specific sending IP is flagged, which a generic deliverability test will miss entirely.
6. Feedback loop complaint rate. Anything above 0.3% spam complaints per send is a structural problem, not noise — it usually traces back to list quality or an aggressive send cadence rather than message content. Above 0.1% is worth investigating; above 0.3% is worth pausing the domain.
7. Bounce rate by segment. A blended bounce rate under 2% can hide a subsegment — say, a scraped list of a specific job title or region — bouncing at 15%. Break bounce rate out by list source and enrichment date, not just in aggregate, to find where the data is stale.
8. Spam trap density. Pristine traps (addresses that were never real and exist purely to catch purchased or scraped lists) and recycled traps (dead addresses mailbox providers reactivate specifically to catch senders who don't clean their lists) both do outsized reputation damage per hit. If a list hasn't been verified in the last 30-60 days, assume some trap exposure. Our prospect data audit framework covers the verification workflow in more depth.
9. Role-based and catch-all address ratio. info@, sales@, and catch-all domains that accept any address without validation inflate apparent list size while dragging down engagement rates, which mailbox providers read as a reputation signal over time. A healthy B2B list should keep role-based addresses under 5%.
10. Volume consistency. Mailbox providers build a baseline expectation for a domain's sending pattern. A domain that sends 40 emails a day for three weeks and then spikes to 400 in a single day looks like a compromised account or a burst spam campaign, even if every message is legitimately targeted B2B outreach. Ramp changes gradually and keep day-to-day variance under roughly 20%.
11. Engagement-to-volume ratio over time. Track opens, replies, and — critically — the delete-without-open rate as volume scales. If reply rate holds steady but delete-without-open climbs, that's an early warning that targeting or subject lines are degrading before it shows up in a harder metric like spam placement.
12. Time-of-day and sequencing pattern. Sends that go out in identical, second-perfect batches read as automated in a way that content alone doesn't. Natural jitter in send timing, and varied delay windows between touches in a sequence, reduce the pattern-matching signal that spam filters increasingly weight.
This isn't a one-time exercise — it's a recurring check, ideally monthly for actively sending domains and immediately after any unexplained drop in reply rate. The order matters: check authentication first, because a failure there invalidates everything downstream (a domain failing DKIM will show poor engagement no matter how clean the list is). Then reputation, then list quality, then behavior. Most audits find the problem in the first two layers — authentication drift and reputation issues account for a large majority of the deliverability collapses we diagnose, with list quality and sending behavior explaining most of the rest.
One customer running B2B outreach at moderate scale came to us with reply rates that had fallen from 3.8% to 0.9% over ten weeks. Authentication passed cleanly. The audit found the actual cause two layers down: a data provider integration had started feeding in a batch of role-based and catch-all addresses at a roughly 18% rate, up from under 3% previously, which had dragged domain reputation down enough to affect inbox placement for the entire sending pool — including the well-targeted, correctly-addressed portion of the list. Fixing the enrichment filter and re-warming the affected mailboxes brought reply rates back to 3.2% within four weeks. Nothing about the messaging changed.
Most teams running cold email automation treat deliverability as a setup problem — get SPF, DKIM, and DMARC right once, warm up the domain, and move on to writing sequences. The audit framework above exists because deliverability is a maintenance problem, not a setup problem. Reputation and list quality degrade continuously in small increments, and by the time the drop shows up clearly in reply rates, the underlying cause is usually weeks old and several layers removed from where the symptom appears.
This is also where the case for automated prospecting over manual list-building becomes concrete rather than theoretical. A rep manually pulling contacts from a handful of sources has no visibility into role-based address creep or spam trap exposure until a domain is already damaged. Our ICP scoring framework and enrichment pipeline are built to catch data quality problems before they reach a sending domain, and our platform runs the authentication and reputation checks above on a recurring basis rather than as a one-time setup task — the kind of ongoing monitoring that's easy to skip when it's a manual line item on someone's checklist and hard to skip when it's built into the sending infrastructure itself.
If your reply rates have drifted down without an obvious cause, run this framework top to bottom before touching your copy. See how OnyxSend handles deliverability monitoring as part of automated prospecting, or request access to get your sending domains audited against all twelve points above.