You rewrote the subject line, cut the exclamation mark, and sent it again. It went to spam again.
That is the normal experience, and it is a clue. The filter was probably never grading the sentence you changed. It was grading you.
Filters score senders, not sentences
Reputation attaches to what persists between messages — the sending domain, the IP or pool the mail leaves from, the authenticated identifiers, the links inside. It accumulates from how recipients react over time.
A sender with a long, uneventful history survives things that would sink an unknown one — an odd attachment, a burst of volume, a handful of complaints. A sender with no history has nothing to survive on, so every ambiguous signal resolves against them.
Which is why "but my email is well written" is not an argument. Nobody said otherwise.
Authentication is the cheap part
Publish SPF, DKIM, and DMARC, and make sure the authenticated domains align with the address in the From line — SPF, DKIM, and DMARC explained covers the mechanics and the alignment trap.
Be clear about what this buys. Passing authentication does not create trust — it removes a cheap, machine-checkable reason to distrust you, and lets reputation attach to your domain rather than to nothing. Failing it, or publishing records that contradict how you actually send, is one of the few unambiguous negatives within your control.
Volume and pattern changes
Filters notice change more than they notice level.
A new domain that starts sending in quantity looks exactly like a domain bought to send in quantity. Ramping up gradually is the standard answer — not a trick, just letting reputation accrue before you lean on it.
Established senders trip this too. A sudden multiple of the usual volume, a new platform, a change of infrastructure — each resets part of what receiving systems thought they knew.
Two more negatives are self-inflicted: sending to addresses that no longer exist, and sending to addresses that were never real. Both say the list is unmaintained, and an unmaintained list is one nobody consented to.
Recipients decide more than you do
The loudest inputs come from people. Marking as spam, deleting unread, and never engaging push one way. Opening, replying, and rescuing a message from the spam folder push the other.
That has an uncomfortable implication for outreach. Mail to people who did not ask for it does not merely annoy them — it trains the system to distrust your domain, and the cost lands on the messages you needed delivered. Your invoice suffers for your campaign.
Someone using the unsubscribe link is doing you a favour compared with the alternative button — what an unsubscribe link signals goes further into that. Many jurisdictions have rules about commercial mail; that is a question for your counsel, not a blog post.
Links and images do more damage than words
The folk model of forbidden words is largely obsolete. Individual phrases are weak evidence weighed against everything else. What still registers is shape:
- A message that is one large image with almost no text, which reads as empty to anything that cannot see pictures.
- Link text that says one thing and points somewhere else.
- Shorteners and redirect chains that conceal the final destination.
- Links to a domain whose reputation someone else already ruined.
- File types that carry executable risk.
Remote images are their own trap. Many clients decline to load them by default, so a message whose meaning lives in pictures arrives blank. A tracking pixel is just a remote image — a request to a third party the reader never made.
Nobody can promise the inbox
Filtering is opaque on purpose, and it has to be. A published rule set is an evasion manual — the moment the criteria are known, the senders you least want optimize against them first. The rules also move, because the other side adapts.
So treat any promise of inbox placement as a wish. You can remove reasons to be distrusted. You cannot compel a decision made on infrastructure you do not own, by a system that will not explain itself. Outright rejection at least produces a bounce with a code; quiet filing into a spam folder produces silence.
A new agent address is the worst-case profile
Now assemble the profile of a freshly minted address for an AI agent. New domain. No history. Machine-generated text. Recipients who never asked. A rate no person could sustain. A link in every message.
That is not a caricature. It is the archetype filters exist to catch, and being sincere does not change the shape.
RelayLink's approach is to not give the agent a mailbox at all, and to send mail that is deliberately dull. Notifications are plain text — no HTML body, so no images and no tracking pixel. Each carries the unsubscribe link twice, as a visible URL in the footer and as the header a mail client reads for its own unsubscribe button, and using it blocks that sender permanently rather than ending one campaign. The consent limits live on the sending side rather than in a prompt; consent in AI-to-AI communication sets out how.
The honest limits. This moves the reputation problem to the relay rather than abolishing it, and RelayLink cannot promise placement either. It also knows less about delivery than you might assume: it records an email as queued before the provider call is even attempted, it has no bounce or complaint handling, and it can tell a sender that a package was seen — meaning the magic link was fetched or the recipient's assistant pulled it — but never whether the email itself was opened.
If the alternative you were weighing is your own sending domain, RelayLink versus a DIY agent email account compares them honestly. The recipient's side of all this is how to stop AI-generated spam. Or connect your assistant and make deliverability someone else's standing problem.