The Filters Come Before the Words
A newsletter's deliverability fate is settled before any human eyes reach the subject line. Mail servers exchange three layers of authentication in the seconds after a message arrives, and a failure at any layer can route the message to spam — or drop it entirely.
SPF (Sender Policy Framework) is the simplest: a DNS TXT record that lists which IP addresses are authorised to send mail for a domain. A message arriving from an unlisted server fails SPF. DKIM (DomainKeys Identified Mail) goes further, attaching a cryptographic signature to the message headers; the receiving server fetches the corresponding public key from DNS and verifies that the content hasn't been altered in transit. DMARC (Domain-based Message Authentication Reporting and Conformance) sits atop both. It tells receiving servers what to do when SPF or DKIM fails — quarantine the message, reject it outright, or do nothing — and routes aggregate reports back to the sender so failures can be diagnosed.


None of these standards is new. SPF dates to the early 2000s. DKIM was formalised as RFC 6376 by the IETF in 2011. DMARC reached RFC status as RFC 7489 in 2015. For most of that period, adoption was patchy and enforcement was gentle. That changed in February 2024.
The 2024 Deadline Changed the Calculus
Google and Yahoo jointly announced requirements for bulk senders — any domain sending more than five thousand messages per day to Gmail addresses. The requirements: a valid SPF record, DKIM signing, and a DMARC policy of at least p=none. Google also mandated a working one-click unsubscribe header (List-Unsubscribe-Post) and a spam complaint rate below 0.10 percent. Senders who missed the deadline faced message rejection, not just filtering.
From the record
Key standards and their roles
- SPFa DNS record declaring which servers may send mail for a domain
- DKIMa cryptographic signature letting receivers verify message integrity
- DMARCa policy layer directing what happens on SPF/DKIM failure, plus feedback reporting
- List-Unsubscribe-Posta header enabling one-click unsubscribe, mandated by Google's 2024 bulk sender rules
- DMARC alignmentthe requirement that the DKIM signing domain or SPF-authenticated domain matches the visible From address
Timeline
- Early 2000sSPF developed
- 2011DKIM standardised as RFC 6376
- 2015DMARC standardised as RFC 7489
- February 2024Google and Yahoo enforce bulk sender authentication requirements
For newsletter operators running on Substack, Ghost, beehiiv, or Mailchimp, the major platforms handle DKIM signing on a shared or custom domain basis and push DMARC setup to the sender's DNS. Getting the DNS records wrong — a mismatched alignment between the DKIM signing domain and the From header — can invalidate DMARC even when SPF passes. The failure mode is silent: the message looks fine to the sender, and vanishes for the recipient.
Deliverability infrastructure is infrastructure. A writer who produces genuinely useful work but ships it through a domain with no DMARC policy and a misconfigured SPF record is producing for an audience that may never receive it. The authentication paperwork is not a detail; it is the first editorial decision.



