I look at these dashboards constantly, and the number at the top doesn't really tell me what you'd assume it does.
In 2025, Unspam.email ran millions of tests across consumer and enterprise mailbox providers and found that only 60% of email reaches a visible mailbox location. Another 36% gets filtered into spam. Did you know, that the remaining 4% is blocked outright and never lands anywhere at all?
Technical delivery success, in their words, now overstates real inbox reach by about 40%.
That's the 2025 picture. In January of this year Gmail added an AI layer on top of it.
Delivery and Deliverability Are Different Things
Most senders conflate two numbers that measure completely different events.
- Delivery means a receiving server accepted your message. That's about it. The handshake completed, the server said yes, your platform logged a success, you see this number reported. An email that lands directly in the spam folder still counts as delivered.
- Deliverability means the message reached somewhere a human might actually look.
Your dashboard reports the first number because it's the only one your sending platform can see. What happens after the receiving server accepts your message is invisible to you, and that's where filtering decisions get made.
The benchmarks don't agree with each other though.
Validity's 2025 benchmark report found that one in six legitimate marketing emails fails to reach the inbox, which puts global placement around 84%. EmailToolTester's own testing across 15 email platforms landed at 83.1%, with 10.5% going to spam and the rest vanishing entirely.
Unspam's number is far lower, and they explain why. Their corpus spans cold outreach and transactional mail alongside established marketing programs, so it captures a rougher slice of the email world than a marketing-only benchmark does.
Worth noting their own figure moves too. The full-year 2025 report says 60% while their more recent rolling statistics put it at 65%. Even a single source measuring the same thing lands five points apart depending on the window.
So your experience depends heavily on what kind of sender you are. An established list with real engagement does far better than the average. A cold outreach program drags it down.
Run a newsletter people actually asked for and you're on the good side of that spread, though the ceiling is lower than you'd like.
SPF, DKIM, and DMARC
Since these three come up constantly and get explained badly, let me do it properly.
They exist to answer one question for the receiving server.
Is this message really from who it claims to be from?
Email was designed in an era when nobody considered that people would lie about their identity, so the From field is trivially forgeable. These three protocols are the patches bolted on afterward.
- SPF (Sender Policy Framework) is a guest list. You publish a DNS record naming which servers are allowed to send email on behalf of your domain. When a message arrives claiming to be from your domain, the receiver checks whether it came from a server on that list. If your ESP sends your newsletter, your SPF record needs to name your ESP.
- DKIM (DomainKeys Identified Mail) is a wax seal. Your sending server signs each message with a private cryptographic key. You publish the matching public key in DNS. The receiver verifies the signature, which proves both that the message came from you and that nobody altered it in transit.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) is the policy layer sitting on top. It tells receivers what to do when SPF or DKIM fails. You can say do nothing, quarantine it, or reject it entirely. DMARC also gives you reports on who is sending mail claiming to be you, which is how you discover somebody is spoofing your domain.
Adoption is high for the first two. Unspam's 2026 benchmark puts SPF at roughly 93% of tested senders and DKIM at about 90%. DMARC sits lower at 64%, which means over a third of senders are still running without the policy layer that ties the other two together.
Get all three right and you've cleared the entry requirement. That used to be enough.
Why Authentication Stopped Being Enough
The same 2025 analysis found that fully authenticated mail, with all three protocols valid and passing, still landed in spam more than 30% of the time.
I had to read that twice 🤯
If you've been running on the assumption that correct authentication means inbox placement, it doesn't, and it hasn't for a while.
Authentication answers who you are. That's it.
Once the receiver knows that with confidence, it moves to a completely different question, which is whether anyone actually wants what you're sending.
That second question gets answered with behavioural signals.
Opens, clicks, replies, time spent reading, deletions without reading, complaints. Providers weigh these far more heavily than a passing authentication check, because compliance is cheap to fake and engagement is not.
Complaint rate is the one to watch most closely.
Google asks bulk senders to keep the user-reported spam rate below 0.10% and to never let it reach 0.30%. Both numbers matter, because Google states plainly that anything above 0.10% already hurts your inbox delivery.
For a list of 10,000 people, 0.30% is 30 complaints.
That's indeed a very small number of annoyed subscribers standing between you and a reputation problem.
Cross that line and you lose access to mitigation, which is Google's escalation process for when your delivery breaks and you need a human to look at it. Rates are recalculated daily in Postmaster Tools, and you only become eligible again after staying below 0.30% for seven consecutive days.
What Changed Between 2024 and Now
Enforcement tightened in stages, and 2026 is the first full year in which the largest providers reject non-compliant bulk mail outright rather than quietly filing it in spam.
| When | Who | What happened |
|---|---|---|
| Feb 2024 | Google and Yahoo | Bulk sender requirements go live. Authentication required, complaint rate under 0.30% |
| Apr 2024 | Begins rejecting some non-compliant traffic | |
| Jun 2024 | Deadline for one-click unsubscribe on commercial and promotional mail | |
| May 2025 | Microsoft | Hard rejection at the SMTP level for Outlook, Hotmail, and Live. Safe Sender lists cannot override it |
| Nov 2025 | Enforcement ramps up. Soft warnings end, replaced by temporary and permanent SMTP rejections | |
| Jan 2026 | Gemini 3 ships inside Gmail |
The Microsoft entry is worth a footnote. They originally planned to route non-compliant mail to the Junk folder and reject it later, then reversed course six days before launch and went straight to rejection, citing a desire to remove confusion about why messages were being filtered.
Failures come back as 550 5.7.515, and a recipient adding you to their Safe Senders list will not rescue you if the underlying authentication is broken.
Apple announced its own requirements alongside Google and Yahoo, but enforcement has stayed vague, and most analysts expect them to formalize it sometime across 2026 and 2027.
Two details in Google's own documentation are worth knowing.
A bulk sender is anyone sending close to 5,000 messages or more to personal Gmail accounts inside 24 hours, and subdomains aggregate toward that total. Cross the line once and you are permanently classified a bulk sender. There is no route back by lowering your volume afterward.
The rules also apply to free Gmail accounts rather than Workspace ones, which Google clarified after the original announcement.
The failure mode changed with that shift.
It used to be a quiet slide into spam that you might notice months later in declining opens. Now it's a visible bounce in your sending logs.
Which is an improvement, honestly.
The rules became objective, so you can check whether you comply instead of guessing.
Most senders didn't bother, unfortunately. Two years into enforcement, roughly 30% of bulk senders still fail at least one requirement, and the most common miss is the RFC 8058 one-click unsubscribe header.
Google's own enforcement table splits the consequences into two tiers.
Authentication problems get your mail rejected or spam-foldered outright. Everything else, including a spam rate over 0.30% or a missing unsubscribe header, cuts you off from delivery support instead.
Your mail still flows, but when something breaks you have no path to a human at Google.
Compliant senders average around 89% inbox placement. Non-compliant senders see 22% to 34% of their mail routed to spam, against a baseline of 5% to 10%.
That unsubscribe requirement is stricter than most people assume. It has to be the List-Unsubscribe header paired with List-Unsubscribe-Post, per RFC 8058. A mailto link doesn't satisfy it. Neither does a link in your message body, and Google explicitly won't go looking for one if the header is missing.
Honour requests within 48 hours!
The one piece of relief is that transactional mail is exempt.
Password resets and order confirmations don't need it, since the requirement covers marketing and promotional messages only.
Then Gemini Showed Up
On January 8, 2026, Gmail entered what Google calls the Gemini era.
AI Overviews now summarize email threads, rolling out to everyone at no cost.
Paid subscribers can ask their inbox questions in natural language. A new AI Inbox, still in limited testing, sits above the traditional view and filters out what it decides is unimportant.
Gmail has roughly 1.8 billion users and accounts for about a quarter of all tracked email opens. So a large share of your subscribers are now reading you inside an AI-mediated inbox whether they chose that or not.
Nieman Lab noticed something in Google's announcement that should concern anyone running a newsletter. The blog post said nothing at all about how the AI Inbox will handle newsletters. Not how they'll be prioritized, not how they'll be summarized, not whether they'll be filtered as noise.
Back in June I made the case that email was the last channel where a human verifiably opens the thing, hedged with a "for now at least" and a note that inbox AI was coming eventually.
Looks like it had already arrived...
Gemini shipped five months before I wrote that, and I hadn't connected it to my own sends. Which is a little embarrassing for someone who mails tens of thousands of people every morning.
Then I went and looked at the numbers.
What My Own Numbers Show
I pulled twelve months of broadcast data from our largest photography list, roughly 27,000 subscribers, spanning July 2025 through June 2026.
Through the back half of 2025 that list opened at right around 50%, drifting a point either side depending on the month. Clicks ran roughly 2%.
Gemini shipped January 8. Every month since has come in lower than the one before it, with no reversal.
Opens fell close to four points. Clicks didn't move.
By June the list was opening at roughly 47%, down almost seven points from where it peaked back in October last year.
If people were actually disengaging, clicks would fall alongside opens. They didn't. Click-to-open ratio nudged up, meaning each registered open now represents more real reading than it used to.
List size held steady at roughly 27,000 across the entire period, too.
Unsubscribes stayed well under a tenth of a percent. Bounce rate sits below half a percent. Those numbers rule out list decay and rule out a deliverability collapse.
Our resend segment moved further. Those are the follow-up sends we push to people who didn't open the first time. Their open rate dropped about a fifth, roughly triple what the main list saw.
Which makes sense. I mean, those are people who already skipped once. Hand them a summary and they have even less reason to click in.
I want to be careful about what I'm claiming though. This is correlation.
Apple's Mail Privacy Protection was already distorting the baseline before any of this. Content mix shifted across the year. Lists age. I also can't isolate the Gemini variable cleanly.
But the trend is monotonic across six months, and the two explanations you'd normally reach for, disengagement or list decay, are both ruled out by the click and list-size data.
Open Rate Is Broken in Both Directions
The industry narrative said AI would inflate your open rates, because Gemini pre-loads messages to summarize them and that fires your tracking pixel. That's real and it happens.
My data shows the opposite.
Both effects are real at the same time, which is what makes the metric useless now.
You get phantom opens from machines that loaded your email without a human ever seeing it. And you lose real opens from humans who read the AI summary, got what they needed, and never opened the message at all.
Call that second group the informed non-openers. They received your message and they may have acted on it. But, your analytics show nothing.
Apple started this in 2021 with Mail Privacy Protection, which pre-fetches images regardless of whether anyone opens. Litmus estimates that for most programs, roughly half of all reported opens are now inflated this way. AI summaries added a second distortion on top of the first.
If you're still reporting open rate as your headline metric, you're reporting on something that barely exists.
What to Measure Instead
Move your attention to signals that survive machine mediation.
Click-to-open ratio is the obvious first one. Of the people who registered an open, how many clicked? A bot loading a pixel doesn't click through, so this filters out a good chunk of the machine noise.
Reply rate is better still. It's the strongest engagement signal in Gmail's own model and the hardest to fake, because a reply is a human deciding to do something.
Then there's revenue per email sent, which is the number that actually tells you whether the program works. Money either arrives or it doesn't, and no tracking distortion touches it.
I'd also watch unsubscribe rate per campaign, since a rising rate means your content stopped matching what people signed up for, and leaving takes intent. And complaint rate, weekly, against Google's Postmaster Tools rather than whatever your ESP reports. Keep it under 0.10%.
Writing for a Reader Who Might Be a Machine
If a summary sits between your words and your subscriber, some practical adjustments follow.
Front-load everything.
Language models weight opening sentences heavily when generating a summary. If your point arrives in paragraph four, the summary won't carry it.
The old advice about burying the lede to build tension works against you now. Now you have to be very upfront about your intentions.
Keep the structure clean.
Unspam found that 74% of tested emails contained structural problems like invalid nesting or missing attributes, and messy markup produces messy summaries.
A model parsing a tangle of nested tables will pull out something less coherent than what you meant to say.
Lean plainer than you think you should.
HubSpot's analysis of more than half a billion marketing emails found that heavy HTML templates cut open rates by about 25%, and plain text drove 42% more clicks than image-heavy alternatives.
That research is several years old at this point, and the advantage only gets larger when a model is parsing your message.
Write subject lines that promise something a summary can't deliver.
If your entire value fits in one summarizable line, the summary replaces you. If the value sits in your voice, or your specific example, or the thing only you would have noticed, then the summary turns into an advertisement for opening.
That one matters more than the formatting advice above it. If a summary can replace your email, it will.
The Practical Checklist
| Area | What to do |
|---|---|
| Authentication | SPF, DKIM, and DMARC all configured and passing. Move DMARC to at least quarantine |
| Unsubscribe | List-Unsubscribe and List-Unsubscribe-Post headers present. Mailto links and body links don't count. Honor requests within 48 hours |
| Complaint rate | Under 0.10%. Check weekly in Google Postmaster Tools, not your ESP dashboard |
| List hygiene | Remove people who haven't engaged in 90 to 180 days. Mailing the disengaged actively damages your reputation |
| Monitoring | Watch inbox placement by provider. A Gmail-only drop points at a different cause than an across-the-board one |
| Metrics | Report click-to-open, reply rate, and revenue. Demote open rate to a diagnostic |
| Content | Front-load the value. Keep HTML simple. Write things a summary can't replace |
What Comes Next
AI Inbox is still limited to testers. When it rolls out broadly, an algorithm will be deciding which messages surface in a priority view and which get buried in a catch-up list.
Nobody outside Google knows how newsletters get classified in that system.
Agentic email handling is arriving on the other side too.
Assistants that triage, summarize, draft replies, and eventually act on messages without the human reading them.
That capability is already being built for customer service inboxes, where the goal is explicitly to resolve cases without a person involved. Point the same thing at a personal inbox and your subscriber may stop being the one who reads you.
The pattern rhymes with what already happened to search.
Content got summarized at the point of delivery, the click disappeared, and publishers who'd optimized for ranking found out they didn't own the channel.
Email has one structural advantage search never had. The subscriber chose you.
An agent can summarize a message someone asked to receive, but it can't make them un-ask for it. An agent scraping a public page has no such constraint.
Where That Leaves Us
Six out of ten emails reach somewhere a person might look, on the broadest measure of who's sending. Roughly a third of bulk senders still fail a requirement that's been public for two years.
And the inbox now has a reader sitting between you and your subscriber, summarizing you before they decide whether you're worth the tap.
My own numbers say that reader is costing me real opens, steadily, month over month, while the people who actually want what I send keep clicking at exactly the rate they always did, even slightly more.
Which I find more reassuring than not.
The machines seem to be absorbing the subscribers who weren't really reading anyway, and what's left is the group that chose you on purpose.
So fix your authentication, clean your list, and stop treating open rate like it means something.
Then go write something worth opening.