Pillar Guide

Email Deliverability Playbooks: Battle-Tested Strategies for Every Scenario

Ready-to-execute playbooks for email deliverability crises, migrations, launches, and scaling. Step-by-step guides for spam folder recovery, ESP migration, and more.

Boxset TeamFeb 20, 202623 min read
playbooksstrategymigrationcrisis managementdeliverabilitybest practices

Why Every Email Team Needs Playbooks

Email deliverability is not a "set it and forget it" discipline. It is an ongoing operational challenge where things go wrong regularly and unpredictably. Authentication records get misconfigured during routine DNS changes. A sudden influx of bad addresses from a lead generation campaign poisons your sender reputation. A blacklist operator flags your IP based on a spam trap hit you did not even know happened. Your ESP experiences an infrastructure incident that degrades delivery across your entire sending volume. These are not hypothetical scenarios. They happen to legitimate senders every week.

68 hrs

average time to detect a deliverability issue without automated monitoring

That figure comes from aggregate industry analysis of email operations teams that rely on manual monitoring, typically checking Google Postmaster Tools and ESP dashboards once or twice a week. Compare that to organizations using automated anomaly detection, which identify the same issues in an average of 4.2 hours. The difference between 68 hours and 4 hours of exposure is not marginal. It is the difference between a minor dip that resolves itself in a week and a full-blown reputation crisis that takes 60 to 90 days to remediate.

The purpose of a playbook is not merely documentation. It is operational readiness. When your inbox placement drops from 92% to 54% on a Monday morning, you do not have time to research what to do. You need a predefined sequence of diagnostic steps, triage actions, and recovery procedures that your team can execute immediately. Every hour of delay compounds the damage because mailbox providers continuously update their reputation models. An unanswered reputation drop on Monday becomes a deeper reputation drop on Tuesday, which becomes a blacklist event on Wednesday.

Playbooks also eliminate the single-point-of-failure problem. If the one person on your team who understands deliverability is on vacation when a crisis hits, the rest of the team has no reference point. A documented playbook transfers that expertise into an executable procedure that anyone with basic email operations knowledge can follow.

The six playbooks in this guide cover the scenarios that account for over 90% of deliverability incidents. Each one is structured as a step-by-step procedure with diagnostic criteria, action items, expected timelines, and success metrics. They are designed to be used in the moment, not just read in advance.

Playbook 1: Spam Folder Recovery

Spam folder placement is the most common and most damaging deliverability incident. One day your emails are reaching the inbox at 90%+ rates; the next, Gmail is routing 40% of your traffic to spam. Revenue drops, engagement metrics crater, and without intervention, the situation compounds daily.

The first step is always diagnosis. Spam folder issues stem from four primary root causes, and the correct recovery strategy depends entirely on which root cause is at play. Applying the wrong fix wastes critical time and can deepen the problem.

Authentication failure is the fastest to diagnose and fix. Check your SPF, DKIM, and DMARC records using DNS lookup tools. Look for recent DNS changes that may have overwritten or invalidated your records. SPF records that exceed the 10-lookup limit, expired DKIM keys, and DMARC misalignment between the header From domain and the authentication domain are the most common culprits. Authentication fixes can restore inbox placement within 24 to 48 hours.

Reputation degradation is the most common root cause. Check Google Postmaster Tools for your domain reputation score. If it has dropped from High to Medium, Low, or Bad, you are dealing with a reputation issue driven by one or more factors: rising complaint rates, increased bounces, declining engagement, or a combination. Reputation recovery takes 2 to 6 weeks of disciplined action.

Content triggers are less common in 2026 than they were historically, but they still occur. If your reputation is healthy and authentication is intact, analyze your recent email content for elements that may trigger machine learning filters: heavy image-to-text ratios, links to newly registered or low-reputation domains, HTML rendering errors, or sudden changes in content format that diverge from your historical sending patterns.

Blacklist placement causes sudden, dramatic drops. Check your sending IPs and domains against major blacklists including Spamhaus, Barracuda, SORBS, and Proofpoint. A single blacklist hit on Spamhaus can reduce your inbox placement to near zero at multiple providers simultaneously.

Recovery timelines vary significantly based on root cause and response speed. Authentication fixes can restore placement in 1 to 3 days. Reputation recovery from complaint rate spikes typically takes 2 to 4 weeks. Recovery from a major blacklist incident can take 3 to 8 weeks depending on the blacklist operator's delisting process. The single most important variable is how quickly you begin the recovery process. Every day of delay adds approximately 3 to 5 days to the total recovery timeline.

Playbook 2: ESP Migration

Migrating from one Email Service Provider to another is one of the highest-risk operations in email. Done poorly, it results in weeks of degraded deliverability, lost revenue, and subscriber confusion. Done well, it is seamless and invisible to your recipients. The difference comes down to preparation and execution discipline.

The fundamental challenge of ESP migration is that your domain reputation is portable but your IP reputation is not. When you move from ESP A to ESP B, your domain reputation follows you, but you are sending from entirely new IP addresses that have no reputation of their own. If your new ESP assigns you dedicated IPs, those IPs start cold. Even if you are placed on shared IPs, the overall sending infrastructure change can trigger temporary scrutiny from mailbox providers.

Phase 1: Pre-migration preparation (2-4 weeks before cutover). Audit your current authentication records and document every SPF include, DKIM key, and DMARC configuration. Map your current sending volume, patterns, and engagement metrics to establish a baseline. Verify that your new ESP supports the same authentication standards and can replicate your current DNS configuration. Export and clean your subscriber lists. Remove all hard bounces, complaints, and addresses that have not engaged in 180+ days. Do not migrate bad data to your new platform.

Phase 2: DNS configuration and IP warmup (2-3 weeks). Configure SPF, DKIM, and DMARC records for your new ESP while keeping your existing records active. If your new ESP provides dedicated IPs, begin warming them using your most engaged subscriber segment at low volume. Follow a standard warmup schedule: start at 100 to 200 emails per day and increase by 30 to 50% daily while monitoring bounce rates, open rates, and complaint rates.

Phase 3: Parallel sending period (1-2 weeks). This is the most critical phase and the one most teams skip. Run both ESPs simultaneously, splitting your traffic by segment or by percentage. Send 80% through your old ESP and 20% through the new one. Monitor deliverability metrics for each ESP independently. Gradually shift traffic: 60/40, then 40/60, then 20/80. This parallel period ensures that if the new ESP encounters deliverability issues, you can quickly shift traffic back without losing your entire sending capability.

Phase 4: Full cutover and old ESP decommission (1 week). Once the new ESP is handling 80%+ of traffic with stable metrics for 7 days, complete the cutover. Update DNS records to remove old ESP entries from SPF. Deactivate sending on the old platform. Monitor metrics closely for 14 days post-cutover, as this is when latent issues surface.

The three most common ESP migration mistakes that cause deliverability damage: (1) Cutting over 100% of traffic to the new ESP on day one without a warmup period, which triggers spam filtering on the new IPs. (2) Forgetting to update SPF records, causing authentication failures that silently route emails to spam. (3) Migrating your entire list including unengaged and bounced addresses, poisoning your new sending reputation from the start. A parallel sending period of at least 7 days eliminates the first risk. A DNS audit checklist eliminates the second. A list cleaning pass before migration eliminates the third.

The total ESP migration timeline for a well-executed transition is 5 to 8 weeks from preparation to full cutover. Rushing this timeline to meet an internal deadline is the most common source of migration-related deliverability damage. If your contract with the old ESP is expiring, negotiate an extension rather than cutting corners on the migration process.

Playbook 3: Blacklist Removal

Being listed on an email blacklist is one of the most acute deliverability crises a sender can face. Unlike reputation degradation, which erodes inbox placement gradually, a blacklist hit can cause a sudden and dramatic drop in delivery rates. Understanding which blacklists matter, how to get delisted, and how to prevent recurrence is essential knowledge for every email operations team.

Not all blacklists are created equal. There are over 300 known email blacklists, but only a handful have meaningful impact on your deliverability. The severity of a blacklist hit depends entirely on which list you are on and which mailbox providers consult that list for filtering decisions.

Detection is the first challenge. Many senders discover they are blacklisted only after noticing a sustained drop in delivery or inbox placement. Proactive monitoring involves regularly checking your sending IPs and domains against major blacklists. Tools like MXToolbox, Hetrix, and Boxset's Seltra monitoring provide automated blacklist checks. Best practice is to run checks daily for all active sending IPs and domains.

Impact assessment determines your response urgency. A listing on Spamhaus, which is consulted by the majority of enterprise email servers and many consumer mailbox providers, requires immediate action. A listing on a minor, obscure blacklist that no major provider consults may require no action at all. Focus your energy on the blacklists that actually affect your delivery.

The delisting process follows a consistent pattern regardless of which blacklist you are on. First, identify and resolve the root cause that triggered the listing. Common triggers include sending to spam traps (recycled or pristine), high complaint rates, sending to large numbers of invalid addresses, and compromised sending infrastructure. Second, submit a delisting request with evidence of what caused the listing and what you have done to prevent recurrence. Third, monitor the listing status and your delivery metrics after removal to confirm the delisting has propagated.

Root cause remediation is more important than the delisting itself. Getting delisted without fixing the underlying problem guarantees relisting, often within days. If spam traps triggered the listing, you need to identify and remove them, which typically means running your entire list through a verification service and implementing double opt-in for new signups. If complaint rates triggered it, you need to audit your content, frequency, and unsubscribe process. Blacklist operators track repeat offenders and become progressively less willing to delist senders who do not demonstrate genuine remediation.

Post-delisting monitoring should continue for at least 30 days. Check the blacklist daily for the first week to confirm you remain delisted. Monitor delivery rates and inbox placement across all major mailbox providers to verify that the delisting has restored your sending capability. If you are relisted within 30 days, the root cause was not fully resolved and you need a deeper investigation.

Playbook 4: New Domain Launch

Launching a new sending domain is a foundational operation that sets the trajectory of your email program for months or years. A domain launched correctly builds reputation quickly and reaches full sending capacity in 30 to 60 days. A domain launched incorrectly accumulates negative signals that can take months to overcome, and in severe cases, the domain may never recover to full deliverability.

Step 1: Domain registration and aging. Register your sending domain at least 2 to 4 weeks before you plan to send your first email. Newly registered domains are treated with heightened suspicion by mailbox providers. A domain that has existed for 30+ days before it begins sending carries more implicit trust than one that starts sending within hours of registration.

Aged domains carry significantly more baseline trust than freshly registered ones. If you are planning a new email program and have time to prepare, register your sending domain 30 to 90 days before your first send. During this aging period, set up a basic website on the domain with legitimate content and ensure the domain has valid WHOIS information. Some experienced operators acquire existing aged domains with clean histories from domain marketplaces. An aged domain with no negative history can reduce your warmup timeline by 20 to 30%.

Step 2: DNS authentication setup. Before sending a single email, configure all authentication records. SPF should include only the IP ranges or ESP include mechanisms you will actually use. Keep it as tight as possible and well within the 10-DNS-lookup limit. Generate a 2048-bit DKIM key pair through your ESP and publish the public key as a DNS TXT record. Configure DMARC starting at p=none with reporting enabled (rua and ruf tags) so you receive aggregate and forensic reports. Plan to move to p=quarantine after 30 days and p=reject after 60 days of clean reports.

Step 3: Infrastructure decisions. Decide between shared and dedicated IPs based on your target volume. If you plan to send fewer than 50,000 emails per month, shared IPs managed by your ESP are typically the better choice because they already have established reputation. Above 100,000 emails per month, dedicated IPs give you full control over your reputation. Between 50,000 and 100,000, either approach can work depending on your ESP's shared IP quality.

Step 4: Initial audience selection. Your first recipients must be your most engaged and most forgiving audience. Internal team members, business partners, existing customers who have purchased recently, and opt-in subscribers who have engaged with your brand on other channels. These people will open, click, and reply, which generates the positive engagement signals that form the foundation of your domain reputation.

Step 5: Warmup execution. Follow a structured warmup schedule. Start at 50 to 100 emails per day during the first week, targeting open rates above 50%. Increase by 30 to 50% every 2 to 3 days as long as metrics remain healthy. Pause or reduce volume immediately if bounce rates exceed 2%, complaint rates exceed 0.05%, or open rates fall below target thresholds for the current phase. A complete warmup to moderate volume (10,000 to 20,000 per day) takes approximately 30 to 45 days.

Step 6: Graduation to full volume. Once your domain has maintained healthy metrics at your intermediate target volume for 7 consecutive days and Google Postmaster Tools shows Medium or High reputation, begin scaling to full volume. Increase by no more than 25% per week during this graduation phase. Introduce progressively less-engaged subscriber segments as your reputation strengthens. Full graduation to target volume typically completes 45 to 75 days after your first send.

Playbook 5: Deliverability Audit

A deliverability audit is a comprehensive health check of your entire email operation. Unlike reactive playbooks that respond to crises, the audit playbook is proactive. It identifies vulnerabilities, inefficiencies, and emerging risks before they escalate into deliverability incidents. Every email program should undergo a full audit quarterly, with lightweight checks monthly.

The audit covers six domains, each with specific tools, benchmarks, and red flags.

Authentication records. Verify that SPF, DKIM, and DMARC are correctly configured for every domain and subdomain that sends email. Check SPF for the 10-lookup limit. Verify DKIM key lengths (2048-bit minimum) and that keys have been rotated in the last 12 months. Confirm DMARC is at enforcement level (p=quarantine or p=reject). Review DMARC aggregate reports for authentication failures that may indicate unauthorized senders using your domain.

Reputation scores. Pull domain reputation data from Google Postmaster Tools, Microsoft SNDS, and any third-party reputation monitoring tools. Compare current reputation against historical trends. Identify any domains or subdomains with reputation below High. For IP reputation, check sender scores and review the reputation of all active sending IPs.

List quality. Analyze your subscriber list for hygiene indicators: hard bounce rate over the last 90 days, percentage of addresses that have never engaged, age distribution of subscribers, and presence of known problematic patterns (role addresses, disposable email domains, high-frequency complainers). Run a sample through an email verification service to estimate the overall list validity rate.

Content analysis. Review your recent email templates for technical quality: valid HTML, proper character encoding, appropriate image-to-text ratio, functional unsubscribe links, and compliance with CAN-SPAM and GDPR requirements. Test rendering across major email clients. Check that all links resolve correctly and point to domains with healthy reputation.

Infrastructure review. Audit your sending infrastructure: dedicated vs shared IPs, IP warmup status, ESP configuration, bounce handling automation, feedback loop integration, and stream separation between transactional and marketing email. Verify that your ESP's infrastructure has not been flagged or degraded.

Engagement metrics. Analyze engagement trends over 30, 60, and 90-day windows. Look for declining open rates, rising unsubscribe rates, or increasing complaint rates. Segment engagement analysis by mailbox provider to identify provider-specific issues. Review your sunset policy to confirm that chronically unengaged subscribers are being suppressed.

The output of a deliverability audit should be a prioritized action list with three tiers: critical issues that require immediate remediation (authentication failures, blacklist listings, complaint rate violations), important issues that should be addressed within 30 days (reputation trending downward, list quality degradation, DKIM key rotation overdue), and optimization opportunities that improve performance over time (engagement segmentation refinement, content template improvements, infrastructure upgrades). Track audit findings and remediation progress across quarters to identify recurring patterns.

Playbook 6: Scaling Email Volume

Scaling email volume is a natural part of business growth. As your subscriber list grows, your product catalog expands, or your marketing strategy evolves to include more email touchpoints, your sending volume increases. The challenge is that mailbox providers treat sudden volume increases the same way they treat new senders: with suspicion. Scaling without a deliberate strategy triggers the same filtering responses as an unwanted spam operation ramping up volume.

When to scale. Volume scaling is appropriate when your business genuinely needs to reach more people or send more messages. Legitimate scaling triggers include subscriber list growth from organic acquisition, expansion into new markets or segments, introduction of new email programs (such as adding a newsletter to an existing transactional-only operation), or seasonal volume increases for industries like e-commerce. Scaling is not a substitute for poor engagement. If your current volume is underperforming, adding more volume amplifies the problem rather than solving it.

Infrastructure preparation. Before increasing volume, verify that your infrastructure can support the increase. If you are on shared IPs, confirm with your ESP that your volume increase will not exceed the shared pool's capacity or degrade its reputation. If you are on dedicated IPs, you may need to add additional IPs and warm them before scaling. Review your ESP's sending rate limits and confirm they accommodate your target volume. Ensure your bounce handling, feedback loop processing, and suppression list management can operate at the higher volume without delays.

Gradual volume increase strategy. The golden rule of scaling is to never increase volume by more than 30 to 40% week over week. If you are currently sending 50,000 emails per week and want to reach 200,000 per week, the ramp should take approximately 5 to 6 weeks. Week 1: 65,000. Week 2: 85,000. Week 3: 115,000. Week 4: 150,000. Week 5: 185,000. Week 6: 200,000. At each step, monitor bounce rates, complaint rates, inbox placement, and Google Postmaster reputation. Any negative movement requires holding steady or pulling back for a week before resuming growth.

Pro Tip from Boxset Team

Never increase sending volume by more than 40% in a single week, even if your metrics look healthy. Mailbox providers evaluate volume changes against your historical baseline. A sudden 2x or 3x increase — even from a sender with excellent reputation — triggers automated throttling and enhanced filtering. If you need to scale faster than the 30-40% weekly guideline for a legitimate business reason (such as a product launch or seasonal peak), contact your ESP's deliverability team in advance to coordinate the ramp and avoid unnecessary filtering.

Monitoring thresholds during scaling. During active scaling, tighten your monitoring thresholds beyond normal operating ranges. Your normal acceptable bounce rate might be 2%, but during scaling, flag anything above 1.5%. Your normal complaint rate threshold is 0.10%, but during scaling, flag anything above 0.06%. Tighter thresholds give you an early warning system that catches problems while they are still small and correctable. Scale-related deliverability damage that is caught within 48 hours can typically be reversed by reducing volume to the previous stable level. Damage that goes undetected for a week or more may require a full reputation recovery process.

Content considerations during scaling. If your volume increase comes from new subscriber segments or new email programs, the content going to these new recipients may differ from your historical content. Mailbox providers evaluate content patterns as part of their filtering. A sender that historically sends text-heavy newsletters and suddenly begins sending image-heavy promotional campaigns may trigger enhanced scrutiny even if the volume increase is gradual. Introduce new content types incrementally alongside the volume increase, not simultaneously.

How Boxset Automates Playbook Execution

The playbooks in this guide are designed to be executed manually by any competent email operations team. But manual execution has inherent limitations: it depends on someone noticing the problem, correctly diagnosing the root cause, and consistently following through on every step of the recovery process. Each of these stages introduces delay, human error, and organizational friction.

Boxset's Seltra AI automates the detection layer and provides intelligent guidance for the execution layer. Seltra continuously monitors your sending infrastructure across all connected ESPs, cross-referencing bounce rates, complaint rates, engagement metrics, authentication status, blacklist status, and mailbox provider reputation data. When any metric deviates from your established baseline, Seltra identifies the anomaly and classifies it against known incident patterns.

For example, if your Gmail inbox placement drops by 15 percentage points over 48 hours while your Outlook placement remains stable, Seltra recognizes this as a Gmail-specific reputation issue rather than a universal problem. It cross-references your Google Postmaster data, checks for recent SPF or DKIM changes, and scans for blacklist listings. Within minutes of detection, Seltra delivers a root cause assessment and a prioritized action plan drawn from the appropriate playbook, with steps customized to your specific situation.

This automated detection and classification capability transforms playbook execution from reactive to proactive. Instead of discovering a problem days after it began and scrambling to figure out what happened, your team receives an alert with a diagnosis and a step-by-step remediation plan while the issue is still in its early stages, when intervention is most effective and recovery is fastest.

Detect Issues Before They Become Crises

Boxset's Seltra AI monitors your deliverability across every ESP in real-time, automatically detecting anomalies and recommending the right playbook actions before reputation damage compounds.

Try Boxset Free

Seltra also provides ongoing monitoring during playbook execution. When you are in the middle of a spam folder recovery or an ESP migration, Seltra tracks your progress against expected recovery curves and alerts you if metrics are not improving at the expected rate. If your recovery is stalling, Seltra identifies why and recommends adjusted tactics, such as further reducing volume, tightening your engaged-only segment, or investigating a secondary root cause that the initial diagnosis may have missed.

Frequently Asked Questions

Discover Your Seltra Score

Get a single number that reflects the health of your entire email operation. Boxset's Seltra AI analyzes data from all your ESPs to calculate your real deliverability score.

Check Your Score Free

More in Industry Playbooks