Email deliverability

Understand what is affecting your email delivery, and what to do next.

For sales teams whose prospecting or ordinary business email is being flagged as spam, in one region or several, and who need a proper assessment rather than fixes to individual messages. Read-only, evidence-led, and written for the people who have to act on it.

What is an email deliverability assessment?
An email deliverability assessment is a structured, read-only investigation into why an organisation’s email is being junked, quarantined or rejected. It examines the sending environment, authentication, mail flow, connected platforms, sending practices and the available message evidence, and it produces findings with evidence, a prioritised action plan and a written specification for the changes. A public DNS check is one input to an assessment, not a substitute for it.
The problem

Not every delivery problem is a cold-email problem.

Business email fails for many reasons. A marketing platform shares the SPF record with the sequencer and pushes it past the ten-lookup limit. A tool in the sending path breaks the DKIM signature. A rep trips the tenant’s outbound recipient limits and is restricted until the next day. Tracking links sit on a shared domain that a filter has already learned to distrust. Or a template simply reads like every phishing email the recipient’s gateway has seen this month.

Some of these problems are on the sending side and produce bounce reports. Others are on the receiving side and produce silence. From the sales floor the symptoms look the same. The evidence does not, and separating sender-side restriction from recipient-side filtering is the first job.

Who this is for

  • B2B sales teams from a handful of reps to a few hundred, in one region or several
  • Teams on Microsoft 365 or Google Workspace, sending from a sequencer, the CRM or the mailbox client
  • RevOps, Sales Ops and IT leaders who need one joined-up view rather than five partial ones
  • Agencies whose client has a delivery problem they would rather not diagnose alone
Scope

What we assess

Written so a technical buyer can check it against their own environment. Not every workstream applies to every engagement; the written scope says which do.

Environment map

  • Every domain, subdomain, mailbox and sending application, and which message types each carries: ordinary business email, individual sales conversations, automated sequences, marketing and transactional mail
  • Lookalike and legacy domains still in use, and who owns what
  • How each platform connects and sends: sending limits, throttling, tracking domain, open and click tracking, unsubscribe handling

Authentication by route

  • SPF, DKIM and DMARC checked on real messages for every sending route, not only on the DNS records
  • SPF lookup count against the ten-lookup limit, void lookups and permerror results
  • DMARC policy, alignment mode, subdomain policy, and whether aggregate reports are collected and read
  • DKIM selectors per platform, key sizes, and signatures that survive the sending path

Sending environment

  • Microsoft 365 and Exchange Online: outbound spam policies and recipient limits, restricted-sender events, connectors, mail flow rules, message trace and the tenant external recipient rate limit
  • Defender for Office 365 policy interactions where they affect outbound mail or replies
  • Google Workspace equivalents: per-user sending limits, SMTP relay settings and compliance rules
  • Whether the provider’s limits and terms suit the intended traffic at all

Sequencer, CRM and marketing platforms

  • Configuration, mailbox connections, sending schedules and ramp behaviour
  • Tracking domains, links, signatures, images, attachments and templates
  • Marketing and transactional platforms that share the same domain or SPF record

Message evidence

  • Original junked and delivered messages with full headers decoded: Authentication-Results and composite authentication, the categories, verdicts and direction Microsoft stamps in X-Forefront-Antispam-Report, and the bulk complaint level
  • Tabulated against sender, mailbox, sending route, template, recipient organisation and recipient environment, so like is compared with like
  • Bounce and non-delivery reports, distinguishing sender-side restrictions from recipient-side filtering

Cohorts, volumes and data

  • Volumes and patterns per mailbox, domain and region, including spikes and how new reps ramp
  • Recipient environments: Microsoft-hosted, Google-hosted and secure email gateways, and how each behaves
  • List sources, verification, bounce rates, suppression and CRM hygiene
  • Open and reply differences treated as prompts for investigation, not as proof of placement

Controlled testing

  • Seed mailboxes across Microsoft 365 with and without Defender, Google Workspace and consumer providers
  • Two rounds, one variable changed at a time, with a plain statement of what seed tests cannot tell you

People

  • Short interviews with sales, IT and RevOps to find where practice differs from the documented process
  • Who changes what, how the last change was made, and what nobody has written down
Method

Where the evidence comes from.

Each stage of the path leaves different traces. The assessment collects evidence from all three and compares it, instead of reasoning from one DNS record or one bounce.

1. Sending platform
  • Mailbox client
  • Sequencer or CRM
  • Marketing platform
  • Volume, cadence, ramp
2. Authentication
  • SPF, per sending route
  • DKIM signature intact?
  • DMARC alignment and policy
  • Reverse DNS, TLS
3. Recipient filtering
  • Domain and IP reputation
  • Content and link signals
  • Bulk and complaint history
  • Tenant policies, gateways
Inbox Accepted and placed where people read.
Junk Accepted, filed out of sight. Bounce reports say nothing.
Quarantine or rejected Held by policy, or refused with an NDR.
The path a business email takes. A problem at any stage produces the same symptom on the sales floor.Illustrative
Deliverables

What you receive

Everything is written for the people who have to act on it, with the evidence attached.

Environment map

Domains, mailboxes, applications, routes and message types in one document, with owners.

Findings with evidence

Each finding states what was observed, the evidence, and whether it is confirmed, plausible or still open.

Prioritised action plan

Ordered by impact and dependency, with responsibilities, what each change needs, and what it must not break.

Executive summary

A short account for leadership: what is wrong, what it is costing, and what to do first.

Technical handover

A written specification your administrators or MSP can implement under change control.

Findings workshop

A working session with sales, IT and RevOps to walk through the findings and agree the order of work.

Process

How an assessment runs

Typically three to five weeks, depending on the number of domains, routes and regions and how quickly evidence arrives.

  1. Scope and access

    We agree the domains, teams and regions in scope, the evidence needed, who provides it, and the access route: least-privilege and time-limited, guided sessions, or exports.

  2. Evidence collection

    Message samples, headers, reports, configuration exports, traces and interviews, gathered without changing anything.

  3. Analysis and testing

    Headers decoded and tabulated, authentication checked per route, cohorts compared, controlled placement tests run.

  4. Findings and plan

    The report, the prioritised plan and the specification, then the findings workshop with the people who will act on it.

  5. After the assessment

    Remediation and monitoring are separate, optional engagements. You can stop at the report.

Your side

What we need from you.

Affected domains and users, examples of junked and delivered messages with dates, platform reports, and an IT or platform owner we can work with. Where access is needed we prefer least-privilege, time-limited, read-only access. Guided sessions and exports you provide are good alternatives.

Client time is stated up front. As a guide, expect around a day of IT time in total across the engagement, half a day from sales operations, and forty-five minutes per interviewee.

Please never send passwords, credentials or raw customer emails through the website. We agree how evidence is shared before the work starts.

Read-only means read-only

  • No DNS, tenant, security or sequencer changes during the assessment
  • Nobody’s inbox is read; message samples are supplied by the people affected
  • Your IT team or MSP stays in the loop and in control
Next steps

After the assessment: remediation and monitoring.

Both are scoped separately. Neither is required to commission an assessment, and the report stands on its own.

Remediation and monitoring stages after a deliverability assessment
StageWhat happensWho does what
RemediationAuthentication and DNS changes, tenant policies and a restricted-sender runbook, sequencer configuration, tracking and link changes, delisting where justified, then a validation round.Your administrators implement to the written specification under change control with rollback planning, or we implement where you prefer and access allows.
MonitoringDMARC aggregate report review, blocklist checks, bounce data, periodic placement tests, configuration-change review, sending-health trends and recommendations.Neotiqa, on an agreed cadence. Not a round-the-clock service, and not a promised date by which delivery is fixed.
InfrastructureWhere cold outbound needs to move off the corporate domain, a dedicated and documented outreach setup.See outbound infrastructure.

Things an honest assessment says out loud

  • Authentication passing does not guarantee inbox placement.
  • An accepted message is not proof that it reached the inbox.
  • Seed tests are indicative, not a census of every recipient.
  • Open rates are not a reliable diagnostic on their own.
  • Microsoft 365 and Google Workspace are not built for bulk mail, and both providers say so. Volume has to respect their limits and terms.
  • Some findings will be plausible rather than confirmed. We say which, and what would confirm them.

Questions about deliverability assessments

Do we need to give you admin access to Microsoft 365?

Usually not. Read-only reporting roles, time-limited access or guided screen-share sessions with your administrator cover most workstreams, and exports of message trace, policies and DMARC reports cover the rest. Nothing is changed during the assessment, and Global Administrator is never required.

Can you tell why one rep’s email is junked when everyone else’s is fine?

Often, yes, but only by comparing like with like: the same recipient environment, route and template with a different sender. The evidence table is built for exactly that comparison. Sometimes the answer is a per-mailbox restriction or a signature. Sometimes it is the rep’s cadence.

The free checkers say our domain is fine. Why is mail still junked?

Public checkers look at DNS records and a few blocklists. They cannot see a DKIM signature broken in transit, a tracking domain with a poor history, a recipient tenant’s own policies, or the categories Microsoft stamps on each message. That is why the assessment works from real messages, not from records alone.

Does the assessment cover ordinary business email as well as prospecting?

Yes. Not every delivery problem is a cold-email problem. Invoices, proposals and support replies fail for the same underlying reasons, and the environment map covers every message type in scope.

How much does an assessment cost?

Each assessment is quoted after a short scoping conversation, based on the domains, routes, regions and teams involved. You receive a written scope and price before deciding, and there is no obligation to commission remediation afterwards.

Will you work with our existing IT provider?

Yes, and we prefer to. Your IT team or MSP knows the environment, owns the change control and will run whatever we specify. We share findings with them directly and write the specification for them.

What if the problem turns out to be the copy?

Then we say so. Templates and sequences are part of the assessment, and the plan points to messaging and cadence wherever the evidence leads there. We can help with that through sales coaching or managed outreach, but the assessment does not depend on selling either.

Last reviewed September 2026. Service descriptions are general; every engagement has a written scope.

Ready to find out what is actually happening?

Tell us which teams are affected, which platforms you send from and what you have noticed. We reply within two working days with the questions we need answered to scope an assessment.