Symptoms#
- Messages landing in spam despite previously good placement
- Bounces mentioning policy, authentication, or reputation
- Provider dashboards showing a drop in reputation or authentication pass rate
Diagnosis steps#
- Confirm the configuration is live: query DNS from an external resolver and check the sending platform's settings page.
- Send to a seed mailbox and read the full headers, especially Authentication-Results.
- Compare the domains in From, Return-Path, and DKIM d= for alignment.
- Check provider dashboards (Google Postmaster Tools, Microsoft SNDS) for reputation and error rates.
- Review recent changes: new vendors, DNS edits, list imports, volume spikes.
Likely causes#
- Treating 'mailbox full' as a hard bounce and losing valid contacts.
- Ignoring 'blocked by policy' bounces that signal a blocklist or DMARC failure.
Fix and re-verify#
- Parse DSN codes: 5.1.x means the address does not exist (hard); 4.x.x means temporary (soft).
- Suppress hard bounces after one failure and soft bounces after three.
- Route bounce notifications to a monitored mailbox or webhook.
- Review bounce reasons weekly for patterns like 'blocked' that indicate reputation issues.
Frequently asked questions#
What is the difference between a hard and soft bounce?
Hard bounces are permanent failures (bad address). Soft bounces are temporary (full mailbox, server down). Suppress hard immediately.