A receiving mail service decides whether a message belongs in Inbox, Spam, or Junk. Authentication, sender reputation, message content, and the recipient's own rules can all affect that decision. A successful send or a verified domain does not guarantee inbox placement.
This guide mainly covers messages you send that land in someone else's spam folder. If legitimate incoming mail is going to Cedros Junk, use the correction steps near the end. If the message cannot be found anywhere, start with Why aren’t my emails arriving?.
Identify the affected messages
- Ask the recipient to confirm that the message is in Spam or Junk. Record the sender address, recipient provider, subject, approximate time, and any explanation shown by their mail service. A categorized inbox tab, a quarantine, and a delivery rejection are different outcomes.
- Identify how the message was sent: a Cedros-hosted mailbox, connected Google Workspace account, campaign, or site notification. Check the actual From address rather than relying on its display name.
- Determine the scope. Does it affect one recipient, one receiving provider, one template, or all recent messages? Compare a known successful message with an affected one.
- Send one short, ordinary test through the same sending path to an outside account you control. Use a distinct subject and no attachments. Check both Inbox and Spam; avoid repeatedly resending to customers while investigating.
- Inspect the received test's authentication results and compare them with the original affected message. Use the next section before making DNS changes.
| What you find | Best next check |
|---|---|
| SPF, DKIM, or DMARC fails | The actual sending service, signing domain, and DNS configuration |
| Authentication passes but several providers use Spam | Sender reputation, recipient expectations, message content, and recent sending changes |
| Only one recipient is affected | Their personal rules, blocked senders, and organization's filtering policy |
| Only a campaign or notification is affected | That workflow's sender, provider, template, and recipient list |
| A short test reaches Inbox but the normal message does not | Differences in links, attachments, formatting, and content |
| Cedros places incoming mail in Junk | The recorded spam reason, mail rules, and Not spam correction |
These comparisons help narrow the cause. One successful test does not establish that every recipient or message type will behave the same way.
Check authentication on the received message
Use a message received by the affected provider, preferably sent directly rather than forwarded through another account. Inspect the original message's headers or authentication summary. In Gmail on the web, open the message, select More beside Reply, then Show original. Google documents this in Trace an email with its full header.
Ask the administrator to check:
- SPF: Whether the sending server is authorized for the envelope sender domain, often shown through the Return-Path. This can differ from the visible From domain.
- DKIM: Whether the signature passes and which domain signed the message.
- DMARC: Whether a passing SPF or DKIM result aligns with the domain in the visible From address, under that domain's alignment policy.
An SPF pass for a provider's domain does not, on its own, establish DMARC alignment for your business address. Conversely, a message can pass DMARC through aligned DKIM even when SPF is not aligned. Forwarding can change these results, so compare a direct test before concluding that your original sender is misconfigured. See AWS's DMARC explanation.
Use the receiving service's own authentication results. A display name, a padlock, or an isolated “pass” elsewhere in the headers is not a complete assessment. Keep the original evidence when asking the administrator to investigate.
Verify the setup for the actual sender
Cedros-hosted mailbox mail uses the native mail service's Amazon SES connection. Open Settings → Site → Mail → Mail domain and review SES verified and the generated sending records. Use Recheck DNS to compare the current published values with the expected records. On a managed site, ask the responsible administrator to resolve unavailable provider controls.
Follow Understanding and verifying your email DNS records for SPF, generated DKIM records, the SES MAIL FROM domain, and DMARC. Publish records at the authoritative DNS provider for this domain. Keep one SPF policy per hostname and preserve authorizations for other legitimate senders; adding a second SPF record can create a new problem.
Connected Google Workspace mailbox mail uses the Google account's sending setup. Have the Workspace administrator check authentication for that domain and account. An SES verification badge in Cedros does not establish that a Google-sent message is authenticated. See Connecting your Google Workspace account for the connection's scope.
Campaigns and site notifications may use a separate configured sending path. Check that workflow's sender and provider rather than assuming a successful inbox reply verifies all site email. Setting up outgoing email delivery explains the distinction.
After any correction, send a fresh message and inspect its received authentication results. DNS verification alone does not show how an already-sent message was signed. Do not replace incoming MX records to fix outgoing spam placement, and do not weaken DMARC merely to make a failing sender appear acceptable. Review all legitimate senders before changing enforcement.
If the provider rejects sending entirely, use Why can I receive email but not send it?. SES sandbox restrictions, account pauses, and a message accepted into Spam are different problems.
Review reputation, recipients, and feedback
If authentication passes, review who receives the messages and whether they expect them. For subscription mail, use confirmed signups, keep a record of the intended subscription, and stop sending to people who no longer want it. Use a recognizable business identity and a monitored reply address. AWS's sender-reputation guidance covers identity, authentication, and list maintenance.
Treat hard bounces and complaints as reasons to investigate and stop inappropriate retries. A complaint means a recipient reported the message as unwanted; automatically placing a message in Spam is not necessarily a recorded complaint. Do not clear suppressions just to make a campaign send again. Read the underlying reason and resolve it with the administrator. See Amazon SES delivery and complaint guidance.
In Cedros, administrators with access can open Observability → Delivery Health and select Recheck. Review Provider feedback, Hard bounce rate, Complaint rate, and Suppressions. Where shown, Configuration details includes domain-authentication information, and Email provider reports can provide additional authentication evidence.
Read each report's period and coverage. Missing provider feedback, a stale report, or a small sample is not proof of a clean sending history. These indicators are not a measurement of every recipient's Inbox-versus-Spam decision and may not cover every sending path, especially a separate Google connection. Check the relevant provider's reports too.
For mail to personal Gmail accounts, review Google's sender guidelines. They distinguish all-sender requirements from additional bulk-sender requirements. These include authentication, aligned sending, secure transport, low spam rates, and one-click unsubscribe for applicable marketing or subscribed mail. A visible unsubscribe link alone does not establish that the required one-click mechanism is working.
Increase legitimate sending volume gradually, monitor results, and address a worsening trend before expanding a campaign. Changing sender addresses or providers to work around filtering leaves the original cause unresolved. A purchased list, repeated unwanted mail, or a sudden burst can undermine otherwise correct authentication.
Compare the message content
Compare the message that went to Spam with your short test. Look for a misleading sender name or subject, unfamiliar link destinations, broken URLs, oversized attachments, or a template that obscures the message's purpose. Check the actual destination of a link as well as the visible text.
Use a clear subject, recognizable identity, readable body, and only the links or attachments needed for the message. Keep promotional content separate from essential account or order messages. Do not disguise a new message as a reply by adding a false “Re:” or imply that the recipient requested something they did not request. Google's sender guidelines explain its expectations for accurate message formatting and sending practices.
Change one relevant element at a time, then test through the same workflow. A plain inbox message and a campaign preview can use different senders or formatting; compare like with like. There is no single word to remove or formatting trick that guarantees inbox placement.
If only one organization's recipients are affected, ask their mail administrator to review the message and filtering reason. They may have a local policy, blocked-sender entry, or quarantine rule. A recipient can mark a message they recognize and want as not spam, but that correction is not a global approval of your domain.
If legitimate incoming mail goes to Cedros Junk
- Open Email → Inbox, select the relevant mailbox, and use More → Junk if Junk is not already visible.
- Open the message and read any spam explanation. It may identify Cedros spam protection, Gmail's classification, a blocked-sender rule, an inbox rule, or a previous manual report. Older messages may have no detailed classification history.
- Confirm that the message is legitimate before opening links or attachments. Check the full sender address and any authentication or reply-address warning; a familiar display name is not enough.
- Open the message's ⋯ actions and select Not spam. If the action is unavailable, ask someone with permission to change that mailbox's messages.
- Check that the correction succeeded and locate the message in its resulting folder. For Cedros-hosted mail, the correction is also submitted for spam-learning feedback. Submission does not promise immediate learning or future delivery to Inbox.
If messages from the same legitimate sender keep returning to Junk, review Email → Inbox → Settings → Your mail rules. Ask the administrator to check Settings → Site → Mail → Rules for every address too. Look for the specific matching Send to Junk rule before changing anything broadly.
A Never send to Junk sender rule is not a blanket security bypass. Cedros's native receiving path requires verified sender authentication before such an allow rule overrides spam scoring, and malware rejection is not bypassed. Have the administrator check authentication and conflicting rules when an allow rule does not have the expected effect. Follow Blocking or allowing a sender for exact-address and domain rules, mailbox scope, and conflict priority.
For a Google-hosted message, also check Gmail directly. Cedros can preserve Gmail's spam classification, and changing a local view is not proof that Google accepted a correction. If mailbox states remain inconsistent, use Reconnecting Google Workspace when syncing stops to check connection and write-access status before reconnecting.
Under Settings → Site → Mail → Mail service, administrators can review Spam protection, Corrections, learning warnings, and Junk retention where available. Review wanted messages before the retention period expires. Correct the identified rule, authentication, or feedback problem rather than disabling protection for the whole site.
Verify improvement and get help
Repeat a small test using the same sender and workflow that had the problem. Check the message's folder and authentication results at the affected provider, then compare with another provider if you have an account there. Test a representative normal message as well as the simplified one. Record the result and monitor subsequent legitimate mail; reputation changes may take time and no fixed recovery period is guaranteed.
If you need help investigating delivery, provide:
- The sending address, workflow, and provider, plus the affected receiving provider.
- A test subject, send time with time zone, and message identifier if available.
- Whether one recipient, one template, or a wider set of messages is affected.
- The receiving service's spam explanation and relevant authentication results.
- Recent DNS, provider, template, list, or sending-volume changes and the outcome of a comparison test.
Share message headers or diagnostic details through the support channel requested by the administrator, with unrelated private information removed. Do not post complete customer messages, app passwords, or provider credentials publicly.