IP Reputation Filtering: How It Works and How to Fix It

Learn how IP reputation filtering shapes inbox placement, the signals mailbox providers weigh, and the exact steps to recover and protect your sender

•

Published on

•

IP Reputation Filtering: How It Works and How to Fix It
Do not index
Do not index
A Monday campaign report shows opens collapsing from 28% to 7% overnight. Nothing changed in the template, tracking code, or subject line, so the team blames the dashboard. Seed-list tests then show the same message reaching spam at Gmail and Outlook. The investigation eventually finds the actual problem: a third-party onboarding tool has started sending from the same IP pool, and that pool's reputation has dropped.
This is why IP reputation filtering can't be treated as a static score or a one-time setup. Mailbox providers reassess sender behavior on every delivery attempt, combining IP history with complaints, bounces, authentication, blocklists, domain signals, and the activity of other senders on shared infrastructure. A reputation problem can reduce inbox placement, conversions, and brand trust before a campaign report makes the cause obvious.
Table of Contents

When Opening Realizes Stops Working and a Hidden Draft

At 9:00 on Monday morning, a SaaS marketing lead sees a campaign's reported 28% open rate fall to 7%. No deployment, content edit, or tracking change occurred after the previous send. The team checks the analytics dashboard, refreshes the report, and compares the message with the last approved version.
The dashboard is working. A controlled seed-list test shows delivery reaching some inboxes while many messages go to spam. Transactional traffic from a separate stream remains normal. That narrows the incident to a sending path rather than a broad domain problem.

The diagnostic path matters

Start with the sending IP, recent volume, bounce activity, authentication results, and blocklist status. In this case, the decisive clue is a sharp reputation decline after an onboarding vendor begins sending heavily through the same shared pool. The SaaS company's own list quality has not suddenly changed. It has inherited risk from a neighboring sender.
Mailbox providers treat IP reputation as an operational input, not a permanent label. Their postmaster tools can expose reputation bands alongside spam rates, authentication results, and delivery errors. Bulk-sending guidance also identifies 0.10% spam complaints as a healthy target and 0.30% as the complaint ceiling, making 3 complaints per 1,000 emails enough to push a sender toward enforcement territory. The relationship between sender behavior and inbox placement is outlined in this overview of sender reputation and inbox placement.
The incident also reveals why IP reputation is not a single dial. Providers re-evaluate a composite signal on every send, combining complaint behavior, blocklist exposure, authentication, traffic patterns, and the conduct of other senders on shared infrastructure. A clean history can deteriorate quickly when one of those inputs changes.
That makes remediation more precise. Identify which signal moved, isolate the affected stream or IP, and verify placement after each traffic adjustment. Changing subject lines while leaving a damaged sending path untouched rarely improves delivery.

What IP Reputation Filtering Actually Is

A campaign can be technically valid and still face throttling or spam placement because the sending IP has lost trust. IP reputation filtering evaluates whether that address has earned enough confidence for a receiving system to accept, inspect, throttle, or reject a message. Mailbox providers maintain an ongoing record of traffic from the IP and how recipients and security systems respond.
IP reputation is a composite signal, not a single dial. Mailbox gateways typically combine complaint behavior, sending volume and consistency, public blocklists, open-proxy indicators, authentication results, and related abuse signals. They then apply internal thresholds to allow delivery, increase scrutiny, delay traffic, or block it. Those thresholds can change between providers and can be re-evaluated with each send.
notion image

Filtering is layered

The IP is only one input in the delivery decision. A receiving system may also assess:
  • Envelope sender reputation, covering the return-path identity used for bounces and delivery handling.
  • Authenticated domain identity, including whether SPF, DKIM, and DMARC align with the visible sender.
  • Message and recipient signals, such as complaints, invalid addresses, and engagement patterns.
  • External intelligence, including DNS-based blocklists and abuse indicators.
DNS-based blocklists let receivers check listed IPs or domains during message processing. Their records can identify infrastructure associated with spam, automated abuse, or compromised hosting. A listing does not explain the entire delivery problem, but it can raise scrutiny or trigger a policy response.
The practical distinction matters for anyone studying about email marketing. Strong campaign content cannot compensate for an IP that repeatedly sends unwanted traffic. A clean IP also cannot rescue a domain with broken authentication or persistent complaints.
IP reputation filtering is an early decision layer. Trusted traffic may receive less scrutiny, while unfamiliar or low-trust traffic faces additional checks before the gateway decides how to handle it. Recovery therefore requires identifying the signal that changed and correcting the sending path, not just rewriting campaign copy.

The Signals Mailbox Providers Feed Into IP Reputation

An IP reputation incident rarely comes from one bad metric. Mailbox providers recalculate treatment on each send using a composite of complaint behavior, bounce patterns, volume changes, authentication, blocklist presence, shared-IP neighbors, and recipient engagement. Their formulas are private, and the same IP can receive different treatment across major consumer and corporate mailbox providers. Diagnose the signal that changed before replacing infrastructure.

Complaint behavior carries immediate risk

Spam complaints often produce the fastest deterioration. Industry guidance uses 0.10% as a healthy target and 0.30% as a ceiling. At that ceiling, 3 complaints per 1,000 emails can move a sender toward enforcement, so review complaints by sending stream and recipient segment rather than relying only on an account-wide average.
Hard bounces and unknown users indicate that the sender is targeting addresses that cannot receive mail. Abrupt volume increases make an IP look unlike its established pattern. Role accounts, stale recipients, and low-intent segments can also produce weak engagement or complaints. These signals reinforce one another: a volume spike paired with poor list hygiene gives a receiving system stronger evidence that the traffic is unsafe.
Authentication helps providers connect the message to an authorized sender. SPF identifies permitted infrastructure, DKIM protects message integrity, and DMARC relates those results to the visible From domain. Review alignment and reporting with this email authentication guide.

Reputation also comes from outside the mailbox

Public blocklist appearances can prompt investigation or direct filtering. Shared infrastructure adds inherited risk because another tenant's complaints, abuse, or sudden volume can affect the IP used by careful senders. Check whether the sending IP appears on relevant spam databases, then compare the timing with traffic changes and complaint activity. Reputation is an operational deliverability control, not a branding metric.
Signal
Typical Weight
Healthy Threshold / Target
Spam complaints
High and immediate
0.10% target, 0.30% ceiling
Hard bounces and unknown users
High
Keep invalid-recipient activity low and suppress failures promptly
Sending volume
High when patterns change
Maintain a consistent cadence and avoid abrupt spikes
SPF, DKIM, and DMARC alignment
Foundational
Authenticate every relevant sending stream and investigate failures
Public blocklists
Potentially decisive
No active listing on monitored lists
Shared-IP neighbor behavior
Variable but material
Use a managed pool and isolate problematic streams
Recipient engagement
Context-dependent
Segment inactive recipients and protect high-intent traffic
Treat the table as a control framework, not a universal scoring formula. Providers reweight signals according to recipient history and trend direction. A stable complaint rate may still require attention if it is rising, while a single blocklist event may warrant immediate investigation. Monitor both the current value and the direction of change. Complementary Outlook sender support guidance can help with sender-side checks.

IP Reputation vs Domain Reputation and Why It Matters

IP reputation reflects the sending infrastructure. Domain reputation reflects the identity recipients see and mailbox providers associate with the brand. Treating them as one score leads teams to rotate infrastructure while leaving the underlying sender identity unchanged.
IP reputation can fall quickly after a volume spike, complaint event, or shared-pool incident. Replacing the IP may remove some infrastructure history, but it does not erase domain-level complaints, authentication failures, or recipient distrust. Domain reputation follows the brand across sending systems and usually improves only through sustained corrective behavior.
Dimension
IP Reputation
Domain Reputation
Scope
Sending infrastructure
Brand and authenticated identity
Main inputs
IP history, volume, complaints, blocklists, neighbors
Domain complaints, authentication, engagement, identity consistency
Change pattern
Can shift rapidly after operational events
Usually changes more gradually
Rotation effect
A new IP may have different infrastructure history
The domain identity remains connected to the brand
Main risk
Shared pools, cold infrastructure, abrupt volume
Persistent complaints, weak authentication, poor recipient expectations
Best diagnostic question
What traffic is leaving this IP?
What does this domain consistently send and represent?

Repair both layers in the right order

A sender with a damaged IP and a healthy domain should isolate the affected stream, stop harmful traffic, and verify authentication before considering a new IP. A sender with a damaged domain will not recover just by moving to dedicated infrastructure.
Major mailbox providers evaluate IP, URL, domain, sender, and ASN reputation alongside authentication and complaint signals. Bulk-sender requirements for high-volume senders typically include SPF, DKIM, DMARC, one-click unsubscribe, and complaint controls. Some requirements apply to senders operating at 5,000 or more messages per day. The authentication and sender controls are summarized in this Gmail and Yahoo sender requirements guide.
The practical distinction is simple: IP reputation describes how a sending route behaves, while domain reputation describes the trust attached to the sender identity. Mailbox providers reassess both on every send, so changing one layer cannot conceal persistent problems in the other.

How to Build and Repair IP Reputation Step by Step

Recovery starts with containment. Continuing to send the same traffic while investigating gives mailbox providers more negative evidence and makes the eventual recovery harder.

1. Verify authentication alignment before sending

Check SPF authorization, DKIM signing, and DMARC alignment for every marketing, transactional, and outbound stream. A message can pass one authentication test while failing alignment with the visible From domain, so the review must inspect the actual headers and DMARC reports.
A simplified header excerpt might look like this:
Authentication-Results: receiver.example;
 spf=pass smtp.mailfrom=mailer.example;
 dkim=pass header.d=example.com;
 dmarc=pass header.from=example.com
A failure requires investigation, not blind record changes:
Authentication-Results: receiver.example;
 spf=fail smtp.mailfrom=unapproved.example;
 dkim=none;
 dmarc=fail header.from=example.com
Authentication matters because it helps mailbox providers connect the message to a legitimate domain. If ignored, spoofing risk and inconsistent identity signals can push legitimate mail into spam and undermine trust in every sending stream.

2. Clean the list before the next send

Suppress hard bounces, unknown users, known complainers, role addresses that aren't appropriate for the campaign, and recipients who have stopped engaging. Third-party or unverified lists shouldn't be used as a shortcut to volume.
This step protects the IP from fresh complaints and invalid-recipient events. It also protects revenue by keeping high-intent recipients in a cleaner stream instead of forcing valuable messages through the same reputation path as questionable addresses.

3. Ramp volume gradually

A new or recovering IP needs a predictable sending pattern. A typical warmup lasts 2 to 6 weeks, and senders should increase volume only when complaint activity remains below the 0.10% healthy target. Exact pacing depends on the stream, recipient mix, and prior history, so a fixed calendar is less reliable than a threshold-based ramp.
The email warmup guide can help teams distinguish gradual volume control from just sending more messages and hoping reputation catches up.

4. Keep cadence and preference controls stable

Send on a consistent schedule, make unsubscribe options easy to find, and implement one-click unsubscribe where required. If recipients can't control message frequency, they're more likely to complain rather than disengage safely.
Volume control matters because mailbox providers compare current behavior with historical patterns. A sudden burst can trigger throttling or spam placement even when the underlying content is legitimate.

5. Choose shared or dedicated infrastructure deliberately

Shared IPs can work for lower-volume senders when the pool is well managed and traffic remains predictable. Dedicated infrastructure becomes more appropriate when a sender needs stable scoring, separates transactional and marketing traffic, and can sustain consistent volume without creating its own reputation shock.
A dedicated IP doesn't fix poor list hygiene or broken authentication. It only gives the sender more control over the reputation attached to that infrastructure.

Shared IP Inherited Risk and Common Mistakes to Avoid

A shared IP pool behaves like a neighborhood. One tenant's aggressive volume, unwanted mail, or abuse complaints can affect other tenants before each sender understands what changed. Independent deliverability guidance notes that shared-IP senders can inherit reputation problems from other tenants, which means a sudden inbox-placement decline may not originate in the affected sender's own content or list.

Use this diagnostic checklist

  • Unverified lists: Acquired or poorly sourced addresses create unknown users, bounces, and complaints. Suppress questionable records and use permission-based acquisition.
  • Post-pause volume bursts: Sending a full campaign after a long pause creates an abrupt pattern change. Resume gradually and watch complaint signals.
  • Bounce rates above 2%: A bounce rate above 2% indicates a list-quality problem and should trigger suppression and investigation. The threshold is part of MailAdept's stated operating benchmarks.
  • IP rotation: Moving between IPs without fixing authentication or recipient targeting spreads the problem. Identify the failing stream first.
  • Seed-list overconfidence: Seed testing shows placement for controlled accounts, not every recipient. Use it alongside provider-level metrics, complaint data, and blocklist checks.
  • Missing feedback loops: Without complaint feedback, teams learn about abuse after reputation has already declined. Register available feedback loops and assign an owner.
The cost isn't limited to a spam-folder placement. Missed product notices can reduce activation, promotional messages can lose conversions, and repeated filtering teaches recipients to distrust the brand. Teams should separate transactional, marketing, and outbound streams so one risky audience doesn't contaminate messages with direct revenue or operational importance.
notion image

Monitoring and Measuring IP Reputation in Production

Production monitoring needs named owners, defined thresholds, and a response window. A dashboard that only records failure does not protect revenue. Assign each signal to someone who can investigate and act.

Build a tiered review routine

Review postmaster tools daily for IP reputation, spam-rate, authentication, and delivery-error signals. Review secondary mailbox provider sender data weekly, check monitored blocklists daily, and run controlled seed-account placement tests monthly across major mailbox providers.
Track four operational indicators:
  1. Spam complaints per 10,000 messages, translated into an internal alert based on the sender's healthy target and enforcement ceiling.
  1. Unknown-user rate, segmented by list source and sending stream.
  1. Blocklist appearances, recorded by IP and provider.
  1. Inbox placement, measured against a consistent controlled seed list.
Use the sender's baseline and each provider's requirements to set alert values. An assigned owner should investigate deterioration within 24 hours, before another campaign adds volume to the problem.
Metric
Healthy Threshold
Review Cadence
Primary Source
Spam-complaint rate
At or below the healthy target
Daily and after major sends
Postmaster reporting and feedback loops
Unknown-user activity
Low and declining
Daily
SMTP results and campaign logs
Blocklist status
No active listing
Daily
Monitored DNS-based blocklists
Inbox placement
Stable against the sender baseline
Monthly and after incidents
Controlled seed testing
Authentication results
Consistent pass and alignment
Daily during remediation
Headers and DMARC reporting
Baseline each IP, then segment trends by sending stream. Aggregate results can conceal deterioration from one sender inside a shared pool. Review complaint, bounce, placement, and authentication changes at the stream level, and record the investigation, decision, and recovery result. This history shows whether a fix worked or merely shifted the problem to another IP or audience.

Putting It All Together and When to Call for Help

Healthy sending programs keep complaints below the 0.10% target, maintain aligned SPF, DKIM, and DMARC, and investigate blocklist listings immediately. No single metric proves inbox placement, so simultaneous deterioration across complaints, authentication, blocklists, and seed testing deserves escalation rather than another content rewrite.
The first response should be controlled: pause the affected stream, preserve logs, isolate shared-IP exposure, validate authentication, suppress risky recipients, and resume only with a measured volume plan. Continuing to send through a degraded pool can reduce conversions and prolong brand distrust.
MailAdept combines AI agents with human deliverability experts through a subscription model, with monitoring, authentication review, and hands-on remediation for teams dealing with reputation incidents. It operates as a Mailwarm company and is backed by Y Combinator, S20. Teams can also use a focused reputation check to identify whether a sending IP appears on monitored blacklists, but automated checks won't explain every domain, list, or shared-pool interaction.
MailAdept can investigate the IP, domain, authentication, complaint, and shared-infrastructure signals behind a filtering problem, then turn the findings into a controlled recovery plan. Visit MailAdept to request a free deliverability audit before the next campaign turns a reputation warning into lost revenue.

Fix Your Email Deliverability Before It Costs You Revenue

Get expert insights on why your emails go to spam and how to consistently reach the inbox.

Get a Free Deliverability Audit
Thami Benjelloun

CEO Mailwarm, email deliverability expert.