· 7 min read
Maritime B2B E-mail Deliverability: SPF, DKIM and DMARC
Why do introduction e-mails land in spam? SPF, DKIM and DMARC in plain words, the Gmail, Yahoo and Microsoft sender rules, warm-up, bounces and list hygiene.
- E-mail deliverability
- E-mail authentication
- B2B e-mail
In short
To reach the inbox, maritime B2B introduction e-mails need a domain authenticated with SPF, DKIM and DMARC, a sending volume that grows gradually, prompt removal of bounced and complaining addresses, and one-click unsubscribe in every message. Gmail, Yahoo and Microsoft now enforce authentication rules for bulk senders to their personal mailboxes.
Whether your introduction e-mail reaches the inbox depends on three things: a domain authenticated with SPF, DKIM and DMARC, a sending volume that grows gradually, and a clean list of addresses. This guide explains these terms without the jargon, summarizes the rules from Gmail, Yahoo and Microsoft, and shows how VesselCall handles each of them.
What is deliverability, and why does it matter in shipping?
Deliverability is the ability of your e-mail to reach the recipient’s inbox instead of the spam folder or a rejection. In shipping, first contact has a time window: if the offer you send while a vessel approaches sits in spam, the opportunity for that port call is usually gone. Corporate mail services check incoming mail too; Microsoft 365, for example, looks at SPF, DKIM and DMARC results when it evaluates inbound messages.
What are SPF, DKIM and DMARC?
| Record | What it does, in plain words | Standard |
|---|---|---|
| SPF | Lists in DNS the servers allowed to send mail for your domain. The receiving server checks whether the message came from one of them. | RFC 7208 |
| DKIM | Adds a digital signature tied to your domain to each message. The public key sits in DNS, so the receiver can confirm the message came from your domain and was not altered in transit. | RFC 6376 |
| DMARC | Requires the SPF or DKIM result to match the visible “From” domain, which is called alignment. It tells receivers your policy for messages that fail (none, quarantine or reject) and where to send reports. | RFC 9989 |
The current DMARC specification is RFC 9989, published in May 2026, which replaced RFC 7489 from 2015. Records still start with v=DMARC1. A simple starting record looks like this:
_dmarc.yourcompany.com TXT "v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.com"
Starting with p=none lets you collect reports without affecting delivery. Once the reports show that all of your mail passes, you can move to quarantine or reject.
What rules did Gmail, Yahoo and Microsoft introduce?
The three largest consumer mailbox providers now require authentication from high-volume senders:
| Provider | In force since | Who is covered | Key requirements |
|---|---|---|---|
| Gmail | February 2024 | Senders of about 5,000 or more messages within 24 hours to personal Gmail accounts | SPF and DKIM, DMARC (at least p=none), From domain alignment, one-click unsubscribe for marketing messages, spam rate below 0.3% |
| Yahoo | February 2024 | Bulk senders | SPF and DKIM, DMARC (at least p=none) with alignment, one-click unsubscribe, opt-outs honored within 2 days, spam rate below 0.3% |
| Microsoft (Outlook.com, Hotmail, Live) | May 5, 2025 | Domains sending 5,000 or more messages a day | SPF and DKIM must pass; DMARC at least p=none, aligned with SPF or DKIM |
A few details matter:
- Gmail counts messages per primary domain, and a sender that crosses the threshold once is treated as a bulk sender permanently. Since November 2025, Gmail has been stepping up enforcement against non-compliant traffic.
- Microsoft rejects non-compliant mail with the error
550 5.7.515 Access denied. - Baseline rules apply to all senders: SPF or DKIM, valid forward and reverse DNS (PTR) records for sending IPs, messages formatted to RFC 5322 and, at Gmail, TLS for transmission.
These rules are written for personal mailboxes, and you will usually reach ship managers at company addresses. Corporate filters look at the same signals, though, so treat the bulk sender rules as your baseline whatever your volume.
Why send from your own domain?
An introduction e-mail sent from a free address (such as @gmail.com) or from someone else’s domain creates two problems. The first is trust: a purchasing manager judges from the domain whether the sender is a real company. The second is authentication: DMARC requires the visible From domain to align with SPF or DKIM, and only the owner of a domain can publish the DNS records that make that possible.
Replies also come straight to your inbox, and the conversation stays in your own systems. Some companies send outreach from a subdomain (for example mail.yourcompany.com) to keep its reputation separate from day-to-day correspondence on the main domain.
How do you warm up a domain?
A sudden burst of e-mail from a new domain, or from one that has been quiet for a long time, looks suspicious to mailbox providers. Google’s sender guidelines advise starting with a low volume, increasing it slowly over time and avoiding sudden spikes, and they recommend monitoring delivery in Postmaster Tools along the way. In practice:
- Keep daily volume low in the first weeks, then raise it step by step.
- Send similar volumes at similar times each day.
- If bounces or complaints rise, stop increasing volume until you find the cause.
How should you handle bounces and complaints?
A bounce is an e-mail that cannot be delivered and returns to the sender. There are two kinds:
- Hard bounce: The address does not exist or the domain does not accept mail. Never send to it again.
- Soft bounce: A temporary problem such as a full mailbox or a busy server. If it keeps happening, remove the address; Google also recommends automatically unsubscribing recipients whose messages bounce repeatedly.
A complaint is a recipient marking your e-mail as spam. Gmail asks senders to keep the spam rate reported in Postmaster Tools below 0.1% and never let it reach 0.3%. Never writing again to someone who complained is the first step to keeping that rate low.
For unsubscribes, RFC 8058 defines how the “unsubscribe” button in a mail app works in one click: the message carries List-Unsubscribe and List-Unsubscribe-Post headers, and the DKIM signature must cover both. Yahoo requires bulk senders to honor opt-outs within 2 days, Google recommends 48 hours, and in Türkiye, Law No. 6563 sets a limit of three business days.
Which addresses should you not e-mail?
- Purchased lists: Spamhaus warns that bought lists expose senders to spam traps.
- Old addresses: Mailbox providers can turn closed addresses into spam traps after a period of rejecting mail.
- Unverified addresses: If a domain has no MX record, it cannot receive mail. Check before you send.
- Every address at one company: Pick one primary address per company, in the right department.
- Opted-out addresses: Someone who opted out of one campaign should not hear from you in another.
How VesselCall handles deliverability
VesselCall Outreach builds these rules into its sending infrastructure:
- DKIM on your domain: E-mails are signed with your own domain. You add one DKIM record to your DNS; your SPF record does not need to change, because DMARC alignment comes from the DKIM signature. If you have no DMARC record, VesselCall flags it and suggests one.
- Rate limits and automatic warm-up: Sending is spread out with per-minute and daily limits, and the daily limit for a newly verified domain increases gradually.
- Bounce and complaint processing: Every bounce is matched to the exact e-mail that caused it. An address that hard-bounces is marked invalid and not used again, and an address that complains is removed from your sending.
- One-click unsubscribe (RFC 8058): Every e-mail carries the
List-UnsubscribeandList-Unsubscribe-Postheaders plus a visible opt-out link, and opt-outs take effect immediately. - Address verification: Addresses are checked against the domain’s MX record, and one primary address is chosen per company.
- Frequency limits: No second e-mail goes to the same vessel within 7 days, a vessel receives at most 3 e-mails in 90 days and a company at most 1 in 3 days.
All of this runs on VesselCall’s own sending infrastructure, so you do not have to configure a mail server. To see the full flow, visit How it works, and for wording ideas, see our introduction e-mail templates.