The complaint always arrives the same way: open rates were fine, then over a few sends they halved. Nothing changed in the emails, so the assumption is HubSpot broke something. It almost never did.
Mailbox providers score the sending domain, not the platform. HubSpot's shared and dedicated infrastructure is well maintained; what fails is authentication, list quality, sending patterns and the signals in your own content. Those are all yours to fix.
This is the diagnostic order we use. Work top to bottom — rewriting subject lines while your DMARC record is missing is wasted effort. If you want it handled end to end, that sits inside HubSpot CRM setup and automation.
Step 1: Prove your authentication is complete, not just present
Connect your sending domain in HubSpot and verify all three records resolve publicly: SPF, DKIM signed by the sending domain, and a DMARC policy. Google and Yahoo have required authentication for bulk senders since 2024, and 'configured a while ago' is not the same as 'currently resolving'.
The most common failure we find is a DMARC record left at p=none forever, or an SPF record that has silently exceeded its DNS lookup limit after a few tool additions. Both look fine in a dashboard and fail at the mailbox.
Send from a subdomain you control for marketing (for example news.yourdomain.com) so campaign reputation is separated from the domain your sales team and invoices use. If marketing sending ever goes wrong, your transactional and one-to-one email survives it.
| Record | Purpose | Typical failure |
|---|---|---|
| SPF | Lists servers allowed to send for the domain | More than 10 DNS lookups — silently invalid |
| DKIM | Cryptographically signs each message | Connected in HubSpot but DNS record never published |
| DMARC | Tells providers what to do with failures, and reports | Stuck at p=none with no reporting address monitored |
| Sending subdomain | Isolates marketing reputation | Bulk sending from the root domain used for invoices |
| Return-path alignment | Keeps bounce handling on your domain | Left on HubSpot default after domain connection |
Step 2: Look at reputation before you look at the email
Check Google Postmaster Tools and Microsoft SNDS for your sending domain. If domain reputation is 'low' or spam complaint rate is above roughly 0.3%, no amount of copy editing will get you back into the inbox this week.
Complaint rate is the single strongest signal you control. It rises when people receive mail they do not remember requesting — bought lists, event scans, imports from a previous tool, or a form that quietly subscribed everyone who downloaded a PDF.
Reputation recovers slowly and predictably: send only to people who opened in the last 90 days for three to four weeks, keep volume steady, then widen again. It is boring and it works.
Step 3: Cut the list before you defend it
Suppress hard bounces immediately and permanently. Then build a graduated re-engagement list: 180 days without an open, 365 days without any engagement, and never-opened contacts who have received more than five sends.
Give the disengaged one honest re-permission email, then stop mailing them. Continuing to send to people who never open is how you teach filters that your mail is ignorable.
Removing dead contacts also usually drops a marketing contact tier, which is the rare hygiene job that pays for itself — the mechanics are in the HubSpot pricing breakdown, and the wider process in the CRM data cleanup guide.
Step 4: Fix the sending pattern, not just the send
Spikes look like compromise. Going from 2,000 emails a month to 40,000 in one afternoon after connecting a new domain is the classic way to get throttled on day one. Warm a new sending domain over two to three weeks, starting with your most engaged contacts.
Keep a predictable rhythm. A steady weekly send to an engaged segment builds far more reputation than a monthly blast to everyone, even at identical total volume.
Separate transactional mail from marketing mail. Order confirmations and form notifications should never sit behind the same reputation as a promotional campaign — and on a HubSpot site that means checking what your forms and workflows send, not just what marketing schedules.
Step 5: Then, and only then, look at the content
Content signals matter at the margin. Keep a real plain-text alternative, keep the image-to-text ratio sane, avoid link shorteners, and use link domains that match your sending domain wherever possible.
Do not hide the unsubscribe link. Making it hard to leave converts unsubscribes into spam complaints, and one complaint costs you roughly as much as several hundred quiet unsubscribes gain you.
Use a person's name in the from field where the relationship is one-to-one, and a brand name for genuine broadcasts. Mismatch between from name, subject and content is a pattern filters have been trained on for years.
Step 6: Instrument it so you see the next decline early
Set a DMARC reporting address and actually read the aggregate reports — they show you every service sending as your domain, including the ones nobody remembers authorising.
Build a HubSpot dashboard with delivery rate, bounce rate, complaint rate and open rate by segment, reviewed monthly. Deliverability decays gradually; you want to catch a 4% drift, not a 50% collapse.
Add seed-inbox testing before large sends, and check rendering in the three clients your audience actually uses. Most of this is routine, which is exactly why it belongs in ongoing HubSpot support.
What we do first on a portal that has already been filtered
Freeze the broad sends. Every additional low-engagement campaign digs the hole deeper, and the temptation to 'test whether it recovered' is what keeps portals stuck for months.
Republish and verify DNS from scratch rather than trusting the existing setup, connect a clean sending subdomain, and rebuild the engaged segment from the last 90 days of activity.
Then send small, consistent and genuinely useful mail for a month. In every portal we have taken through this, inbox placement returned before the copy changed at all.
