You did the thing everyone tells you to do. Every address on your list asked to be there. Nobody was scraped, nobody was bought, the sign-up form was honest about what people were agreeing to, and you have the consent records to prove it. And your emails are still landing in spam.
This is a particularly maddening place to be, and it costs more than most people realise. The contacts on a permission-based list are, by definition, your warmest audience. They are the people who wanted to hear from you, the ones most likely to open, click, buy, renew, or come back. When your mail skips their inbox and drops into spam, you are not losing cold traffic. You are losing revenue you had already earned, from people who had already said yes.
So it is worth being precise about why this happens, because the instinct when you have done everything right is to assume the cause must be something small and cosmetic, a subject line or a spammy word or an image that loads too large. It is almost never any of those.
Permission and deliverability are two different questions
Here is the thing that trips up almost everyone who runs into this. Permission answers a legal question. Deliverability answers a technical and behavioural one. They overlap far less than the language suggests.
When someone opts in, you have satisfied UK GDPR and the Privacy and Electronic Communications Regulations, and that is the right foundation for any email programme. But consent is a record you hold. It is not a signal the inbox provider can see. Gmail does not read your database. Microsoft does not check your double opt-in logs before it decides where to place your message. At the moment of delivery, the provider has no idea whether the person on the other end asked for your email or not.
What it has instead is behaviour. It watches what happens to your mail once it arrives, across everyone you send to, and it forms a view of you from that. Permission from eighteen months ago tells the provider nothing about whether the person still wants to hear from you today. Engagement does. That gap, between "they consented once" and "they engage now", is where most of these problems live.
What inbox providers watch instead
Inbox providers score your list as a cohort, not as individuals. This is the part that catches out well-run, permission-based senders more than anything else, so it is worth slowing down on.
Picture two thousand people who opted into your list eighteen months ago, all of them legitimately. Some still open everything you send. A good share have quietly drifted. They changed jobs, lost interest, moved to a different address, or simply stopped noticing you. You keep emailing all of them, because they all opted in and it feels wrong to stop. From your side, that looks responsible. From Gmail's side, it looks like a sender whose mail a large portion of recipients ignore, delete unread, or never open.
The provider reads that aggregate and applies it to your whole domain. It infers engagement from a range of quiet signals: whether people open, how long the message sits in view, whether it gets replied to or deleted on sight, and how often someone reaches for the spam button. So the dormant half of your list is not dead weight sitting there harmlessly. It is actively pulling down placement for the engaged half, the people who do still want your email. You end up in the strange position where sending to the subscribers who stopped caring is the very thing keeping you out of the inbox of the subscribers who never stopped.
This is why "but they all opted in" is not the defence it feels like. Opt-in got them onto the list. Only engagement keeps the list healthy enough to reach the inbox, and engagement decays whether you tend to it or not. There is a fuller explanation of how this cohort scoring works in our piece on dormant subscribers, because it is the single most common reason a clean list underperforms.
The other places it breaks, even with a spotless list
Engagement is the usual culprit for permission-based senders, but it is not the only one. A few others come up again and again, and any of them can undo an otherwise well-behaved programme.
- The first is authentication that does not quite line up. SPF, DKIM and DMARC are how a provider confirms you are really you. If they are missing, misconfigured, or misaligned with the infrastructure you actually send from, the provider cannot verify the mail, and unverified mail is treated with suspicion no matter how consensual it is. This turns up most often after a platform change, or when a new tool starts sending on your behalf without being added to your records. We walk through what these records do and how they fail in SPF, DKIM and DMARC explained, and there is a practical rollout plan in the 90-day DMARC guide for UK teams.
- The second is a reputation you inherited rather than earned. If you send on a shared IP address, you share a reputation with every other sender on it, and their behaviour affects your placement. The same is true of a sending domain with history you were not around for. You can be a careful sender today and still be carrying the consequences of decisions made before you arrived.
- The third is marketing and transactional mail sharing one reputation. If your promotional mail and your password resets, receipts and verification emails all go out from the same domain, they share a single reputation. A promotional send that generates a spike of complaints can drag down placement for the transactional mail going out the same afternoon, which is how businesses end up with sign-up verification emails landing in spam for reasons that have nothing to do with the verification email itself. That is worth separating properly, and it is a common reason transactional mail fails silently.
- The fourth is sending behaviour that changes suddenly. Providers notice pattern changes. A sharp jump in volume, a new sending schedule, or a large re-engagement send to people who have not heard from you in a year can all read as risk, even when your intentions are good. The classic own goal here is the well-meant "we miss you" send to every dormant contact at once, which often does more damage to your reputation than leaving them alone would have.
The UK wrinkle worth knowing
Most deliverability advice you will find online was written for the US market, and it quietly assumes Gmail is the inbox that matters most. In the UK, and especially in UK business-to-business, Microsoft matters far more than that advice lets on. A large share of professional inboxes here run on Microsoft 365, and Microsoft filters differently from Gmail. It is stricter in places, more opaque about its reasoning, and slower to forgive a dip in reputation.
The practical consequence is that a UK sender can look perfectly healthy in Gmail, fire a couple of test sends to personal Gmail accounts, watch them land, and conclude everything is fine, while a meaningful part of their real audience sits behind Microsoft and never sees the mail. If your customers or subscribers are UK businesses, checking only Gmail gives you a flattering and misleading picture.
There is a small irony in this for UK senders in particular. Your permission is probably watertight, because UK GDPR made you get it right. That is exactly why the cause of your spam problem is almost certainly somewhere else.
How to find your actual cause
The hard part of all this is that you cannot see it from inside your own platform. Your email tool will happily report a delivery rate of 99 percent, and that number is close to meaningless, because "delivered" only means the receiving server accepted the message. It says nothing about whether the message reached the inbox or was quietly filed in spam. Your dashboard cannot tell the difference, which is why so many teams are surprised to learn they have a problem at all. We pulled that apart in why a 99 percent delivery rate hides a revenue problem.
To find the real cause, you have to see what the inbox provider sees: whether your authentication passes, how your domain is regarded, and where your mail is actually landing rather than merely being accepted. That is the gap the free email health check is built to close. You send one test email from your normal sending platform and get an immediate read on your authentication and the signals a provider uses to place your mail, with no sign-up and nothing to install. It is the quickest way to tell whether your problem is authentication, reputation, list health, or something in your sending setup, so you fix the actual cause instead of guessing.
Run the free health check · Free, and it takes less than a minute.
If the results raise more questions than they answer, that is what the free 15-minute check-up is for. We run your domain properly beforehand and walk through what we find in plain English, with no pitch and no obligation.
The short version
Permission is where a good email programme starts. It is not where deliverability ends. Consent gets someone onto your list and keeps you the right side of UK law, and both of those matter.
But the inbox provider standing between you and your audience never sees that consent. It sees how people behave when your mail arrives, whether you are who you claim to be, and whether your sending looks like something it should trust. Get those right and permission finally does what you always assumed it did. Get them wrong, and the cleanest opt-in list in the country will still land in spam.

