Why AI Agent Emails Land in Spam (and How to Fix It)
Spam filters rarely care about a single word. They care about who you are, how you behave and whether people want your mail. Here is what that means for AI agents.
By Toan Nhu

You built an agent that writes a thoughtful reply, and the recipient never sees it because it went to spam. The instinct is to blame the wording: maybe it said free, or urgent, or used too many exclamation marks. In practice, modern filters at Gmail, Outlook and Yahoo lean far more on signals about the sender than on individual words. Lists of forbidden spam words are mostly a relic of older filters. If your agent's mail is being filtered, the cause is usually one of the five things below.
1. The domain cannot prove who it is
Unauthenticated mail is the easiest thing for a filter to distrust. Every message your agent sends should pass SPF or DKIM, aligned with the From domain under a DMARC policy. On a hosted @mermail.app address, Mermail manages that authentication for you. On your own domain, publish the records Mermail generates and add a DMARC record yourself. Our SPF, DKIM and DMARC guide walks through the rollout.
2. The sender has no history, then sends a lot
A brand new domain that suddenly sends hundreds of messages looks exactly like a spammer spinning up infrastructure. Reputation is built by sending modest volumes of wanted mail and increasing gradually as results stay healthy. Mermail's own guidance for custom domains is to start with a small number of relevant messages to people who expect them, and to pause and investigate bounces or complaints instead of chasing a fixed daily growth target. Agents that batch work can make this worse, so spread sends out rather than firing a whole queue at once.
3. Recipients did not ask for the mail
Engagement is a major signal. When people open, reply to and move your messages out of spam, filters learn your mail is wanted. When they delete without reading or click Report spam, the opposite happens. An agent that replies to inbound requests, confirms actions a user started, or follows up on an existing thread tends to have excellent engagement. An agent that emails strangers from a scraped list does not, no matter how well the copy is written.
The most reliable deliverability strategy for agents is therefore also the simplest: send mail people expect, and make stopping it easy. Honor opt-outs immediately, and for any bulk or marketing mail include a clear unsubscribe option.
4. The message looks machine-made
Filters notice patterns across many messages, not just inside one. Some habits common in LLM-generated mail can hurt:
- Near-identical bodies sent to many recipients. Personalization should be real and relevant, not a swapped first name. Trying to fool filters with random spinning of phrases is still bulk mail and is treated as such.
- Broken formatting. Raw Markdown asterisks, stray HTML tags or a mismatch between the plain-text and HTML parts look careless to people and suspicious to software. Render Markdown properly or send clean plain text.
- Heavy HTML. For one-to-one agent mail, a simple message with little markup reads like a person wrote it. Large image-only emails, hidden text and many tracking links read like a campaign.
- Links to unfamiliar or shortened URLs. Link to your own, established domain where you can. URL shorteners and brand new domains are common in phishing.
- Oversized attachments. Keep files small and relevant. On Mermail, hosted addresses have an encoded message limit of about 5 MiB and custom-domain addresses about 40 MB.
Words still matter a little. Misleading subject lines, fake Re: prefixes and pressure tactics are both spammy and, for commercial mail in many countries, legally risky. Write the way a helpful person would.
5. Bad addresses are dragging you down
Sending to addresses that bounce, or to old abandoned addresses that providers have turned into spam traps, tells filters you are not maintaining your lists. The fix is upstream: only email addresses from trusted sources, never guess them, and suppress hard bounces and complaints automatically. Mermail reports bounces and spam complaints as webhook events, so you can feed them straight into a suppression check that runs before your agent's send tool.
How to test where your agent's mail lands
Before you let an agent loose, send a few real messages from its mailbox to test inboxes you control at the major providers, such as a personal Gmail and an Outlook account. Check the folder each one lands in, open the headers to confirm SPF, DKIM and DMARC pass, and read the message as a recipient would. Repeat this whenever you change domains, templates or sending patterns. Remember that a handful of test inboxes is a spot check, not a guarantee: placement varies by recipient history.
Once real traffic flows, watch delivered, bounced and complained events per mailbox. A rising complaint count is an earlier warning than anything you will see in a test.
A pre-flight checklist for agent senders
- Authenticated domain with SPF, DKIM and a DMARC record.
- Agent mail on its own subdomain or hosted address, separate from your team's mail.
- Recipients who expect the message, and an easy way to opt out.
- Clean rendering, simple markup, few links, small attachments.
- Gradual volume, with automatic suppression of bounces and complaints.
- Seed tests before launch and after every significant change.
Mermail gives each agent its own authenticated inbox, with delivery and complaint events you can act on. Compare Mermail plans and start with a free hosted inbox.


