GUIDE

What to collect when email delivery fails

Before you ask anyone about bounced, delayed or filtered email, collect this evidence: what it is, who holds it and how long it is kept.

Before you ask anyone for help with email that bounced, was delayed or went to spam, collect the evidence for one affected message: the exact bounce text, the full headers, your sending platform's record of it and the time it was sent. Collect it early. Gmail's sender contact form (opens in a new tab) asks for the full headers of a recent message, less than 12 days old.

What happened to the message?

A recipient not seeing an email in their inbox is not the same as the email not being delivered, and sometimes the message was never sent to the recipient at all (Postmark's guide to missing messages (opens in a new tab)). Each outcome needs different evidence, so name yours first:

  • Never sent. Check your Sent Mail and Drafts (opens in a new tab). If the email isn't there, you might have deleted it before you sent it.
  • Never accepted by the sending platform. On Postmark, for example, check the Activity tab of the relevant Message Stream, which shows a recipient's message events within your activity retention period. If a message sent through Postmark's application programming interface (opens in a new tab) (API) isn't there, check your own logs for the response code Postmark sent when you submitted it.
  • Delayed. Wait a few hours to see whether a delivery error message arrives. Amazon SES (opens in a new tab) also suggests checking whether the problem is a delay rather than a permanent delivery failure.
  • Bounced. You received a delivery error message. Keep it: the next section covers what to copy from it.
  • Accepted, then filtered. Determine whether the email arrived but was filtered as spam. Ask the recipient to check their Junk or Spam folder.

Note when the problem started and whether it affects one recipient or many.

The bounce message, word for word

Copy the whole bounce message, not a summary. Microsoft calls the most common kind a nondelivery report (opens in a new tab) (NDR): it tells you the message wasn't delivered, and it includes an error code for the reason plus technical details for administrators. Make sure you get the NDR code or status code from it.

The first digit of that status code matters. RFC 3463 (opens in a new tab) defines these status codes for reporting mail system conditions. In it, a code starting with 4 is a persistent transient failure: the message was valid, but a temporary condition delayed or stopped the attempts to send it. A code starting with 5 is a permanent failure, one not likely to be resolved by resending the message in its current form.

If you fill out Yahoo's Sender Support Request (opens in a new tab), include the error and diagnostic codes from your logs.

What a particular code means is a separate question. DemiSignal's guide to 550 5.7.1 (opens in a new tab), for example, explains that bounce, how to read the text after the code from Gmail or Microsoft 365, and whether you or the recipient's admin must fix it.

Full headers from a recent message

If an affected message reached a mailbox, including a spam folder, get its full headers. In Gmail, open the email, then next to Reply choose More and Show original (opens in a new tab).

Use a recent message. Gmail's sender contact form (opens in a new tab) asks for the full headers of a message less than 12 days old, both for a message marked as spam or phishing and for one that was rejected or blocked.

Note the Message-ID as well. In Microsoft's message trace (opens in a new tab), the message ID is the value in the message's Message-ID header field, and users can give it to an administrator to investigate a specific message.

Your sending platform's record

Find the platform's record of the affected message, and note how long the platform keeps it:

A delivered status means less than it sounds. In Mailgun's events, delivered means Mailgun sent the email and the recipient's email server accepted it. Once Postmark hands a message to the recipient's mail server, it loses all sight and control over the message.

When you ask the platform for help, include identifiers. Amazon SES (opens in a new tab) asks for the relevant recipient addresses and any request IDs or message IDs returned by its SendEmail or SendRawEmail calls. Postmark asks for a link from its Activity to the message.

Logs on the recipient's side

If the recipient uses Google Workspace or Microsoft 365, their administrator can look the message up from the receiving side.

In Google Workspace, they can use Email Log Search (opens in a new tab) (ELS). If a message known to exist and sent to one of their registered users doesn't appear in ELS, it probably never made it to the Google network. Delivery logs aren't available for messages received more than 30 days ago.

In Microsoft 365, a message trace (opens in a new tab) shows whether the service received, rejected, deferred or delivered a message. The time range defaults to 2 days and can go up to 90 days.

Give the administrator the sender, the recipient, the time sent and the Message-ID.

Mailbox-provider data

For Gmail, Postmaster Tools (opens in a new tab) has dashboards for spam rate, reputation, message authentication and delivery errors. Its data only covers messages sent to personal Gmail accounts, and data might be missing on days with too few messages. To let someone else see the dashboards, add them to the domain in Postmaster Tools.

If you use Gmail's sender contact form (opens in a new tab), allow at least 2 weeks between submissions.

For Outlook.com, the Smart Network Data Services (opens in a new tab) (SNDS) need a Microsoft Account and an access request for the Internet Protocol (opens in a new tab) (IP) addresses you're responsible for. Note which IP addresses send your mail; Postmaster Tools also reports on the domains and IP addresses you use to send email.

Your domain's authentication setup

DemiSignal's free check (opens in a new tab) needs no account. It only reads the public records of the domain you enter in the Domain Name System (opens in a new tab) (DNS). Keep its result with the rest of your evidence. A DNS finding shows how your domain is set up; it does not show where a particular message landed.

If your domain publishes DMARC, the record that tells receivers what to do with email failing authentication and where to send reports, include those reports. Google recommends DMARC reports (opens in a new tab) for monitoring email sent from your domain or appearing to be sent from it.

What not to send, and what to expect

Leave passwords and access credentials out of any enquiry, ours included. Where someone needs access, give them their own: Mailchimp (opens in a new tab), for example, lets agencies and freelancers connect to a client's account without taking up a user seat or sharing login information.

Submitting information to Outlook.com (opens in a new tab) doesn't guarantee that any message you send to its users will be delivered, and Yahoo (opens in a new tab) cannot guarantee inbox delivery either. Mailbox providers decide how messages are handled.

To ask DemiEmail, describe what happened, when it started and what you've collected. A person reads your enquiry and replies by email, with questions or with what a scoped piece of work would involve. Keep the full headers and logs to hand for that reply.

Sources

Questions

How recent does the evidence need to be?

As recent as you can get. Gmail's sender contact form asks for full headers from a message less than 12 days old, and Mailgun keeps event data for 30 days.

Should I share my password so someone can investigate?

No. Leave passwords and access credentials out, and give the person their own access where the service offers it, such as Mailchimp's agency access.

Will reporting the problem to a mailbox provider get my email delivered?

Not necessarily. Submitting information to Outlook.com does not guarantee delivery to its users, Yahoo cannot guarantee inbox delivery, and mailbox providers decide how messages are handled.

LET'S FIND THE NEXT STEP

What's happening
with your email?

Tell us what's happening with your email. A person reads your enquiry and replies by email, with questions or with what a scoped piece of work would involve.