Email deliverability is solved by infrastructure, not instinct. Whether you are running cold outreach sequences for a B2B startup or managing campaigns across 40 clients in a white-label agency, the same truth holds: if your domain is not authenticated, not warmed up, and sending to a dirty list, your emails go to spam regardless of how good the copy is. This guide covers the full technical stack in the order you should build it - authentication, sender reputation, warm-up, list hygiene, content hygiene, sending architecture, and monitoring. Getting this right is not complicated. It is mostly a checklist. The problem is most senders skip it.
Short answer: Email deliverability is your ability to land in the inbox rather than the spam folder or promotions tab. It depends on four layers in descending order of control: authentication (SPF, DKIM, DMARC set up correctly), sender reputation (domain and IP age and engagement history), list quality (verified addresses, low bounce and complaint rates), and content (messages that pattern-match as legitimate B2B communication). You need all four. Skip any one of them and the others compensate only partially.
What Is Email Deliverability?
Email deliverability is the rate at which your emails actually reach the recipient's inbox folder - not just their server - versus being filtered into spam, quarantined, rejected outright, or silently dropped.
Email deliverability is the measure of how consistently your outgoing emails reach the intended inbox folder at the receiving mail server, rather than the spam or promotions folder. It is determined by technical authentication records (SPF, DKIM, DMARC), the sending domain and IP's historical reputation with mailbox providers, the quality of the recipient list, and the behavioral signals of the messages being sent. High deliverability is a pre-condition for any email program to produce results - no other optimization matters if your messages are filtered before they are seen.
Deliverability is distinct from delivery. Delivery means the receiving server accepted the message (it did not bounce). Deliverability means the message reached the inbox folder rather than spam. You can have near-100% delivery rates while the majority of your mail lands in the spam folder - the server accepted the message and then filtered it.
This is why open rates that collapse suddenly are often a deliverability signal. If you were getting 40% opens and they drop to 8% without any change in copy or targeting, the most likely explanation is that your domain's inbox placement shifted. Your messages are routing to spam, and the small fraction of recipients who check spam occasionally are the only ones opening.
The practical question is: can you reliably reach your audience? For cold outreach specifically, the answer is almost entirely determined by infrastructure decisions you make before sending the first email. For a deeper look at cold-email-specific deliverability setup, see our complete cold email deliverability guide.
Why Deliverability Is Harder in 2026
Deliverability has tightened each year, but 2024 introduced the most significant shift since DMARC's mainstream adoption. Google and Yahoo's bulk sender requirements changed the baseline: one-click unsubscribe, spam complaint thresholds enforced at the infrastructure level, and mandatory DMARC records for any domain sending more than 5,000 emails per day to Gmail addresses. The practical effect was that senders who were previously getting away with weak authentication or missing records started seeing inbox placement collapse.
Three forces made 2026 harder than even 2024:
- AI-generated spam volume: The same tools that make legitimate outreach faster also make spam production faster. ISPs trained their filters on the flood of AI-generated messages from 2024-2025. Messages that pattern-match as AI-generated bulk content are scored more aggressively now than they were two years ago. This does not mean AI content fails - it means low-quality, templated, high-volume AI content fails.
- New domain scrutiny: Sending domains registered within the last 90 days or clearly derived from a brand name (company-outreach.io, getacmecorp.com) face higher initial scrutiny. ISPs have tightened reputation bootstrapping, meaning new domains need longer warm-up cycles before they can carry serious outreach volume without damaging inbox placement.
- Engagement weighting: Gmail and Outlook have increased the weight of engagement signals in inbox placement decisions. A list that has never been emailed before gets lower initial inbox placement than a list of verified contacts with known engagement history with your domain. Cold outreach inherently starts from zero, which is why warm-up is non-negotiable - not a nice-to-have.
Spam complaint rate benchmarks: Google enforces a 0.10% complaint rate threshold for bulk senders. Above this threshold, messages route to the spam folder. At 0.30%, senders face temporary delivery restrictions. Well-managed cold outreach programs typically stay below 0.05% through precise ICP targeting and clear opt-out paths. A single campaign to an unverified purchased list can destroy months of reputation building. Source: Google Postmaster Tools guidelines and ACA campaign data across managed sequences.
None of this means cold email is dead. It means the infrastructure bar is higher. Senders who set up correctly still get consistent inbox placement. Senders who skip the setup or rely on shortcuts find their domains degraded within weeks. Based on Cedric's experience running outbound at the agency level, this is the most consistent pattern we see - deliverability failures are almost always infrastructure failures, not copy failures.
The Authentication Foundation: SPF, DKIM, and DMARC
Authentication is the first layer and the one you have the most direct control over. All three records - SPF, DKIM, and DMARC - are DNS TXT records published on your sending domain. ISPs check them before making any inbox placement decision. Without all three, your domain cannot demonstrate to receiving servers that you are who you say you are.
Each record does a different thing. They are not redundant - they are complementary layers of the same authentication system. All three are required for a fully authenticated sending domain.
SPF: Authorize Your Sending Servers
SPF (Sender Policy Framework) is a DNS TXT record that lists which mail servers are authorized to send email on behalf of your domain. When a receiving server gets a message claiming to be from you, it checks your SPF record to see whether the originating server is on your approved list.
An SPF record looks like this: v=spf1 include:_spf.google.com include:amazonses.com ~all
The ~all at the end is a soft fail - unlisted servers are marked suspicious but not hard-rejected. -all is a hard fail - unlisted servers are rejected outright. For outbound email, use ~all during setup and testing, then move to -all once you have confirmed all your legitimate sending infrastructure is listed.
Common setup mistakes: the SPF record exceeds the DNS lookup limit of 10 (it stops working silently without error), or multiple SPF records exist on the same domain (only the last one is valid in practice). Use an SPF flattening tool if you send through many services. For step-by-step setup across major providers, see our SPF, DKIM, and DMARC setup guide.
DKIM: Sign Your Messages Cryptographically
DKIM (DomainKeys Identified Mail) adds a digital signature to your outgoing messages. The receiving server fetches your public key from DNS and uses it to verify that the message content was not altered in transit and that the message genuinely originated from a server holding the corresponding private key.
DKIM uses RSA cryptography. The minimum key size is 1024 bits, but 2048 bits is now the recommended standard - 1024-bit keys are considered insufficiently secure and some providers have begun rejecting them. Check your sending platform's DKIM configuration and upgrade if you are on 1024-bit keys.
DKIM failure does not automatically route your message to spam, but it removes a significant positive authentication signal and leaves your inbox placement reliant on reputation signals alone. More importantly, without DKIM, DMARC cannot fully work - DMARC alignment requires either SPF or DKIM to pass and align with the From header domain.
DMARC: Set a Policy and Monitor Alignment
DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM together with a policy that tells receiving servers what to do when authentication fails. It also enables aggregate reporting so you can see which servers are sending email on behalf of your domain and whether authentication is passing for each.
A minimal DMARC record for monitoring: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
The policy options:
- p=none: Monitor only. Receive reports, take no action. Start here when first deploying DMARC to understand what is sending from your domain before locking it down.
- p=quarantine: Unauthenticated messages are sent to spam or quarantine. Move here after confirming that all your legitimate sending sources pass authentication in the monitoring phase.
- p=reject: Unauthenticated messages are rejected outright. The gold standard for anti-spoofing protection. Move here once you are confident every legitimate sending path - CRM, transactional email, outreach tool, marketing platform - is covered.
If you send through multiple services, all of them must have their sending infrastructure represented in your SPF and DKIM before you escalate to p=quarantine or p=reject. One missed service and legitimate transactional emails (receipts, password resets) start bouncing at receiving servers.
Sender Reputation: How ISPs Score Your Domain
Authentication tells ISPs who you are. Reputation tells them whether to trust you. They are separate signals, and a perfectly authenticated domain with poor reputation still lands in spam - often in spam without any bounce notification, which makes reputation degradation one of the harder problems to detect early.
Sender reputation exists at two levels: domain reputation and IP reputation. Domain reputation is attached to your From domain - the one your recipients see. IP reputation is attached to the sending server's IP address. Cloud-based sending services use shared IP pools by default, which means your domain reputation matters more than the IP. Dedicated IPs give you full control over IP reputation but require their own warm-up cycle and maintenance.
The factors ISPs use to score domain reputation:
- Engagement history: Are recipients opening, clicking, and replying? High engagement from verified contacts is the strongest positive reputation signal available. Gmail in particular weights engagement signals heavily in inbox placement decisions. Sequences that generate genuine replies are the fastest way to build domain reputation with Gmail's infrastructure.
- Spam complaint rate: Complaints come from recipients clicking "Report Spam" (or "Mark as Junk" on Outlook). Even one spam complaint from every 1,000 sends approaches the 0.10% threshold that triggers Google's bulk folder routing. Complaint signals propagate quickly - a campaign with a 0.5% complaint rate can move a domain from High to Low reputation in Google Postmaster Tools within 48 hours.
- Bounce rate: Hard bounces (permanently invalid addresses) signal list quality problems. More than 2% hard bounce rate on any single campaign is a reputation flag. Repeated high-bounce sends move your domain into a higher-risk scoring category that is difficult to recover from quickly.
- Volume consistency: Sudden volume spikes - going from 50 to 5,000 emails per day overnight - are a strong spam signal. Legitimate senders ramp up gradually because their business grows gradually. This is the core logic behind email warm-up.
- Domain age and history: New domains start with no reputation, which receiving servers treat cautiously. Established domains with years of consistent clean sending carry substantial implicit trust - trust that a new domain cannot borrow or fast-track, only build.
Reputation damage is recoverable, but slowly. A domain that enters recovery typically needs 4-6 weeks of careful, low-volume, high-engagement sending before reputation signals improve. Domains that get blocklisted (Spamhaus SBL, Barracuda, Microsoft SNDS block lists) need delisting requests plus the same recovery period - and there is no guarantee delisting is immediate.
Email Warm-Up: Infrastructure Before Volume
Email warm-up is the process of building sender reputation on a new (or dormant) domain by gradually increasing sending volume over time while maintaining high engagement rates. ISPs treat a domain sending 50 emails on day one very differently from a domain that suddenly appears sending 2,000.
The logic is straightforward: established, legitimate senders grow gradually because their business grows gradually. Spam operations spin up domains and blast volume immediately. ISPs use ramp speed as a heuristic because the correlation with spam intent is high. A domain that reaches 500 sends per day after six weeks of gradual increases looks like a legitimate business scaling its outreach. A domain doing 500 on day one looks like a spam operation.
How warm-up works in practice:
- Weeks 1-2: 20-50 emails per day, sent to contacts who are likely to engage - your team, existing clients, partners, newsletter subscribers who opted in. Every open and reply strengthens the reputation signal. Do not send to cold prospects at this stage.
- Weeks 3-4: 50-200 emails per day. Begin introducing cold prospects carefully at the end of this period, but keep the ratio of warm engaged sends high. Monitor open rates and bounce rates closely - any deterioration is a signal to slow down, not accelerate.
- Weeks 5-8: 200-500+ per day, depending on target volume. By week 6-8, a properly warmed domain can sustain 500-1,000 cold emails per day with maintained deliverability - though this varies significantly based on list quality, ICP targeting precision, and reply rates from the cold portion of your list.
Warm-up services accelerate this process by automatically exchanging emails between a pool of real mailboxes, generating engagement signals (opens, replies, explicit "not spam" actions) that build reputation faster than organic activity alone. They do not replace organic warm-up - they compress the timeline from 8 weeks to 4-5 weeks on average for a well-run warm-up process.
For a comparison of warm-up services and how to integrate them with your sending infrastructure, see our guide to the best email warm-up tools in 2026.
New domains that skip warm-up and go straight to cold outreach at volume do not just land in spam - they often get their sending IP flagged within 30 days. The warm-up timeline feels slow. It is significantly shorter than the recovery timeline after getting blocklisted.
ACA includes native warm-up capabilities with built-in ZapMail and Mailreach integration. The warm-up and the outreach sequences run from the same platform - there is no separate warm-up service to configure alongside your sending tool. Warm-up signals from the integrated networks feed directly into the domain reputation for the accounts you use for live campaigns.
List Hygiene: Clean Data Is Infrastructure
Your list is the second most controllable variable in your deliverability stack, after authentication. Every invalid email address you send to is a potential hard bounce. Every uninterested contact who marks your message as spam is a complaint. Compounding low-quality sends is the fastest way to destroy a reputation you spent weeks building.
List hygiene covers three distinct problems that require different solutions:
Verification - remove invalid addresses before sending. Email verification services check whether an address is syntactically valid, whether the domain's MX records are configured to receive email, and whether the specific mailbox exists (using an SMTP-level handshake without actually sending a message). This eliminates hard bounces from typos, dead accounts, and decommissioned domains before they have a chance to affect your reputation. Run verification on every imported list before the first send. Re-verify lists older than 90 days - mailboxes close and change regularly at the velocity of B2B employee turnover.
Suppression management - never re-send to opt-outs or hard bouncers. Every hard bounce address must be added to your suppression list permanently. Every unsubscribe request must be honored - within 10 business days under CAN-SPAM, within 48 hours under Google's 2024 bulk sender requirements. Sending to suppressed contacts is both a compliance violation and a reputation signal that you are running a disorganized list. Most well-configured outreach platforms handle suppression automatically, but verify that suppressions are shared across all active campaigns and accounts, not just the sequence that generated the opt-out.
Re-engagement or removal - do not carry dead weight. Contacts who have received five or more emails over 90 days without opening once are either unreachable (a deliverability sink) or uninterested (a complaint risk). Segment them out of active sequences before they affect your complaint rate. Run a final re-engagement campaign with a clear, low-friction opt-in signal. If they do not engage, remove them. A smaller, active list consistently outperforms a large, unresponsive one across every deliverability metric that matters.
For detailed guidance on bounce types, verification frequency, and suppression list management patterns, see our guide to email list hygiene.
Content and Copy Signals That Trigger Filters
Content filtering is where senders most often look for shortcuts, and the layer where shortcuts most consistently backfire. Modern spam filters are not static keyword lists. They are machine-learning models trained on billions of messages. They recognize patterns and combinations, not individual words in isolation.
Content signals that increase spam scoring:
- Heavy HTML and skewed image-to-text ratio: Marketing emails with complex HTML, large images, and minimal text match the pattern of bulk marketing email. ISPs distinguish between marketing messages and B2B outreach by pattern. Cold emails formatted like newsletters have meaningfully higher spam rates than plain-text equivalents targeting the same list.
- Spam trigger word patterns: "Free", "limited time offer", "act now", and "guaranteed" in subject lines are obvious. Less obvious: excessive use of "click here", "no obligation", "100%", exclamation points in subject lines, and currency symbols throughout the body. The issue is not the individual word - it is the combination and density of patterns.
- Failed personalization: "Hi [FirstName]" or "Hi ," (a missing merge field) signals a mass-sent message with broken personalization - one of the clearest spam indicators available. Every send should be verified for merge field completion before going out. Sequences that fire on empty fields are preventable deliverability problems.
- URL reputation: Links to domains with poor reputation drag your message's spam score down regardless of the content around them. Shortened URLs and tracking redirectors scoring at neutral-to-negative reputation affect message scoring. Monitor your click link domains separately. See our guide to email spam trigger words for a current list of content patterns flagged in 2026.
- Reply-to domain mismatch: Routing replies to a different domain than the From domain is legitimate (shared inbox, help desk), but the Reply-To domain needs its own reputation and authentication. A Reply-To domain with no reputation adds a negative signal to the message.
Sending Infrastructure: Domains, IPs, and Rotation
Your sending infrastructure is the combination of domains, IP addresses, and sending services that carry your outbound email. Getting this right is as important as authentication for any sender running volume beyond 300-500 emails per day.
Use your primary domain when: you are sending low volume (under 500 per day total across all campaigns), you want maximum sender trust from recipients who recognize your brand domain, and you have the operational discipline to warm it carefully and protect its long-term reputation.
Use purpose-built sending domains when: you are running cold outreach at scale where reputation risk is higher, you are an agency running separate outreach programs across multiple clients, or you need to isolate transactional email infrastructure from cold outreach infrastructure.
Sending domains are purpose-registered domains used specifically for outreach. If your primary domain is acmecorp.com, you might register getacmecorp.com or acmecorp.io as a sending domain. Recipients see it as legitimate (it redirects to your main site), but your primary domain reputation is isolated from any deliverability risk that cold outreach generates over time.
Key principles for sending domain setup and management:
- Register sending domains 60-90 days before active use: New domains have no reputation and trigger higher scrutiny at receiving servers. Registering in advance - and building some minimal organic activity on the domain - gives it time to age before you begin cold outreach volume.
- Stable domains, not campaign-specific ones: Spinning up a new domain for each campaign restarts the warm-up cycle each time and generates domain age patterns that match spam operations. Maintain a stable set of sending domains and protect their reputation as long-term assets.
- Sender rotation across multiple domains: Instead of 2,000 emails per day from one domain, rotate across four domains sending 500 each. This keeps each domain within safe daily limits while achieving overall volume targets. Rotation also provides redundancy - if one domain takes a temporary reputation hit, the others continue running while the affected one recovers. ACA handles sender rotation automatically across client workspaces and multi-domain configurations.
- Dedicated vs shared IPs: Most cold outreach senders are better served by shared IP pools from reputable ESPs than by dedicated IPs. Shared pools benefit from pooled reputation, and reputational dilution from other senders is minimal at quality ESPs. Dedicated IPs make sense at 50,000+ emails per day, where full IP reputation control outweighs the management overhead.
For outbound teams running high-volume sequences across multiple channels, multi-channel automation also reduces deliverability risk by distributing touchpoints. A prospect who does not open your cold email might connect on LinkedIn instead. This is the architecture behind full outbound sales automation - deliverability is one layer in a system that does not depend entirely on email inbox placement.
Monitoring: What to Measure and When to Act
Deliverability problems that are not caught early compound. A domain that starts taking inbox placement hits and continues sending at volume accelerates its own reputation damage. Monitoring gives you the signals to catch problems while they are still recoverable - not after two weeks of damaged campaigns.
Key deliverability benchmarks for cold outreach in 2026: Open rate of 25-50% indicates good inbox placement - below 15% on a warmed domain usually signals spam filtering. Hard bounce rate below 2% per campaign. Soft bounce rate below 5%. Spam complaint rate below 0.08% (Google's enforcement threshold is 0.10%; staying below 0.08% gives a buffer for variance). Unsubscribe rate above 0.5% per campaign suggests targeting or messaging problems requiring investigation. Source: aggregated from public ESP benchmark reports and ACA-managed campaign data.
The tools and methods for monitoring deliverability:
- Google Postmaster Tools: Free. Connects to your sending domain and shows Gmail-specific domain reputation (High, Medium, Low, Bad), IP reputation, spam rate, and authentication pass rates. The reputation signal here is the same one Google uses to make inbox placement decisions in real time. Check it weekly at minimum. A drop from High to Medium warrants immediate investigation - it typically precedes measurable inbox placement degradation by 3-5 days.
- Microsoft SNDS and JMRP: Microsoft's equivalent of Postmaster Tools for Outlook and Hotmail. Shows your sending IP's complaint rate and block status for Microsoft's network. Less detailed than Postmaster Tools but essential if a significant share of your target audience uses Outlook or corporate Exchange.
- Inbox placement testing: Services like Mail-Tester, GlockApps, and MXToolbox Inbox Analyzer show where your test message actually lands - inbox, spam, promotions, or missing entirely - across a set of seed addresses at major ISPs. Run these before launching any new campaign from a new domain, and after any changes to authentication setup or sending infrastructure.
- Bounce and complaint monitoring in your sending platform: Every ESP surfaces bounce and complaint rates. Set up alerts for hard bounce rate above 1.5% on any campaign and complaint rate above 0.05%. Investigate immediately when alerts fire - both are leading indicators of deliverability degradation, not lagging ones.
- Blocklist monitoring: Services like MXToolbox monitor your sending domain and IP against major blocklists (Spamhaus, Barracuda, SURBL, Invaluement). Blocklist listings happen to legitimate senders - the key is catching them within hours, not days. Sending a campaign from a blocklisted domain sends it into a void.
Teams running multiple sending domains across a complex outreach stack need consolidated monitoring across all domains, not just the one currently active. For monitoring tools that integrate with your cold email setup, see our comparison of the best email deliverability tools in 2026.
How ACA Handles Deliverability Natively
Most cold outreach platforms ask you to bring your own deliverability infrastructure and stitch it together with your sequencing tool. ACA's approach is different - deliverability is part of the platform, not an external layer you configure separately.
What is included natively:
- Built-in email warm-up: New sending accounts enter a warm-up schedule automatically. Volume starts low and increases on a configurable ramp based on the account's engagement signals. You do not need a separate warm-up service subscription alongside your outreach tool - the warm-up and the outreach run from the same system, and warm-up signals feed directly into the live sending accounts.
- ZapMail and Mailreach integration: For teams that want dedicated warm-up networks beyond ACA's native warm-up, direct ZapMail and Mailreach integration is included. Warm-up activity from these networks consolidates into the same sending accounts used for outreach, so reputation signals are unified.
- Sender rotation across domains and accounts: ACA manages rotation across multiple sending domains and accounts automatically. When running a multi-client agency or high-volume outreach program, rotation is configured once at the account level rather than manually managed per campaign.
- BYO infrastructure: Teams with existing email infrastructure - dedicated sending servers, private IP pools, custom SMTP relays - can route through ACA without abandoning that setup. ACA handles sequence logic, personalization, reply detection, and reporting on top of your existing infrastructure.
- Integrated bounce and complaint handling: Hard bounces are suppressed automatically across all sequences running on the same account. Unsubscribes are honored in real time across all active campaigns. Suppression lists are shared across clients in the same workspace, which matters significantly in agency deployments where a suppressed contact might appear on multiple client lists simultaneously.
Deliverability infrastructure is one layer of a multi-channel B2B outreach system. Email sequences landing in the inbox need to be part of a workflow that also includes LinkedIn, WhatsApp, and other channels - because inbox placement alone does not guarantee replies. For the full picture of how these channels work together as a system, see our B2B lead generation playbook and the complete cold email outreach guide.
FAQ
What is email deliverability, and how is it different from delivery?
Email delivery means the receiving server accepted your message without bouncing. Email deliverability means the message reached the inbox folder rather than the spam folder or promotions tab. You can have near-100% delivery rates while the majority of messages land in spam. Deliverability is the metric that correlates with opens, replies, and campaign results.
How long does email warm-up take for a new domain?
A domain warmed from zero to 500 emails per day typically takes 6-8 weeks of consistent, gradually increasing volume with maintained engagement rates. Using a dedicated warm-up service in parallel can compress this to 4-5 weeks. Trying to shortcut warm-up typically results in inbox placement problems within the first 2-3 weeks of serious cold outreach volume on that domain.
Does authentication guarantee inbox placement?
No. Authentication - SPF, DKIM, DMARC - establishes that you are who you claim to be, which prevents hard rejection on authentication failure grounds. But ISPs then score your message separately based on reputation, list quality, and content. Authentication is a necessary floor requirement. It is not sufficient for inbox placement on its own.
What spam complaint rate is safe for cold outreach?
Google's 2024 enforcement threshold is 0.10% - one complaint per 1,000 emails sent to Gmail. At 0.30%, Google implements temporary sending restrictions. A well-managed cold outreach program targeting a verified ICP-matched list should stay below 0.05%. If your complaint rate exceeds 0.08%, pause the campaign, investigate list quality and targeting precision, and resolve the underlying issue before resuming. Complaint rate spikes do not self-correct without intervention.
Is email deliverability the same for cold email and marketing email?
They share the same infrastructure requirements - authentication, reputation, list hygiene - but differ in two important ways. Marketing email has an existing relationship with the recipient (opted in), which provides positive engagement signals that cold email starts without. Cold email relies more heavily on ICP targeting precision: if you are emailing people who would genuinely benefit from what you offer, engagement trends positive; if you are spraying lists, it trends negative quickly. Cold email also typically uses plain-text messages rather than HTML templates, which score differently with content filters - plain text has a significant inbox placement advantage for outreach.
How do I check if my sending domain is on a blocklist?
Use MXToolbox's blacklist checker to check your domain and sending IP against 100+ major blocklists. For Gmail-specific reputation, Google Postmaster Tools gives you direct visibility into how Google scores your domain in real time. For Microsoft properties, check Microsoft SNDS. Set up automated monitoring rather than checking manually - blocklist listings can happen at any time and need to be caught within hours to minimize campaign impact.
What is the difference between soft and hard email bounces?
A hard bounce is a permanent delivery failure - the address does not exist, the domain has been decommissioned, or the mailbox has been closed. Hard bounces must be added to your suppression list immediately and never retried. A soft bounce is a temporary failure - the inbox is full, the server is temporarily unavailable, or a quota has been exceeded. Soft bounces can be retried after a delay (most ESPs handle this automatically), but contacts that soft-bounce repeatedly (5+ times) should be treated as hard bounces and suppressed.