Your Password Reset Email Is Probably in Spam: Deliverability for a Tiny SaaS
The usual story goes like this. Onboarding emails get low opens and almost no replies, so you rewrite the subject lines. Then rewrite them again. Then one user mentions in a support thread, "btw your welcome email was in my spam, and the password reset too." The copy was never the problem. The mail wasn't arriving. If you run a small SaaS, this is easy to miss because nothing breaks loudly.…
In the world of small SaaS companies, one vital email that often goes unnoticed is the password reset email. It might be sitting in the spam folder of users, leading to lost accounts and churn. A minute of DNS work can ensure that the critical password reset, welcome, and magic link emails reach users' inboxes instead of spam folders.
Since February 2024, Google and Yahoo have made it mandatory for email senders to have SPF or DKIM set up for their domains, valid DNS for the sending IP, and TLS. Even if you send fewer than 5,000 messages a day, it's crucial to follow these guidelines. Set up SPF, DKIM, and DMARC records, and ensure your From domain aligns with them.
Use a real transactional provider rather than sending from an app server with raw SMTP on a shared IP. Set up SPF, DKIM, and DMARC records, and regularly check the reports generated by your provider. Align the domain in your visible From address with the one that passed SPF or DKIM. Test your setup by sending a password reset email to a personal Gmail address and checking the headers for SPF: PASS, DKIM: PASS, and DMARC: PASS.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.