password reset email goes to spam: how to fix
How to fix password reset emails landing in spam: SPF, DKIM, and DMARC checks, plus what to tell users while you fix it. Use when users report reset emails in spam or missing entirely, when setting up transactional email, or during deliverability audits. Not for building auth systems, marketing email deliverability, or phishing investigations.
TL;DR
Reset emails land in spam for two reasons: your sending domain fails authentication (SPF, DKIM, DMARC), or the content looks spammy. Check authentication first with a deliverability test, fix the DNS records, then clean up the content: plain text-ish design, no URL shorteners, one clear link. While you fix it, tell users to check spam and add the sender to contacts.
The query
password reset email goes to spam: how to fixUse this when
- Users report reset emails in spam or missing
- Setting up transactional email for the first time
- Deliverability audits
- "Never received the reset email" tickets spike
Not for
- Building authentication systems
- Marketing email deliverability
- Phishing investigations
- Email client bugs
Steps
1. Verify SPF, DKIM, and DMARC
Send a test to a deliverability checker and read the authentication results. Missing or misaligned SPF/DKIM is the top cause. Fix the DNS records: SPF authorizes your senders, DKIM signs the mail, DMARC ties them together.
Expected output: passing SPF, DKIM, and DMARC on test sends.
2. Check the sending reputation basics
New domains and new IPs start with no reputation. Warm them gradually. Check whether the sending IP or domain is on a blocklist. Shared IPs inherit other senders' sins; consider a dedicated IP for transactional mail.
Expected output: blocklist check clean, warmup plan if new.
3. Clean up the email content
No URL shorteners (they scream phishing), one clear reset link with your domain visible, minimal images, plain subject line like "Reset your [product] password." Spam filters score content too.
Expected output: a simplified, single-link template.
4. Give users the immediate workaround
While the fix propagates: check the spam folder, add the sender address to contacts, and search for the subject line. Put this in the reset-request confirmation page so users see it before they open a ticket.
Expected output: workaround text live on the reset page.
5. Monitor and confirm the fix
Watch reset-email ticket volume for two weeks after the change. Resend tests to the major providers. Deliverability is verified by customer behavior, not by one green checkmark.
Expected output: ticket volume back to baseline.
Template: the user-facing workaround
Did not get your reset email? Two quick things:
1. Check your spam or junk folder - it sometimes lands there.
2. Add [sender address] to your contacts, then request a new reset link.
The link expires in [time]. If it still does not arrive after that, reply here and we will sort it out another way.Variant phrasings
reset email not received
Steps 1 and 4. Check auth, give the workaround now.
transactional email going to spam
Steps 1 through 3. Authentication, reputation, content.
SPF DKIM setup for reset emails
Step 1. The DNS records are the fix.
Why it works
Spam filters trust authenticated mail from reputable senders with clean content. Password resets fail the trust check most often on authentication, because they are frequently sent from a different system than the marketing mail that the domain was set up for. Fixing auth fixes the majority; content cleanup gets the rest.
Edge cases
- Corporate filters stricter than Gmail: the user's IT may quarantine it. The workaround plus IT allowlisting covers this.
- The user typed the wrong email: verify the address before debugging deliverability. Typos are common.
- Apple relay addresses: sign-in-with-Apple users get mail at a relay address. Make sure your system sends there.
- Link expired by the time they find it in spam: extend the expiry window or make re-request one tap.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_Nx7kP3Bj4NLXaW0ShYWHGQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.