## TL;DR
Reset emails land in spam for two reasons: your sending domain fails authentication (SPF, DKIM, DMARC), or the content looks spammy. Check authentication first with a deliverability test, fix the DNS records, then clean up the content: plain text-ish design, no URL shorteners, one clear link. While you fix it, tell users to check spam and add the sender to contacts.

## The query

```text
password reset email goes to spam: how to fix
```

## Use this when

- Users report reset emails in spam or missing
- Setting up transactional email for the first time
- Deliverability audits
- "Never received the reset email" tickets spike

## Not for

- Building authentication systems
- Marketing email deliverability
- Phishing investigations
- Email client bugs

## Steps

### 1. Verify SPF, DKIM, and DMARC

Send a test to a deliverability checker and read the authentication results. Missing or misaligned SPF/DKIM is the top cause. Fix the DNS records: SPF authorizes your senders, DKIM signs the mail, DMARC ties them together.

Expected output: passing SPF, DKIM, and DMARC on test sends.

### 2. Check the sending reputation basics

New domains and new IPs start with no reputation. Warm them gradually. Check whether the sending IP or domain is on a blocklist. Shared IPs inherit other senders' sins; consider a dedicated IP for transactional mail.

Expected output: blocklist check clean, warmup plan if new.

### 3. Clean up the email content

No URL shorteners (they scream phishing), one clear reset link with your domain visible, minimal images, plain subject line like "Reset your [product] password." Spam filters score content too.

Expected output: a simplified, single-link template.

### 4. Give users the immediate workaround

While the fix propagates: check the spam folder, add the sender address to contacts, and search for the subject line. Put this in the reset-request confirmation page so users see it before they open a ticket.

Expected output: workaround text live on the reset page.

### 5. Monitor and confirm the fix

Watch reset-email ticket volume for two weeks after the change. Resend tests to the major providers. Deliverability is verified by customer behavior, not by one green checkmark.

Expected output: ticket volume back to baseline.

## Template: the user-facing workaround

```text
Did not get your reset email? Two quick things:

1. Check your spam or junk folder - it sometimes lands there.
2. Add [sender address] to your contacts, then request a new reset link.

The link expires in [time]. If it still does not arrive after that, reply here and we will sort it out another way.
```

## Variant phrasings

### reset email not received

Steps 1 and 4. Check auth, give the workaround now.

### transactional email going to spam

Steps 1 through 3. Authentication, reputation, content.

### SPF DKIM setup for reset emails

Step 1. The DNS records are the fix.

## Why it works

Spam filters trust authenticated mail from reputable senders with clean content. Password resets fail the trust check most often on authentication, because they are frequently sent from a different system than the marketing mail that the domain was set up for. Fixing auth fixes the majority; content cleanup gets the rest.

## Edge cases

- Corporate filters stricter than Gmail: the user's IT may quarantine it. The workaround plus IT allowlisting covers this.
- The user typed the wrong email: verify the address before debugging deliverability. Typos are common.
- Apple relay addresses: sign-in-with-Apple users get mail at a relay address. Make sure your system sends there.
- Link expired by the time they find it in spam: extend the expiry window or make re-request one tap.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_Nx7kP3Bj4NLXaW0ShYWHGQ
