Fix Kit emails going to spam

ConvertKit became Kit in 2024, but the sending infrastructure kept the old name, so an unverified account still gets DKIM-signed by convertkit-mail.com. This guide covers that alignment gap, the Verified Sending Domain setup that closes it, the DMARC trap that Kit's own docs warn will send your mail to spam, Gmail's Promotions tab, and list hygiene on the free Newsletter plan. The one fix that matters most: verify your sending domain before you publish a DMARC record, not after.

Why Kit emails land in spam.

01

Your DKIM signature still says convertkit-mail.com

Until you set up a Verified Sending Domain, Kit signs your broadcasts with its own shared domain, so the DKIM signature on a live send reads d=convertkit-mail.com and the message carries a third-party sender label instead of your domain alone. Kit describes the default this way: your friendly-from is the address you send from, while the return-path is a Kit address. Kit describes a Verified Sending Domain as the thing that will "DKIM-sign your messages using your domain" and "Allow your Kit messages to pass DMARC". Set it up under Settings > Email, then confirm the DKIM d= value on a live send.

02

You published a DMARC record but never verified your domain in Kit

This is the single most damaging Kit-specific mistake, and Kit states it plainly: if your sending domain has a DMARC policy but you have not verified the domain in Kit, your messages will likely go to spam. The mechanism is alignment. Your From domain asks receivers to enforce DMARC, but the mail is signed by convertkit-mail.com and bounced from a Kit-controlled return path, so nothing aligns to you. Kit's DMARC guidance says the same thing in reverse: if you use a DMARC record, you need a Verified Sending Domain for your emails to reach the inbox.

03

Your From address is a gmail.com or yahoo.com address

Kit is blunt about this: send from a free address like gmail.com or yahoo.com and your messages will likely go to spam. You are borrowing a consumer provider's reputation instead of building your own, and those providers publish strict DMARC policies that no third-party sender can align to. Kit's guidance is that all marketing email should come from a domain you own, not a personal account at a provider domain. Change the default From under Settings > Email before you touch anything else, because a Verified Sending Domain cannot rescue a freemail From address.

04

You verified your domain and lost Kit's reputation cushion

Kit is unusually candid about the trade: after a sender verifies their domain they rely solely on their own domain reputation, whereas previously many senders had Kit's domain reputation helping offset a poor one. So verification is correct long term and can look like a regression for a few weeks. Kit also warns that a change this significant can affect your engagement metrics, and that a temporary drop is normal while reputation recalculates. Do not verify and immediately mail your coldest segment at full volume.

05

Gmail files your newsletter under Promotions and you read that as spam

Most creators who say Kit emails are "going to spam" are actually looking at the Promotions tab, which is a different outcome entirely. Kit's position is that Promotions helps keep marketing messages out of the spam folder, and that messages there are more trusted and more seen. Kit explicitly advises against trying to game the tab algorithm. The one lever Kit endorses is asking subscribers to drag a message from Promotions into Primary, which trains Gmail's filter for that individual recipient.

06

Cold subscribers pile up on the free plan and nothing removes them

The Newsletter plan carries up to 10,000 subscribers for free with unlimited email sends, so pruning never becomes financially urgent. Kit counts a subscriber as cold when they have not opened an email or clicked a link in the last 90 days, or 30 days if they have been subscribed for fewer than 90. Kit never removes those people for you, and they keep counting toward your list total. On the Subscribers page, switch the status dropdown to cold, then run Kit's ad hoc list cleaning automation if you are on a paid plan (Kit gates both cleaning templates to paid plans), or select the cold subscribers and choose Unsubscribe from the Bulk Actions menu if you are on the free plan.

How Kit authenticates your mail.

Kit handles authentication through one feature rather than a set of records you assemble yourself. Everything below is downstream of whether you have completed a Verified Sending Domain under Settings > Email. Kit offers two setup paths and recommends trying the automatic one first: it hands the job to Entri, which detects your DNS provider and writes the records for you. The manual path publishes the same CNAMEs for you to paste yourself.

record default the problem the fix
Verified Sending Domain Off. A new Kit account sends over Kit's shared infrastructure with no records on your domain. Nothing on the message identifies your domain to a receiver, so you inherit whatever reputation the shared pool currently has and you cannot pass DMARC on your own From domain. Go to Settings > Email, open the Verified Sending Domains section, and run the setup. Kit publishes CNAME records rather than asking you to edit your root SPF, and Entri can apply them for you in a few clicks.
DKIM Kit signs with its own shared domain, so the d= value reads convertkit-mail.com instead of your domain. The signing domain never matches your From domain, so DKIM alignment fails and Gmail shows the via label next to your sender name. Complete the Verified Sending Domain setup. It adds CNAME records that delegate DKIM selectors to Kit's signing keys, after which the d= value on a live send is your own domain. Confirm it on a real broadcast, not in a preview.
SPF The return path is Kit-controlled, so SPF passes against Kit's domain rather than yours. SPF passes but does not align, which is why DMARC aggregate reports can show an SPF pass alongside an alignment failure on the same message. Do not add a Kit include to your root SPF record. Kit does not use one, and it changes nothing. The Verified Sending Domain moves the return path onto a subdomain of your own domain, which is what Kit means by putting your from-address in the return-path.
DMARC Optional for a small list, mandatory once you scale. Kit's own pages give two different thresholds for when Gmail and Yahoo require at least p=none: one says more than 3,000 messages a day, another says at least 5,000 emails a day. Below either number Kit sends fine with no DMARC record, and plenty of creator domains have never published one. Publishing DMARC before verifying your domain in Kit actively breaks your sending, because you are asking receivers to enforce a policy your Kit mail cannot satisfy. Verify the sending domain first, then publish v=DMARC1; p=none; rua=mailto:dmarc@example.com with your own address. Kit's own escalation guidance is to sit at each policy level for a couple of weeks before moving up, and to confirm every legitimate sender passes before you reach p=reject.

Once you have updated these records, confirm they pass with Unspam's free SPF checker, DKIM checker, and DMARC checker.

How to test a Kit campaign with Unspam.

Kit's Preview email button is not a substitute for a send. Kit notes that personalization and Link Triggers do not work in previews, which means a preview cannot tell you how a filter will score the real message. Kit also publishes a supported way to send a genuine broadcast to exactly one address, and that is the path to use.

  1. 01

    Get your Unspam seed address and your Test ID

    Start a spam test or an inbox placement test in Unspam and copy the seed address it generates. Placement tests deliver to seed mailboxes at Gmail, Outlook, Yahoo and five other providers and report where each copy landed. An inbox placement test also issues a Test ID. Paste it into the subject line or the body before you send, or the message reaches the seed mailboxes and is never matched to your test.

  2. 02

    Add the seed address as a Kit subscriber

    The single-subscriber send filters on an address that already exists in your account, so add the Unspam seed address first. Go to Grow > Subscribers, click Add Subscribers, choose One subscriber, and enter the seed address. Kit's importer confirms subscribers automatically, even into a form with double opt-in enabled, so no confirmation email is sent and there is nothing waiting in the seed inbox for you to click.

  3. 03

    Open the real broadcast and filter it down to the seed address

    Go to Send > Broadcasts, open the draft you are worried about, and click Publish. Under "Who would you like to send this to?", hover over each existing filter and click the X to remove it, then click Add Filter, choose Email Address, leave the condition on Is Exactly, and enter the Unspam seed address.

  4. 04

    Check the recipient count, then send it for real

    Kit shows a recipient counter in the top right. Confirm it reads one before you continue, because a stray filter here mails your whole list. Then click Continue and send. This goes out through your normal sending path with live tracking and live unsubscribe headers, exactly like a subscriber copy.

  5. 05

    Read the results in Unspam

    Check the spam score, the SPF, DKIM and DMARC results on the live send, placement per provider, client previews and the heatmap. The DKIM d= domain should be your own domain, not convertkit-mail.com. If it still reads convertkit-mail.com, the Verified Sending Domain has not taken effect and every other fix is premature.

The same test renders your campaign in 50+ real email clients, Gmail, Outlook, Apple Mail, iPhone, and Android among them, each in light and dark mode, via email client previews, so you confirm placement and rendering in one pass.

Kit features that quietly affect delivery.

Testing by mailing your own domain gives you a false spam result

Kit lists internal mail as its own cause of spam placement: send from info@yourdomain.com to bob@yourdomain.com and your mailbox sees a message from itself that it did not send, suspects spoofing, and files it as spam. A broadcast you send to your own address therefore tells you nothing about how subscribers receive it. Kit's advice for test sends is to use a free address like gmail.com instead, which is what an Unspam seed address gives you. If you need to mail your own domain beyond testing, Kit publishes its sending IPs so whoever manages mail for the domain can allowlist them.

The Preview email button hides the two things most likely to break

Kit states that personalization and Link Triggers do not work in email previews. A preview that looks perfect can still ship with an unrendered merge tag or a dead trigger link, and neither the content nor the routing matches a real broadcast. Kit's own recommendation is to send a real version to yourself as a final check, which is exactly the single-subscriber flow above.

Bot filtering silently changes the numbers you are diagnosing from

Kit can filter automated opens and clicks out of your reports using signals like cloud hosting IP ranges, user agent, click speed and click proximity. Turning it on under Settings > Advanced can drop your click rate noticeably, and filtered clicks stop firing Link Triggers. That is a reporting change, not a deliverability change, so check the toggle before you conclude your engagement collapsed.

A dedicated IP is not the fix, and Kit gates it accordingly

Kit requires a minimum of 150,000 messages per week and charges $250 per month for a dedicated IP. Almost no creator newsletter clears that bar, and thin volume on a dedicated IP builds worse reputation than a healthy shared pool. Modern filtering leans on domain reputation, which is exactly what the Verified Sending Domain gives you for nothing extra.

What real Kit senders run into.

The deliverability problems Kit senders hit most often, each with the fix that resolves it.

I migrated years ago and Gmail STILL shows 'via convertkit-mail.com' under my name. It makes my newsletter look like spam to my own readers.

The via label appears whenever the DKIM signing domain does not match the From domain. Kit signs unverified accounts with its shared sending domain, and because the shared pool sits behind one signing identity, every creator on it presents the same signature. The rename to Kit did not migrate those domains, so the string still reads ConvertKit and looks abandoned even on accounts opened this year.

The fix Open Settings > Email and complete the Verified Sending Domain setup, letting Entri write the CNAME records against your DNS provider if it supports yours. Use a subdomain you control and leave the records unproxied if you run Cloudflare, since a proxied CNAME breaks the delegation. Then send one real broadcast to a seed address and read the DKIM d= value on the received message. If it is your domain, the via label is gone for everyone; if it still reads convertkit-mail.com, the records have not resolved yet and nothing else you change will matter.

A security consultant told us to publish DMARC. We did, and our newsletter went from the inbox to spam within one send.

Kit documents this outcome directly: a DMARC policy on a domain that has not been verified inside Kit will likely land in spam. The cause is alignment rather than the policy value. Kit signs with convertkit-mail.com and bounces from its own return path, so a receiver evaluating DMARC finds no identifier belonging to your domain, and honors the enforcement you just asked for. Even p=none can cost you, because receivers read the record as a signal that unaligned mail is unexpected.

The fix Reverse the order. Complete the Verified Sending Domain in Settings > Email first and confirm on a live send that DKIM signs your domain. Then republish DMARC starting at v=DMARC1; p=none; rua=mailto:dmarc@example.com pointed at an address you read. Kit's escalation guidance is to hold each level for a couple of weeks and verify every legitimate sender passes before moving up, so walk p=none to p=quarantine to p=reject rather than jumping. If you cannot verify the domain right now, pulling the DMARC record is the faster way to stop the bleeding than leaving it in place.

I finally verified my sending domain like everyone said, and my open rate dropped by a third the very next week. Did I break it?

Probably not, and Kit says as much. Before verification your mail benefited from the shared pool's accumulated standing, which Kit describes as its domain reputation helping offset a potentially poor one. Verification hands you sole ownership of your reputation, and a domain with no sending history is treated cautiously by every major receiver. Kit also warns that a change this large can move your engagement metrics and that a temporary dip is expected.

The fix Do not revert. Reverting throws away the history you just started building. For the next two to four weeks send to your most engaged segment first, then widen, and avoid stacking other changes like a new From name or a big import on top of it. Kit's guidance is to avoid large increases in volume and to introduce any new group of subscribers gradually rather than all at once. Kit also recommends sending at least once a week, so keep the cadence steady while the domain earns trust, and judge recovery on clicks and replies rather than opens.

Signups exploded overnight with junk addresses and now my deliverability is wrecked. I never changed anything.

Kit calls this a listbomb: a bot or a person submitting addresses to your forms or landing pages without those people's permission. The addresses are real but the consent is not, so you mail strangers who report you. Kit's description of the damage is that open rates plummet and complaint rates spike, which hurts your reputation with providers. Kit monitors bounce, complaint and unsubscribe rates and reaches out when something spikes in the wrong direction, so a support message may be your first warning.

The fix Turn on Double Opt-in for every form and landing page immediately and make sure Auto-confirm Subscribers is unchecked, so unconfirmed bot addresses are never mailed. Double opt-in is Kit's default, which means an affected account usually had it switched off. Add reCaptcha in the form's advanced settings. Then clean up: delete the obviously fake addresses outright, and for the ambiguous ones run a re-engagement send and drop anyone who does not respond. Filter the Subscribers page by Unconfirmed to size the damage, and remember Kit gives you no way to confirm someone on their behalf.

I'm on the free plan with about 8,000 subscribers and every broadcast performs worse than the last. Nothing about my content changed.

The Newsletter plan carries up to 10,000 subscribers with unlimited sends, so there is no billing pressure to prune and most creators never do. Dead addresses accumulate, and receivers read a falling engagement ratio on a growing list as a reason to file you elsewhere. Kit's own threshold is specific: cold means no open and no click in 90 days, or 30 days for anyone subscribed less than 90 days. Kit also warns that everyone on a list should have given clear consent and been engaged in the last 12 months.

The fix Filter the Subscribers page by the cold status, select those subscribers, and apply the Add to Ad Hoc Cold Subscribers Cleaning Automation tag. That runs a re-engagement sequence built on link triggers and unsubscribes anyone who has not clicked a week after the final email, so you never make the delete decision by hand. Build the segment on clicks rather than opens, because Apple Mail Privacy Protection and Gmail's image proxy make opens unreliable and Kit says as much. Repeat it on a schedule instead of once, and expect list size to fall while your rates recover.

Kit deliverability, answered.

Why is my DKIM signature still ConvertKit-branded when the product is called Kit now?

Because the 2024 rebrand changed the name, not the mail infrastructure. Accounts without a Verified Sending Domain are signed by Kit's own shared domain, so the d= value on a live send is not your domain and DKIM cannot align to your From address. Set up a Verified Sending Domain under Settings > Email, then re-send and check that d= reads your own domain.

Is the Verified Sending Domain a paid feature?

Kit's help center does not document a plan restriction on it, and the deliverability articles present it as the expected setup for any sender rather than an upgrade. What is plan-gated is the reporting around it: advanced deliverability reporting sits on the Pro plan, and a dedicated IP is a separate paid add-on. Check the Settings > Email screen on your own account, since plan packaging changes more often than the underlying DNS setup does.

Should I add a Kit include to my SPF record?

No. Kit does not publish an include for you to add, and your root SPF record does not change as part of the setup. Kit controls the return path, so SPF already passes against Kit's infrastructure. The Verified Sending Domain is what moves the return path onto your own domain, which is the part that makes DMARC alignment possible.

My emails go to Promotions, not spam. Do I need to fix anything?

Promotions is not the spam folder, and Kit's own position is that it helps keep marketing mail out of spam. Kit advises against trying to trick the tab algorithm. If Primary placement matters to you, the endorsed approach is asking subscribers to drag one of your emails into Primary, which trains Gmail for that recipient. Confirm which folder you are actually in with a seed test before you rewrite anything.

Can Unspam connect to my Kit account and test broadcasts automatically?

No. Unspam does not integrate with Kit's API or any other platform API, and it never connects to your Kit account. The workflow is deliberately manual: add the Unspam seed address as a subscriber, send a real broadcast to just that address, and read the report. That is the only way to grade the exact message your subscribers receive.

I published DMARC on my domain and my open rates fell. What happened?

You almost certainly published DMARC without a Verified Sending Domain in Kit. Kit warns that this combination will likely send your messages to spam, because your Kit mail cannot align to the domain now demanding enforcement. Verify the sending domain, confirm on a live send that the DKIM d= value is your own domain, and only then reconsider tightening the policy.

Kit platform details were verified against publicly available documentation in August 2026 and may have changed since. Kit is a trademark of its respective owner. Unspam is not affiliated with or endorsed by Kit.

Test your next Kit campaign before your subscribers do.