We switched to single opt-in and started collecting spam traps without knowing it
Mailchimp's hosted signup forms default to single opt-in, so any person or bot can type any address onto your list with no confirmation. That quietly seeds recycled spam traps and typo or role addresses, driving the hard bounces and complaints that tank reputation and can trip Omnivore or a compliance review.
The fix
Turn double opt-in back on for the audience: Audience > Contacts, pick the audience, then the three-dots menu > Audience settings > Form settings > edit the Email opt-in settings, choose Double opt-in, and save. New contacts from hosted or embedded forms must then click a confirmation link before landing on the list, which filters out most spam traps and typo or role addresses and cuts hard bounces and complaints. Double opt-in also auto-enables reCAPTCHA on those forms to block bots, with nothing extra to configure. One caveat: this governs only Mailchimp's own forms, not contacts added through the API or a third-party integration, so keep verifying imported and integration-sourced addresses externally.
One high-unsubscribe campaign got our sending suspended, not just throttled
Mailchimp's Compliance team auto-flags a single campaign that draws too many unsubscribes or spam complaints and disables all sending, including test emails, while it reviews the account. Senders describe it hitting out of the blue after one aggressive or off-audience send, and because forms and the API keep working, the block is easy to miss.
The fix
This is a compliance pause, not a filtering problem, so no DNS, authentication, or content change will lift it. Find the details on your Account page under Account History, then fix the root cause: segment to recently engaged contacts, stop mailing purchased or long-dormant lists, and make the permission reason obvious. Follow the instructions in the Compliance message and reply if one is requested. Reviews run business hours only (Monday to Friday, 9am to 5pm EST) on a first-come, first-served basis, so expect a wait, then send conservatively once reinstated and do not re-blast the same list.
Everything technically 'delivers' but every campaign lands in Gmail's Promotions tab
Inbox placement is technically fine but functionally invisible: mail routes to Gmail's Promotions tab, not spam, so opens crater. Stripping images, links, and promo words rarely helps, because the tab decision is driven mostly by low engagement, the marketing-ESP send pattern, and lack of prior contact, not content.
The fix
Promotions placement is engagement-driven, so chase engagement, not content tricks. Since Gmail's September 2025 switch to algorithmic Most Relevant sorting, even plain-text campaigns still land in Promotions if engagement is low. The highest-leverage moves are on your side: complete custom DKIM domain authentication, mail only recently engaged segments, and prune or sunset non-openers so your engaged rate climbs. On your confirmation page and welcome email you can ask subscribers to add your From address to their Google Contacts, though a saved contact makes Primary more likely rather than guaranteed. The reliable subscriber-side fix is dragging one email to Primary, which Gmail then offers to repeat for future messages. Do not expect subject-line edits to move it.
Our links started tripping 'possible fraud' and phishing warnings on recipients' security software
Mailchimp rewrites every tracked link through its list-manage.com redirector, so corporate security tools and browser or AV scanners sometimes flag campaigns where the visible link text does not match the underlying redirect URL, the same pattern phishers use. Senders report their own legitimate emails getting quarantined or warned about as possible fraud, especially in stricter corporate environments.
The fix
Prefer descriptive anchor text ("Read the guide") over a raw URL as the visible link, since a visible raw URL that redirects through Mailchimp's tracker is exactly the visible-text-versus-destination mismatch scanners look for. This is the single most effective first step and the one Mailchimp itself recommends. It does not always fully resolve the warning, because the tracking redirect can still be scanned as a redirect on its own, so the most aggressive corporate filters may still flag it. For a strict B2B audience where warnings persist, the fallback is to turn off Track clicks in the campaign's Settings & Tracking so links are not rewritten at all, at the cost of click stats; Mailchimp frames this as a last resort.
Bulk sending via Mailchimp tanked our main domain, so even everyday Google Workspace replies now land in spam
Senders assume a separate sending subdomain isolates reputation, then a large Mailchimp campaign sours their Gmail reputation and everyday mail sent from the main domain (often via a Google Workspace Send As alias) starts hitting spam too. Gmail evaluates reputation at the organizational domain level, so the subdomain rolls up to the parent, and the Send As alias links the two.
The fix
Pause sending immediately, since mailing into a souring reputation compounds the damage. Diagnose in Google Postmaster Tools for both the root and sending domain: if the Spam Rate spiked above 0.3 percent during the send, that is your answer, because Gmail measures recipients hitting report spam, not your ESP's abuse metrics. Warm the reputation back by mailing your most engaged openers first, then widening over days. For genuine isolation you need separate sending infrastructure, and ensure Mailchimp is DMARC-aligned on the sending domain. Note that a real subdomain is mail.brand.com, not a lookalike separate domain like emailbrand.com.