Are Your Email Open Rates Declining? Here’s How to Fix Them
In a recent article, we talk about how conversations around email deliverability across EMEA are becoming part of a much broader discussion around digital trust, legitimacy, and operational maturity.
For many companies, these conversations don’t start strategically, and they usually begin with something more practical. Over the past two years in particular, mailbox providers (MBP) have tightened expectations around authentication, reputation, and trust for organisations sending email at scale. Issues that may have sat quietly in the background are now showing up through falling engagement, spam folder placement, ESP warnings, and growing friction among internal teams.
Enterprise Email Communications: A UK Ecommerce Scenario
The following fictionalised scenario is based on patterns we see across enterprises managing email deliverability and communications: James O’Brien manages email marketing for a growing UK-based ecommerce business.
In this scenario, campaign open rates had fallen from roughly 28% to below 20% over the course of a year, and Gmail engagement became less predictable. More campaigns landed in promotions and spam folders; eventually, the organisation’s ESP started flagging sender reputation.
Initially, the assumption was that the campaigns needed improving. The marketing team made a number of changes, including testing subject lines, redesigning templates, and cleaning email lists; they also revisited engagement strategies. Some campaigns improved slightly; overall, campaign performance kept trending in the wrong direction.
We already have SPF and DKIM
From James’ perspective, the organisation had already dealt with authentication years earlier. SPF and DKIM were configured; a DMARC record was in place, too, albeit at a nonenforcement policy of p=none.
Internally, the assumption was that email authentication was “done”. As the deliverability issues continued, that confidence started to weaken. Customer support heard from users that didn’t receive legitimate emails, and the security team had noticed increasing spoofing attempts impersonating the company’s domain. Procurement questionnaires from larger partners had also started asking more detailed questions around anti-phishing controls and email authentication practices. Initially, these all looked like separate events; over time, those lines became harder to separate.
The visibility problem
The turning point in this scenario arrives when the organisation’s ESP continually identifies sender reputation deterioration despite improvements to campaign hygiene and engagement practice. At that point, the conversation expands beyond marketing alone.
As different teams become involved, the organisation discovers that far more systems were sending email on behalf of the company than anyone had originally realised.
The team may uncover the following five concerns:
- an older CRM platform sending automated emails
- a customer survey tool configured years earlier
- regional suppliers using the company domain for notifications
- marketing trial platforms that had never been fully decommissioned
- inconsistent DKIM alignment across several services
While none of these issues may have become catastrophic individually, the bigger problem is that no one has a complete picture of the overall email ecosystem. A seeming campaign performance issue exposed a much broader visibility and governance problem across the company’s email environment.
Why Moving Beyond p=none Is Not Only Technical But Operational
A common misconception around DMARC is that moving to a policy of p=quarantine or p=reject fixes deliverability problems overnight.
For businesses facing similar challenges, moving beyond p=none is often less about flipping a technical switch and more about the operational work required to safely move toward enforcement.
To increase confidence in stronger policies, the company first needed to take the following actions:
- identify all legitimate sending sources
- remove outdated or unused platforms
- correct alignment issues
- improve oversight around third-party senders
- reduce unauthorised or inconsistent email traffic
Stricter enforcement also helped reduce unauthorised use of the organisation’s domain; over time, mailbox providers saw clearer authentication signals and fewer questionable messages associated with particular domains.
Strong DMARC enforcement alone cannot compensate for poor mailing practices, weak engagement, low-quality content, or damaged sender reputation, although the result would be a healthier and more trustworthy email ecosystem. Businesses moving beyond p=none often improve consistency, reduce unauthorised traffic, and gain insight into how email is operating.
Why the conversation has changed
Part of what has changed is that MBPs now treat authentication and trusted sending practices as baseline operational expectations rather than optional best practices. Google and Yahoo’s bulk sender requirements accelerated that shift for enterprises sending email at scale.
As a result, marketing and operations teams found themselves dealing with issues that historically may have sat within IT or security functions. For organisations like in our scenario, that often becomes the moment where deliverability conversations expand far beyond marketing alone.
There was also hesitation around moving toward stricter DMARC enforcement; some teams worried legitimate campaigns or automated workflows could break, others questioned whether the issue was a marketing problem at all. “We already have SPF and DKIM” became a fairly common internal and misguided response.
What started as a marketing problem became something larger
For companies facing similar challenges, improvements rarely happen overnight. The process typically involves the following five steps:
- auditing sending sources
- removing outdated services
- correcting alignment problems
- improving supplier governance
- gradually increasing confidence in legitimate traffic
Over time, sender reputation starts stabilising. Deliverability becomes more predictable. Internal visibility improves significantly.
Enterprises are discovering that deliverability issues are often symptoms of broader governance and visibility challenges across their digital communications environment. The organisations navigating this most successfully are often the ones bringing marketing, security, and operational teams into the conversation earlier rather than later.
We’re Here to Help
With a team of email security experts and a mission of making email and the internet more trustworthy through domain security, dmarcian is here to help assess an organization’s domain catalog and implement and manage DMARC for the long haul.
Want to continue the conversation? Head over to the dmarcian Forum.