Subject Line Blank

Subject Line Blank E8 - Education ranks last in inbox placement: here is why

Mailtrap.io Season 1 Episode 8

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 13:57

Education ranks dead last for inbox placement. This is the industry with the most authority, trust, legacy, and knowledge. Yet, universities and educational institutions are failing to learn one thing - email deliverability. 

In today's episode, we're digging deep. What exactly is causing poor inbox placement for education? When is deliverability an ownership problem rather than a technical one? Who's responsible for making sure critical education emails land in the inbox? 

SPEAKER_00

A university can be 200 years old, have Nobel Prizes, research labs, and Gmail will still treat it like a spam. One 2026 inbox placement benchmark put education at 86%, the lowest industry on the list. B2B SAS sits at 92%. And before anyone screams at me, no, this doesn't mean university emails are being compared directly with cold sales email. The benchmark is looking at opt-in commercial email programs. It's not the same. But if a university with centuries of reputation cannot outtrust a SaaS company, maybe the problem was never a trust issue. Maybe it's just the university's mail issue and its very, very messy structure and strategy. That's what we're digging into today. Why do emails from trusted institutions end up in spam? And how much of this is actually on the university? I have Marcus, and this is Subject Line Blank. An email, a sender can be a few things at once. It can be the name the recipient sees, like admissions or alumni. It can be the domain like university.edu. It can be a subdomain like news.university.edu. It can also be the platform doing the sending like a CRM or a student portal. Now, mailbox providers decide whether mail connected to that sender is safe, wanted, and properly set up. They look at signals like authentication, sending history, spam complaints, bounces, engagement, and whether the email is coming from a platform that is actually allowed to send for that domain. Simple in theory. But most universities are not one sender. They are dozens of senders stacked under the same institutional name. Let's put it this way admissions can send clean, useful emails, but if alumni keeps sending to all list or an all sending tool start bouncing messages, the whole university's email identity can start to look less reliable. After all, a university is basically a small city wearing one logo. And this is not just theory. UW Madison has guidance for campus senders using third-party tools like MailChimp, Constant Contact, and Emma, and the warning is pretty clear. Emails from the same domain are evaluated together, and if other senders from that domain fail to meet the standards, it can hurt the reputation and deliverability of email for the entire domain. Because their user reported spam rate is calculated by looking at all emails from UW Madison collectively. Also look at McGill. According to an Envogue case study, McGill uses email to communicate with 275,000 alumni, 40,000 students, and more than 10,000 staff and academic employees. Its many departments and faculties are sending more than 8 million emails a year. Another Envogue write up says McGill manages more than 300 users across over 150 sub-accounts. So when Gmail, Yahoo, or Outlook are deciding whether to trust the university, it's actually trying to average out the behavior of too many different senders hiding behind one name or one crest. But wait, before moving on, if this kind of breakdown is useful to you, hit subscribe and turn on the notification bell. Every week we bring you a different view of the world of email, AI, deliverability, and the weird places they all collide. This episode is one of those, so stick around. But let's be fair too. Universities are also victims. They are full of useful targets, students, staff, payroll systems, even their own version of dating apps. All the nice boring stuff criminals love to play with. Universities also have a lot of users, a lot of departments, and a lot of tools sending emails on behalf of the institution. That makes the attack surface even bigger. Let's say an attacker gets into a real email account, or worse, gets access to an ESP account or an API key. They can send directly as the actual institution. And if spam or phishing in this case goes out that way, that is the kind of thing that can damage the domain's reputation faster than a classroom emptying when the teacher says you can go. That is where university trusts start working against the university. The brand helps the scam feel real to the recipient. And if the sending is authenticated through a real tool, a legitimate tool, it may also look real enough to the inbox, at least long enough to cause damage. Microsoft reported a 2025 payroll phishing campaign where attackers compromise 11 accounts across three universities and used them to send phishing email to almost 6,000 accounts across 25 universities. Google's Threat Intelligence team had reported similar higher-end phishing campaigns, including cloned university login portals. So, yes, phishing against universities is unfair, but if the bad mail goes out through something the university actually uses, the mailbox provider does not see a fake mustache. It sees your sender and suddenly the security problem is right there eating your deliverability. And what happens to a university list over time? Students graduate. Parents stop being parents of a current student, donors give once and move on. At some point, a big chunk of the list has already left the relationship. And for mailbox providers, that silence is a signal. And not a good one. And look, nobody unsubscribes out of spite unless you really hated your school experience. People just stop noticing those emails exist. To the university that might look like a quiet alumni list, to Gmail, Yahoo, Outlook, whatever mailbox provider you might have, it can start looking like a sender people have tuned out. And there's a practical version of this too. UC Berkeley tells alumni they have to log in into their at Berkeley.edu Google account at least once every six months to keep it active. After four months of no measure activity, they get a warning. After five months, another warning. After six months, the account is disabled and its contents are deleted. That is a university openly saying alumni email's account can become abandoned. Happens. And abandoned accounts, stale addresses, and silent recipients can all become a deliverability problem. A big headache. Now multiply that by classes going back 10, 20, 30 years, and you end up emailing people whose last real interaction with the university was returning a library book and promising to stay in touch. And bounces are not just a vanity metric. In Mailtrap we know that too well. Mailtrap's own deliverability trestles treat a 2% to 5% bounce rate as a warning level. Anything above 5% is critical. Gmail and Yahoo point in the same direction. Bounces mean slow down, clean the list, and stop emailing addresses that are clearly dead. But this is where a sunset policy comes in. A sunset policy is basically a rule for when you stop sending regular emails to someone who has gone cold. Not because the relationship is dead forever. But because after months of no opens, no clicks or replies, sending every campaign to that specific person is not staying in touch. It is teaching mailbox providers that your mail is easy to ignore. And you don't want that. A good sunset policy might move those people into a re-engagement campaign. First, something simple. Do you still want these emails? If they do nothing, you move them out of regular campaigns. You can still keep the alumni record, but you stop using a dead relationship as fuel for bulk and hundreds of emails. So a sunset policy is more than a technical best practice. It is the university admitting the relationship change while protecting its sender reputation at the same time. Okay, now the exciting technical part. Wink. Let's cosplay as DNS administrators for a minute. We looked at the human side. Too many senders. Phishing. Old and outdated lists, but under the hood, the inbox is looking at much colder stuff. And this is why a lot of universities start looking like a domain that has been just patched together for years. First root cause, DMARC that only watches. DMARC can look at Europe's top 500 higher education domains and found that only about a quarter were protected with actual DMARC enforcement, meaning quarantine or reject. The rest were mostly sitting in monitoring mode, had no DMARC record, had a poor record, or were not really enforcing anything. So we have DMARC can mean two very different things. It can mean we are actively telling mailbox providers what to do with suspicious mail. Or it can mean we're watching suspicious mail happen and hoping for the best. Second root cause. SPF turns into a vendor soup. SPF is supposed to say which systems are allowed to send email for your domain. Simple idea. But then a university starts adding more and more tools and every tool wants permission to send. The problem is SPF has a limit. The UK government's own guidance says SPF allows a maximum of 10 DNS lookups during evaluation. Go over that, and SPF can fail. So authentication can break not because someone is evil or lazy, but because their record slowly became a tiny DNS lasagna. And yes, I'm keeping that phrase. Third root cause, bulk email sitting too close to everyday email. Rootgers have a very useful bit for guidance for third-party bulk email vendors. They tell senders not to use a live domain that is used for day-to-day email and to consider using one utility domain per service. So instead of sending everything from the main university domain, you might have one lane for marketing, one for ticketing, another one for your CRM emails. Something like updates.university.edu for campaigns, tickets.university.edu for ticketing, and crm.university.edu for the CRM. Let me translate that for you. If your marketing tool has a bad week, you do not want it standing next to normal staff email. If your event platform sucks, you do not want it sitting on top of student services. It's like having a two days old fish dish next to your freshly made tiramisu in the fridge. So remember, different streams need different lanes. Fourth root cause and probably the most important. Nobody is watching the whole thing. Google Postmaster Tools can show you things like configuration issues, spam rates, authentication rates, and delivery errors, all amazing information. Great, right? But someone has to actually look at it and fix it. That is why most of the time the technical problem is more of an ownership problem. Universities and educational institutions are very good at treating communication as something important. But email reputation does not care how important the message feels to the sender. It is cold, like Arnold Schwarzenegger in Terminator 2. There are many reasons why education struggles with deliverability, but none of them are exclusive to education. Bad segmentation, weak authentication, ignore list, messy vendors, that happens everywhere. What makes education different is the excuse. The assumption that reputation in the real world will carry through the inbox. It doesn't. So hopefully the things we covered today will give you a place to start. And if anything we talk about sounds familiar or made you raise an eyebrow, this is probably the time to go back and look at your strategy. Look at your lists, look at your text setup, or whatever is making that creaking noise in your deli variability. Because email is pretty straightforward in a very annoying way. Do it well, keep an eye on it, and it behaves. Ignore it, patch it together, and eventually the inbox stops giving you the benefit of the doubt. So what's the takeaway for me? Someone needs to own the system. I'm Marcus, and this is Subject Line Blank.