Cross a 0.30% spam complaint rate at Gmail and you lose access to delivery mitigation, full stop, until you hold under 0.30% for seven straight days. That single number does more to determine whether your cold email reaches a Primary inbox than any word you put in the subject line. Most SDR teams are still optimizing for the wrong thing.

For years, cold email advice centered on banned word lists: never say "free," avoid "discount," strip out "guarantee." That advice is outdated. Spam filtering at Gmail and Microsoft has moved from static keyword matching to transformer-based natural language models that evaluate context, intent, and sender authority rather than flagging isolated tokens. A message that says "we offer a free consultation" from an authenticated, reputable domain does not get penalized the way it would have five years ago. What actually gets scored is who you are and how people treat your mail, not which words you used.

Reputation and authentication gate everything else

When a message hits an enterprise mail server, it passes through authentication checks first: SPF, DKIM, and DMARC alignment, plus reverse DNS. Fail those, and receiving systems can rate-limit you, junk the message, or reject it outright before a single word of your copy gets evaluated. Only messages that clear this gate move on to reputation and behavioral scoring, and only after that does content analysis come into play at all.

Google runs this scoring through Postmaster Tools. Bulk senders (domains sending 5,000+ messages a day to personal Gmail accounts) must keep their daily complaint rate below 0.10% as a target and never hit the 0.30% hard ceiling. Cross that ceiling and you're locked out of delivery mitigation programs until you've held below it for seven consecutive days. Worth noting: once a domain crosses the 5,000-message bulk sender threshold even once, that classification is permanent, regardless of what your volume looks like afterward.

Microsoft runs a parallel but distinct system through Exchange Online Protection and Defender for Office 365. Every inbound message gets a Spam Confidence Level (SCL) score, where 7-9 means high-confidence spam that gets quarantined or blocked outright, and a separate Bulk Complaint Level (BCL) that tracks historical complaint patterns specific to bulk mail streams. A high BCL routes you to Junk even if you've technically passed authentication.

The two systems reward different things, which is worth knowing if your team splits sending across both ecosystems. Gmail's model leans harder on real-time complaint and engagement telemetry, so a domain can recover relatively fast once bad behavior stops. Microsoft's SCL/BCL model weights domain alignment, IP history, and structural threat intelligence more heavily, which tends to make Microsoft inboxes stricter and slower to forgive a damaged sender. A domain that's clean on Gmail isn't automatically clean on Microsoft, and vice versa, so checking both matters if your prospect list spans both mail systems.

The infrastructure Google actually cares about right now

Two mechanics are worth building your process around because Google and Microsoft have made them non-negotiable for bulk senders. First, RFC 8058, the IETF standard defining one-click unsubscribe via a List-Unsubscribe-Post header and a POST-able unsubscribe URL, is now required infrastructure, not a nice-to-have. Second, in October and November of 2025, Google retired the old Postmaster Tools v1 interface, which showed a soft, graduated domain and IP reputation score, and replaced it with a binary Compliance Status dashboard that checks authentication, one-click unsubscribe implementation, and spam rate as pass/fail items. That shift matters: Google is telling senders that partial compliance no longer buys partial credit. You either meet the bar or you don't.

What this means for your actual send process

If reputation and complaint rate are the dominant signals, the practical levers are things that affect how recipients react to your mail, not clever phrasing:

  • Watch your complaint rate obsessively. It's a harder gate than anything about your copy. If you're a bulk sender, treat 0.10% as your real ceiling, not 0.30%.
  • Get authentication fully aligned. SPF, DKIM, and a DMARC record with proper alignment aren't optional infrastructure. They're the first checkpoint your message has to pass.
  • Implement RFC 8058 one-click unsubscribe. It's mandated for bulk senders and it reduces the odds someone hits "report spam" instead of unsubscribing, which matters because a spam report costs you far more reputation than an opt-out.
  • Treat direct replies as your best signal. A reply is the strongest positive engagement signal a recipient can send. Deliberately writing copy that invites a genuine response does more for deliverability long-term than avoiding a specific word ever did.

What to stop worrying about

The spam trigger word myth is exactly that: a myth, according to how modern filters actually work. NLP-based filtering evaluates the whole message for commercial intent and urgency density, not a dictionary of flagged tokens. That doesn't mean tone is irrelevant. Dense clusters of aggressive promotional language and manufactured urgency ('Act now! Limited time!') still read as spam signals to a model evaluating intent, but that's a pattern-level judgment, not a word-blacklist problem. Swapping "free" for "complimentary" changes nothing if the surrounding message still reads as a blast.

One byproduct worth calling out: Instantly's 2026 cold email benchmark data (their own customer panel, so read it as directional rather than causal) shows their strongest senders keeping first-touch emails under 80 words. That's consistent with everything above. Short, direct, reply-inviting copy from a well-authenticated, low-complaint domain is the actual formula. Nothing about word choice enters into it.

The mechanics here are demanding enough, authentication alignment, complaint thresholds, unsubscribe infrastructure, that it's worth catching mistakes before they go out rather than after a domain's reputation takes the hit. Grading a draft against these signals before you hit send is a lot cheaper than earning your way back from a Postmaster Tools "Bad" rating.