Why are my emails going to Spam?
Zoho Mail uses multiple spam filtering, email authentication, and security checks to identify and classify potentially harmful emails before they reach your inbox. Incoming emails are evaluated against user-defined spam settings, organization spam control policies, email authentication standards, and other spam detection rules to separate legitimate emails from spam.
If an email is classified as spam, Zoho Mail displays a spam reason that explains the specific rule, policy, or security check that triggered the classification. Reviewing the spam reason helps you determine whether the email was correctly identified as spam or mistakenly classified (a false positive). Based on the reason displayed, you can take the appropriate action, such as updating your spam settings, modifying your organization's spam policies, verifying email authentication, or allowing the sender or domain.
Check Spam reasons in Zoho Mail
Every email in the Spam folder includes a spam reason that indicates why it was classified as spam. Open the email to view the spam alert displayed at the top of the message. The alert identifies the specific spam filtering rule, organization policy, email authentication result, or security check that triggered the classification, helping you identify the exact cause and resolve the issue.
The following sections explain the different spam reasons displayed in Zoho Mail, what each reason means, and the recommended steps to prevent legitimate emails from being marked as spam in the future.
Sender and Domain Blocklist issues
During the spam filtering process, Zoho Mail checks incoming emails against configured sender and domain Blocklists. If a match is found, the email is classified as spam based on the applicable user, group, or organization policy. The following sections describe each blocklist-related spam reason and the recommended resolution.
Sender domain is blocklisted by your organization
This spam reason indicates that the sender's domain matches an organization-level Blocklist configured by your administrator. As a result, Zoho Mail classifies the domain as spam and delivers it to the Spam folder according to your organization's spam policy.
If you trust emails from this domain, contact your organization's administrator to remove the domain from the Blocklist or add it to the Allowlist. This updates the spam policy so that future emails from the trusted domain are no longer classified as spam because of the Blocklist rule.
Organization administrators can manage blocked and allowed domains by navigating to Zoho Mail Admin Console > Security&Compliance > Spam Control > Blocked List > Domains. Then delete the blocked domain.
Sending domain is listed in your domain blocklist
Apart from organization-level blocklists, Zoho Mail also checks your personal domain Blocklist during the spam filtering process. If the sender's domain is listed in your personal domain Blocklist, the email is automatically classified as spam and delivered to the Spam folder. This spam reason indicates that the email was blocked based on your user-defined spam settings rather than your organization's spam policy.
If you want to receive emails from the sender of the domain, you can remove the email address from the Blocklist or move to Allowlist:
- Go to Zoho Mail Settings andnavigate to Anti-Spam List
- Under the Domain Address tab, all the Domain addresses in your Allowlist and Blocklist will be displayed.
- Select the Domain address you wish to remove from your Blocklist.
- Click the arrow icon to move the Domain address added to Blocklist to the Allowlist.
- You can also click the delete button to remove the Domain address from your Blocklist.
Sender email is blocklisted by your organization
The sender's email address matches an organization-level blocklist that your administrator has set up, according to the spam policy. In accordance with your company's spam policy, Zoho Mail categorises the email as spam and sends it to the Spam folder.
The Organization administrator of your company can add the email address to the Allowlist or remove it from the Blocklist if you trust the sender's emails. This modifies the company's spam policy so that the Blocklist rule will no longer consider the sender's future emails to be spam.
If a sender has been blocked by your organization, an organization manager can remove the email address from the blocked list. In the Zoho Mail Admin Console, go to Security & Compliance > Spam Control > Blocked List > Emails, select the blocked email address, and click Delete.
Sender email is listed in your email blocklist
This spam reason indicates that the sender's email address is present in your personal Email Blocklist. During spam filtering, Zoho Mail checks your user-defined spam settings and classifies emails from blocked senders as spam, delivering them to the Spam folder.
If you trust emails from this sender, remove the email address from your Email Blocklist or add it to your Allowlist. This updates your personal spam settings and prevents future emails from the sender from being marked as spam because of the Blocklist rule.
You can manage your personal Email Blocklist and Allowlist from your Zoho Mail spam settings by following the steps below:
- Go to Zoho Mail Settings and navigate to Anti-Spam List
- Under the Email Address tab, all the email addresses in your Allowlist and Blocklist will be displayed.
- Select the email address you wish to remove from your Blocklist.
- Click the arrow icon to move the email address added to Blocklist to the Allowlist.
- You can also click the delete button to remove the email address from your Blocklist.
Sender email is blacklisted for this group
When you receive an email from a sender whose email address has been added to the Blocklist for the group to which the email was sent. As a result, emails from this sender are classified as spam for members of that group based on the group's spam policy.
If you trust emails from this sender, contact the Organization administrator to remove the email address from the group's Blocklist or add it to the group's Allowlist. This updates the group's spam settings and prevents future emails from the sender from being marked as spam for that group.
If a sender has been blocked in your group's email settings, a group administrator can remove or allow the email address. In the Zoho Mail Admin Console, go to Groups > Incoming Email Settings > Email Address, select the blocked email address, and choose Move to allowed list or Delete to remove it from the Blocklist.
One of the recipients of the email is blocklist
This alert is displayed when one of the recipients included in the email is present in your organization's Blocklist. Based on your organization's spam policy, Zoho Mail identifies the email as spam and delivers it to the Spam folder, even if the message is addressed to multiple recipients.
If the recipient was blocklisted by mistake, contact your organization's administrator to review the Blocklist configuration. Removing the recipient from the Blocklist or updating the applicable spam policy will prevent similar emails from being marked as spam in the future.
Organization Policies & Restrictions in Zoho Mail
Organization administrators can define policies that control how incoming emails are handled based on various criteria, such as sender information, geographic location, email content, and security rules. This section explains the spam reasons generated when an email matches these organization-level restrictions.
Sending domain's TLD is blocked by your organization
If the sender's domain belongs to a top-level domain (TLD), such as .xyz, .top, or .info, that has been blocked by your organization, Zoho Mail classifies the email as spam and delivers it to the Spam folder according to your organization's spam policy.
If emails from a specific top-level domain (TLD) are blocked, contact your organization administrator to remove the TLD from the blocked list. In the Zoho Mail Admin Console, go to Security & Compliance > Spam Control > Blocked List > TLDs, select the blocked TLD, and click Delete.
The country from which the email was sent is blocked by your organization
When you receive emails from a country that has been blocked by your organization's spam policy, Zoho Mail classifies the email as spam and delivers it to the Spam folder. This restriction helps organizations prevent unwanted or potentially harmful emails from specific geographic locations.
If you trust emails from a blocked country, contact your organization administrator to review the country-based spam policy. In the Zoho Mail Admin Console, go to Security & Compliance > Spam Control > Internationalized Spam > Country, select the blocked country, and click Delete to remove it from the blocked list.
The email language is blocked by your organization
Emails written in a language might have been blocked by your organization's spam policy. As a result, Zoho Mail classifies the email as spam and delivers it to the Spam folder.
If you expect to receive legitimate emails in a blocked language, contact your organization administrator to review the language-based spam policy. In the Zoho Mail Admin Console, go to Security & Compliance > Spam Control > Internationalized Spam > Language, select the blocked language, and click Delete to remove it from the blocked list.
The email language is blocked by you
When an incoming email is written in a language that you have added to your personal Blocked Languages list, Zoho Mail marks the email as spam and delivers it to the Spam folder based on your personal language filtering settings.
If you want to receive emails in this language, remove it from your blocked languages list or add the sender to your Allowlist. You can update your language filtering preferences from your Zoho Mail Anti-spam settings by following the steps below:
- Navigate to Zoho Mail Settings andnavigate to Anti-Spam List
- From the Anti-spam drop-down, click on the Language filter option.
- Choose from the multiple option if you want to add to allowlist, blocklist or none.
- Then add the languages to allowlist or remove existing languages from the blocklist.
Sender Email Validation Issues
Before delivering an email, Zoho Mail validates the sender's identity to ensure the message originates from a legitimate and trustworthy source. If the sender information is missing, invalid, inconsistent, or shows signs of impersonation, the email may be flagged as spam to protect users from phishing, spoofing, and other email attacks. The following spam reasons explain the different sender validation issues that can cause an email to be classified as spam.
Sender details are Null/empty
The email is identified as spam because the sender information is missing, empty, or invalid. Emails without valid sender details do not comply with standard email format and are commonly associated with spam or malicious email activity. To protect your inbox, Zoho Mail classifies such emails as spam and delivers them to the Spam folder.
If you believe the email is legitimate, ask the sender to verify their email details and ensure that valid sender information is included before sending the email again.
Spoofing attempt made using Display name
Zoho Mail detected a potential display name spoofing attempt in these email. The sender's display name resembles that of a trusted person or organization, but the underlying sender information does not match. To help protect against phishing and email impersonation attacks, the email is classified as spam and is delivered to the Spam folder.
If you were expecting this email, verify the sender's actual email address and email authentication details before interacting with the email message. If the email is legitimate, contact your organization's administrator.
Email Content and HTML-Based Security Checks
Zoho Mail analyzes the HTML structure and content of incoming emails to detect elements that could lead to a potential security or privacy risk. Certain HTML tags, embedded scripts, tracking mechanisms, and other active content can be exploited to deliver malicious code, collect user information, or initiate phishing attacks. When such content is detected, Zoho Mail classifies the email as potentially harmful and delivers it to the Spam folder. The following spam reasons explain the different HTML- and content-based security checks and the recommended steps to prevent legitimate emails from being marked as spam. email-content-html
Emails with FORM tag are potentially harmful
Emails containing a HTML <form> tag, which can be used to collect user input directly within an email. Since form tags may be exploited for phishing, credential data theft, or other malicious activities, Zoho Mail treats emails containing them as potentially harmful and classifies them as spam.
If you trust the sender and believe the email is legitimate, contact your organization administrator to review the HTML<FORM> tag-based spam policy. Organization administrators can modify this setting by navigating to Security & Compliance > Phishing & Malware > Malware Processing and disabling the appropriate option under HTML Tags-based Spam Check.
Emails with EMBED tag are potentially harmful
Embedded content was detected in this email through an HTML <embed> tag which is used to embed external or multimedia content within an email. As embedded content can be exploited to deliver malicious files, execute unsafe content, or bypass email security measures, Zoho Mail identifies the email as potentially harmful and marks it as spam.
If you trust the sender and believe the email is legitimate, contact your organization administrator to review the HTML<EMBED> tag-based spam policy. Organization administrators can modify this setting by navigating to Security & Compliance > Phishing & Malware > Malware Processing and disabling the appropriate option under HTML Tags-based Spam Check.
Emails with FRAME tag are potentially harmful
An HTML <frame> tag was detected in this email. Frame tags can be used to display external web content within an email, which may expose users to phishing attempts, malicious content, or other security risks. To protect users, Zoho Mail identifies such emails as potentially harmful and marks them as spam.
If the email is legitimate, contact your organization's administrator to review the applicable spam policy. Organization administrators can modify this setting by navigating to Security & Compliance > Phishing & Malware > Malware Processing and disabling the appropriate option under HTML Tags-based Spam Check.
Emails with OBJECT tag are potentially harmful
During the security scan, Zoho Mail detected an HTML <object> tag in the email. Object tags can be exploited to load untrusted content or introduce security vulnerabilities. To protect users from malicious or untrusted content, the email is flagged as potentially harmful and moved to the Spam folder.
If the email is from a trusted sender, contact your organization's administrator to review the applicable spam policy. If you are the sender, remove the HTML <object> tag or replace it with an email-safe alternative before sending the message again. This spam setting can be modified by the admin by by navigating to Security & Compliance > Phishing & Malware > Malware Processing and disabling the appropriate option under HTML Tags-based Spam Check.
This email is potentially harmful, as it contains executable JavaScript embedded
Embedded JavaScript was detected during the email security spam check. Since executable JavaScript can be used to perform unauthorized actions, deliver malicious code, or support phishing attacks, Zoho Mail identifies the email as potentially harmful and marks it as spam.
If you are the sender, remove the embedded JavaScript before sending the email. If you trust the email, contact your organization's administrator to review the spam settings by by navigating to Security & Compliance > Phishing & Malware > Malware Processing and disabling the appropriate option under Content based Spam Check.
The email contains tracking signatures that could harm your data
The email includes tracking signatures that may compromise your privacy or security. Tracking signatures can be used to monitor email opens, collect user information, or transmit data to external servers. To protect users from potentially unsafe tracking mechanisms, Zoho Mail marks the email as spam.
If you are the sender, remove unnecessary tracking signatures before sending the email again. If you trust the sender, contact your organization's administrator to review the applied spam policy by by navigating to Security & Compliance > Phishing & Malware > Malware Processing and disabling the appropriate option under Content based Spam Check.
Spam Detection Based on Filter Rules
In addition to validating the sender and inspecting email content, Zoho Mail evaluates incoming emails against predefined spam detection rules and custom spam filters. These rules analyze different parts of an email such as the subject, message content, sender information, email authentication results, and other message attributes to identify patterns commonly associated with spam, phishing, or unwanted emails. When an email matches one or more configured spam rules, it is classified as spam and delivered to the Spam folder. The following spam reasons explain the different spam filter matches and detection rules that may cause an email to be marked as spam.
The email subject matches custom spam filters set by your organization
Zoho Mail checks the subject line of every incoming email against the custom spam filters configured by your organization. If the subject matches a rule defined by your administrator, the email is identified as spam and delivered to the Spam folder. These filters are commonly used to block emails containing specific words, phrases, or subject formats that are associated with spam, phishing attempts, promotional campaigns, or other unwanted emails.
If you believe the email is legitimate, contact your organization administrator to review the custom spam filter rule. In the Zoho Mail Admin Console, go to Security & Compliance > Spam Control > Blocked Patterns > Subject Patterns, select the blocked subject pattern, and click Delete to remove it from the blocked list.
The email content matches custom spam filters set by your organization
If the email body matches a rule defined by your administrator, the email is classified as spam and delivered to the Spam folder. Zoho Mail scans the content of incoming emails against the custom spam filters configured by your organization. These filters can identify specific words, phrases, or content that are commonly associated with spam, phishing attempts, malicious campaigns, or other unwanted emails.
If you think the email is legitimate, contact your organization administrator to review the custom spam filter rule. In the Zoho Mail Admin Console, go to Security & Compliance > Spam Control > Blocked Patterns > Content Patterns, select the blocked content pattern or phrase, and click Delete to remove it from the blocked list.
Email content matches the prevalent spam patterns
Zoho Mail classified this email as spam based on its built-in spam detection checks. During spam analysis, the email is evaluated using multiple signals, such as sender reputation, email content, sending patterns, rate limits, email authentication results, previous spam classification history, and other spam detection indicators. If the email matches one or more known spam patterns, it is automatically delivered to the Spam folder. If you believe the email is legitimate, Mark it as Not Spam.
Marked as Spam via Filter conditions
Email is moved to the Spam folder because it matched one or more mail filter conditions configured in Zoho Mail Settings. These filters can automatically perform actions on incoming emails based on criteria such as the sender, recipient, subject, email content, attachments, or other message attributes. If the configured action is Mark as Spam, the email is classified as spam instead of being delivered to your inbox.
If the email was marked as spam unintentionally, review the filter conditions in your mail settings. Updating or removing the filter rule will prevent similar emails from being marked as spam in the future. To do so, follow the steps mentioned below:
- Navigate to Zoho Mail Settings and navigate to Filters
- Select the filter that is configured to Mark as Spam or Move to folder: Spam.
- Under the Actions section, review the configured spam action.
- Remove or modify the Move to folder → Spam action, then save the changes.
Email does not pass the conditions set by your organization's spam filters
Your organization's spam policy identified this email as matching one or more configured spam filter conditions. Organization-level spam filters evaluate incoming emails against predefined rules based on criteria such as the sender, recipient, subject, email content, attachments, email authentication, and other message attributes. If an email matches a configured spam rule, Zoho Mail classifies it as spam and delivers it to the Spam folder.
To prevent legitimate emails from being marked as spam, ask your organization administrator to review the applied spam filter rule. In the Zoho Mail Admin Console, go to Mail Settings > Rules > Incoming Rules, edit the applicable rule to update its conditions or actions, or click Delete to remove it.
Bulk & Campaign Email Detection
Zoho Mail identifies emails sent as bulk or campaign messages by analyzing factors such as email headers, sending patterns, recipient count, message content, and campaign characteristics.
Based on your personal spam settings or your organization's spam policy, emails identified as bulk or campaign messages may be classified as spam and delivered to the Spam folder.
This is a bulk/ campaign email
Zoho Mail identified this message as a bulk or campaign email based on its content, headers, sending patterns, and other email characteristics. Bulk emails are typically sent to a many recipients for purposes such as marketing, newsletters, announcements, or promotional campaigns. Depending on your organization's spam policy or personal spam settings, these emails may be classified as spam and delivered to the Spam folder.
If you trust the sender and want to continue receiving similar emails, add the sender or domain to your Allowlist or update your spam settings. If the email is sent by your organization, contact your administrator to review the applicable spam policy or bulk email filtering rules.
Repeated User Performed Actions
Your spam management actions influence how Zoho Mail classifies future emails. Actions such as marking an email as Spam or Not Spam help the system recognize your email preferences and automatically apply similar decisions to future emails with matching characteristics. The following spam reasons are triggered based on your previous actions and explain how user-defined spam behavior influences email classification.
You marked similar emails as Spam earlier
Based on your previous spam reporting actions, Zoho Mail automatically classifies emails with similar characteristics as spam. The classification is based on factors such as the sender, sender domain, email content, subject, and other message attributes that closely match emails you have previously marked as Spam.
This personalized spam filtering helps reduce unwanted emails while improving the accuracy of future spam detection based on your preferences. If the email is legitimate, move it to your Inbox or Mark it as Not Spam. This updates your personal spam filtering preferences and helps Zoho Mail distinguish legitimate emails from spam.
Troubleshooting Spam Issues
| Who can fix it? | Issue Type | Recommended Action |
| User | The email was marked as spam because of your personal spam settings, such as your Blocklist, Allowlist, language filter, mail filters, or because you previously marked similar emails as spam. | Review your spam settings, remove trusted senders or domains from your Blocklist, add them to your Allowlist, update your mail filters, or mark the email as Not Spam. |
| Organization Admin | The email was blocked due to your organization's spam policies, such as organization or group Blocklists, blocked countries, languages, TLDs, custom spam rules, or security policies. | Review and update the organization's spam policies, Blocklists, Allowlists, filtering rules, or security settings to allow legitimate emails. |
| Sender | The email contains issues such as missing sender information, display name spoofing, unsupported HTML tags, embedded JavaScript, tracking signatures, or email authentication problems. | Correct the email by using valid sender information, fixing authentication issues, and removing unsupported or potentially harmful content before sending it again. |
| System | The email matches built-in spam detection rules or known spam patterns. | No manual action is usually required. If the email is legitimate, mark it as Not Spam so future similar emails are less likely to be classified as spam. |
FAQs
Why are my emails going to Spam in Zoho Mail?
Your emails might be going to Spam or marked as Spam because it matched one or more spam detection checks, such as your personal spam settings, your organization's spam policies, email authentication failures, unsafe email content, or Zoho Mail's built-in spam detection rules. The spam reason displayed at the top of the email explains the exact cause.
How do I find out why an email was marked as spam?
To check why an email was marked as spam, open the email from the Spam folder. A spam alert appears at the top of the email, showing the specific spam reason that caused the email to be classified as spam.
How do I stop legitimate emails from going to spam in Zoho Mail?
The solution depends on the spam reason displayed. You may need to update your personal spam settings, ask your organization administrator to review spam policies, or request the sender to correct email authentication or email content issues. Refer the above mentioned category wise spam reason check to resolve.
Why is a sender blocked even though the email is genuine?
A genuine email may be blocked if the sender's email address or domain is present in your personal Blocklist, your organization's Blocklist, or a group's Blocklist. Review the spam reason displayed in the email to identify which Blocklist caused the email to be classified as spam. If the sender is trusted, remove them from the Blocklist or add them to the Allowlist.
Why are HTML emails marked as spam?
HTML emails may be marked as spam if they contain potentially unsafe elements such as FORM, EMBED, FRAME, OBJECT tags, embedded JavaScript, or tracking signatures (Web Bugs). These elements can be exploited for phishing or malicious activities, so Zoho Mail treats them as potential security risks.
What should administrators check when multiple users receive genuine emails in spam?
Administrators should review organization-wide spam settings, including Blocklists, Allowlists, spam filter rules, blocked countries, languages, TLD restrictions, subject and content patterns, and HTML security policies. If necessary, update these settings to prevent legitimate emails from being classified as spam.
What should administrators check when multiple users receive genuine emails in spam?
Administrators should review organization-wide spam settings, including Blocklists, Allowlists, spam filter rules, blocked countries, languages, TLD restrictions, subject and content patterns, and HTML security policies. If necessary, update these settings to prevent legitimate emails from being classified as spam.
Why does Zoho Mail mark an email as display name spoofing?
Zoho Mail marks an email as display name spoofing when the sender's display name resembles that of a trusted person or organization, but the actual sender address does not match. This helps protect users from phishing and email impersonation attacks. Always verify the sender's email address before interacting with the message.