Email Health Score Explained: What 80 and 50 Really Mean

Your domain has a health score and you have no idea what the number means. Here is exactly what moves it, and what to fix first.

You log into a dashboard, see a number next to your domain, and have no idea whether 68 is fine or an emergency. Meanwhile mail keeps leaving your server — some of it landing in inboxes, some of it quietly dropping into spam folders or bouncing outright — and nobody notices until a customer says "I never got your invoice." By then the problem has usually been building for days.

An email health score is a single 0-100 number that summarizes whether a sending domain's blacklist status and authentication records are in good shape, so you can tell at a glance whether mail is landing or leaking. It exists because checking Spamhaus, SPF, DKIM, and DMARC separately every morning is not something anyone actually does by hand for more than a week.

What Is an Email Health Score?

It is a composite indicator, not a single test result. Rather than showing you four separate pass/fail checks — blacklist status, SPF, DKIM, DMARC — a health score rolls them into one weighted number so a non-technical person can see "this domain is fine" or "this domain needs attention" without reading a DNS record.

The score updates every time your domain is checked, so it moves in both directions: a fixed SPF record raises it, a new blacklist listing drops it immediately.

How Is the Score Calculated?

The number is a weighted composite, not an average. Blacklist cleanliness carries the most weight because a listing blocks mail outright, while authentication and trend are leading indicators of problems still forming.

ComponentWeightWhat it measures
Blacklist cleanliness50%Whether your sending IP appears on DNSBLs such as Spamhaus ZEN, Barracuda, SORBS, or SpamCop
Authentication records30%Whether SPF, DKIM, and DMARC are published, valid, and free of errors like a permerror or a missing policy tag
Trend20%Direction versus your last several checks — improving, flat, or degrading

That 50/30/20 split is why a domain with perfect SPF and DKIM can still score in the 40s the moment its IP lands on Spamhaus ZEN — one blacklist listing outweighs three clean authentication records.

What Do 80, 50, and Below Actually Mean?

The score sorts into three bands, and the gap between them is the difference between "keep an eye on it" and "mail is being rejected right now."

ScoreStatusWhat it usually means
80-100HealthyClean on every monitored blacklist, with valid SPF, DKIM, and DMARC
50-79Needs attentionA weak DMARC policy, a missing record, or a recent authentication error — mail is likely still delivering
Below 50UrgentAn active blacklist listing in most cases — some receiving servers are already rejecting or spam-filtering your mail

A score sitting at 62 for weeks is a different problem than one that fell from 91 to 40 overnight. The first is a configuration gap you can fix on your own schedule. The second is an active incident.

Why Does the Score Drop Without a New Blacklist Listing?

Because authentication records expire in ways that have nothing to do with spam complaints. A DKIM selector gets removed during an email platform migration. A marketing tool gets added to your sending stack but never added to the SPF record, so its mail starts failing alignment. DMARC reports show a growing share of unaligned mail even though nothing on your end visibly changed.

Trend is 20% of the score specifically to catch this — a domain that was clean last week and is failing DKIM this week scores lower than a domain that has been failing DKIM steadily for months, because a fresh break usually means something just changed in your sending setup.

Checking this by hand means re-running the same four blacklist lookups and three DNS record checks on a schedule and remembering to actually do it. EmailControl runs that exact check set — Spamhaus ZEN, Barracuda, SORBS, SpamCop, plus SPF, DKIM, and DMARC — on a fixed interval and recomputes the score automatically, so a break shows up in the trend component within one check cycle instead of whenever someone happens to look. See how the checks map to the score on the FAQ page.

How fast that break shows up depends on the check interval, and the interval is the one thing that scales with plan rather than with the scoring formula itself: a domain checked weekly can carry a stale score for up to six days before the trend component catches a new problem, a domain checked daily catches the same break within a day, and a domain checked hourly catches it within the hour. Agencies watching client domains tend to need the shorter interval more than a different scoring formula — see the plan comparison for how check frequency and domain limits scale together.

How Do You Raise a Low Score?

Work in the order the weighting implies: fix the blacklist listing first, then authentication, then let the trend component recover on its own over the next few checks.

  1. Confirm the blacklist listing. Reverse your mail server's IP and check it against Spamhaus, Barracuda, SORBS, and SpamCop directly, or read the listing detail your monitor already captured.
  2. Fix the root cause before requesting removal. A compromised mailbox, an open relay, or a stale mailing list with a high bounce rate will get you relisted within days if you skip this step.
  3. Submit delisting through the operator's own process, such as the Spamhaus Blocklist Removal Center, rather than a third-party removal service.
  4. Publish one clean SPF record ending in ~all or -all that lists every real sending source — a second SPF TXT record is a permanent error, not a stricter policy.
  5. Add or repair the DKIM selector your provider actually signs with; a valid record under the wrong selector name checks out as missing.
  6. Move DMARC from p=none toward p=quarantine once your DMARC reports show your legitimate mail aligning cleanly.
  7. Wait for the next check cycle. The blacklist and authentication components update immediately; the trend component needs two or three consecutive clean checks to fully recover.

What About Teams Already Checking DNS by Hand?

The honest objection is: "our IT person already looks at this occasionally." Occasionally is the problem, not the willingness. A blacklist listing can appear and start blocking mail within hours, and DMARC reports arrive daily whether or not anyone reads them. A quarterly manual review catches maybe four snapshots a year on a metric that can move in either direction overnight.

The setup cost is the other objection, and it is small here specifically because monitoring is read-only: EmailControl resolves your domain's MX record and reads public DNS the same way a receiving mail server does. It never touches your mail server, never needs credentials, and cannot make a DNS change on its own — you still control every record. Adding a domain takes about as long as typing it in, and the free tier covers one domain with weekly checks at no cost, so there is no billing decision required just to see the current score.

Check Your Domain's Score Now

If you do not know your current score, that is itself the answer to whether occasional manual checks are working. Start free monitoring and add your domain — the first check runs immediately, scores it against all four blacklists and your SPF, DKIM, and DMARC records, and emails you the moment any component changes.

Frequently asked questions

What is a good email health score?

80 to 100 is considered healthy, meaning your domain is clean across the monitored blacklists (Spamhaus ZEN, Barracuda, SORBS, SpamCop) and has valid SPF, DKIM, and DMARC records. A score in this range means mail is landing normally, though it is still worth checking the trend component for early signs of drift.

What does it mean if my email score is between 50 and 79?

It usually means an authentication gap rather than a blacklist listing — a missing DMARC policy tag, an expired DKIM selector, or an SPF record close to its DNS lookup limit. Mail is generally still delivering at this level, but the underlying issue tends to get worse, not better, if left alone.

Why did my score drop even though I didn't change anything?

The most common cause is a third-party service added to your sending stack without being added to your SPF record, or a DKIM selector that rotated or was removed during a platform migration. The trend component of the score is designed to catch exactly this kind of silent, unannounced change.

How often does an email health score update?

It updates every time your domain is checked, and the check frequency depends on plan: weekly on a free plan, daily on a paid mid-tier plan, or hourly on an agency-level plan. A blacklist or authentication change shows up in the score at the next scheduled check, not in real time between checks.

Can a low health score fix itself?

The blacklist and authentication components only improve once you fix the underlying DNS record or resolve the listing at the operator's removal process — nothing about the score recalculates that for you. The trend component then needs two or three consecutive clean checks before it fully reflects the fix.

Want to know the moment your domain lands on a blacklist? Start free monitoring — takes under a minute.