Our team recently completed a migration to Auth0 for customer identity. While the technical integration was straightforward, we are experiencing a critical deliverability issue: approximately 92% of our email verification emails are being routed to spam folders by major mailbox providers (Gmail, Outlook, Yahoo).
This is not a trivial cost issue. Each failed user activation represents a direct loss in potential LTV and increases our effective CAC. We've followed the standard documentation but with no significant improvement.
Our configuration and steps taken:
* **Domain Verification:** Our custom domain (`login.our-app.com`) is fully verified in the Auth0 dashboard. SPF and DKIM records show as valid.
* **From Address:** Using a no-reply style address from our primary corporate domain (`[email protected]`). We have experimented with a `welcome@` variant.
* **Content:** We have not modified the default templates, assuming they are optimized for deliverability.
* **Auth0 Tenant Region:** We are using the US region. Our user base is ~70% North America, 30% EMEA.
We analyzed the email headers from a sample that landed in spam. The key points are:
```
Authentication-Results: gmail.com;
dkim=pass [email protected] header.s=auth0 header.b=...;
spf=pass (google.com: domain of [email protected] designates 123.45.67.89 as permitted sender) [email protected];
dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=our-app.com
```
The SPF pass is for `auth0.com`, not our domain. This appears to be an alignment issue, even though DKIM and DMARC pass.
Has anyone successfully resolved this at scale? Specifically:
1. Is using a subdomain for the `From:` address (e.g., `[email protected]`) with dedicated DNS records the definitive solution?
2. Are there specific DMARC policy recommendations (p=none vs p=quarantine) during the warm-up phase with Auth0's shared IP pools?
3. Did you need to engage Auth0 support to request placement on specific sending IPs?
We are prepared to implement a dedicated email provider for these transactions if necessary, but we'd prefer to leverage the paid Auth0 service we are already budgeting for. Concrete data on resolution steps and subsequent inbox placement rates would be invaluable.
Right-size or die
That `no-reply@` address is a red flag for spam filters, even with perfect SPF/DKIM. Providers see low engagement on those and it hurts your reputation.
You need to share the headers after `Authentication-Result`. Look for `spf`, `dkim`, and the critical `dmarc` result. If DMARC is missing or failing, that's your issue right there.
Also, check your sending domain's reputation. Tools like Talos or Google Postmaster can show if your IP or domain is already flagged.
terraform and chill
> Our custom domain (`login.our-app.com`) is fully verified in the Auth0 dashboard.
That's your problem. You verified a subdomain (`login`), but you're sending from your root domain (`our-app.com`). The DKIM/SPF setup for `login.our-app.com` does nothing for `[email protected]`.
Auth0 likely signs with the verified subdomain, creating an alignment mismatch. Check the header for the actual `d=` domain in the DKIM signature. It won't match your From domain. That fails DMARC.
You need to verify and send from the same domain, or set up a separate DNS configuration for your root domain.
Least privilege is not a suggestion.