Spam Filters Stopped Reading Your Words

Over half of spam is now AI-generated, so filters quit analyzing content and started watching behavior. Why your engagement signals, not your copy, decide the inbox in 2026.

Cover Image for Spam Filters Stopped Reading Your Words

Here is a workflow that used to make sense and no longer does. You write a campaign, run it through a spam-word checker, see it flag "free" and "act now," swap them for softer phrasing, watch the spam score drop into the green, and hit send — confident you have done the thing that gets you into the inbox. In 2026, that workflow is theater. The filter on the other end is not reading your words. It stopped, on purpose, because reading words quit working.

The reason is simple and a little grim. Over half of all spam is now AI-generated. The classic tells filters were trained on — broken grammar, generic greetings, the literal word "FREE" in all caps — are gone, because the spammers have the same language models you do. AI-written spam has clean grammar, personalized openings, and can imitate the tone of a familiar sender or blend into an existing thread. When the bad mail reads as well as the good mail, content analysis is a coin flip. So the mailbox providers did the only rational thing: they shifted the decision away from what you wrote and toward how people behave when you send it.

The filter moved from the message to the pattern

This did not happen overnight, but it crossed a threshold this year. Two changes tell the story.

The first is that providers got much better at the content analysis they still do — specifically to neutralize the adversarial tricks AI made cheap. Gmail's RETVec (Resilient and Efficient Text Vectorizer) reads text the way a human eye does, as visual patterns rather than character strings, so "F-R-E-E" or "Frее" with a Cyrillic e still resolves to "free." Google reports RETVec improved spam detection by 38% while cutting false positives by 19.4%. Alongside it, Gmail runs TensorFlow models trained on enormous message volumes and Gemini Nano for on-device detection of novel scams. The content layer got smarter — but its main job now is catching evasion, not judging legitimacy.

The second change is the one that should reorganize your strategy: legitimacy is now decided behaviorally. Gmail's filtering watches whether recipients open your mail, how long they spend reading it, whether they click, reply, or forward, and how they shuffle messages between tabs. It watches your complaint rate against a hard ceiling — the 0.3% threshold that bulk senders cannot cross without consequences. And it watches the inverse signal, which is the brutal one: if a large share of your recipients delete your message without opening it, that pattern alone tells Gmail your mail is unwanted, and your next send is more likely to land in spam. One analysis puts the trigger around 60% immediate-delete behavior. Your copy never enters the calculation.

The old content-based filter looked atThe new behavioral filter looks at
Spam trigger words ("free," "act now")Open rate and reading dwell time
Punctuation and ALL CAPSClick, reply, and forward rates
Generic greetings and grammarDelete-without-opening rate
Suspicious link patternsComplaint rate against the 0.3% ceiling
Keyword densityHow recipients sort and move your mail
Image-to-text ratioWhether new recipients engage early

The columns are not equivalent. The left column is about the message and is mostly automatable — you can write to pass it. The right column is about the relationship and cannot be faked, because it is generated by other people's behavior, not by you. That is the entire point. The filter moved to signals you cannot author.

Why this quietly kills cold email

Follow the logic to its conclusion and you arrive at an uncomfortable place for anyone whose growth plan is "send more email to more people."

A cold list — scraped, bought, or harvested from a form people forgot they filled out — generates exactly the behavioral signature the new filters punish. Recipients who did not ask to hear from you do not open, do not click, do not reply, and a meaningful fraction mark you as spam or delete on sight. Each of those is a negative signal. Send to a cold list and you are not just getting low conversion; you are actively teaching the provider that your domain sends unwanted mail, which degrades deliverability for the engaged recipients you do have. Reply.io's 2026 guidance on avoiding AI spam filters is mostly a list of ways to look engaged — warm up slowly, segment hard, suppress non-openers — which is a tacit admission that the content of the email barely matters anymore. Behavior is the product.

This is the real reason "just write better subject lines" stopped moving the needle. A better subject line might lift opens a point or two among people who already like you. It does nothing for a list that fundamentally does not want your mail, because the filter is measuring the wantedness directly. You cannot copywrite your way out of a bad audience.

So the strategic question shifts. It is no longer "how do I write email that gets past the filter?" It is "how do I build an audience whose behavior tells the filter my mail is wanted?"

Reputation is now earned upstream

The answer is that deliverability has become a downstream symptom of how you acquire contacts in the first place. An engaged list is not a thing you achieve by cleaning a bad one; it is a thing you build by only ever adding people who genuinely want to hear from you. Which means the highest-leverage deliverability work does not happen in your email tool at all. It happens at the moment of capture.

Compare two ways the same business adds a thousand contacts.

The first buys or scrapes them. Day one, the list is a thousand strangers. The first send produces low opens, near-zero replies, and a spike of complaints and deletes. The provider takes note. Deliverability drops, and now even the few interested people stop seeing the mail. The list got worse by being used.

The second earns them through genuine interest — a visitor who asked a real question on the website, got a useful answer, and opted in because they wanted the follow-up. Day one, the list is a thousand people who recently had a positive, specific interaction with the brand. The first send produces strong opens, real replies, and almost no complaints. The provider takes note of that, and deliverability improves. The list got better by being used.

Same size, opposite trajectory, and the difference is entirely upstream of the email. The behavioral filter is, in effect, auditing your acquisition strategy after the fact.

Engagement starts before the email exists

This is where a conversational capture surface earns its place in the deliverability conversation, which is not where most people expect to find it. A visitor who opens a chat on your site, asks "do you integrate with Shopify?", gets a clear yes and a how, and then accepts an offer to "send the setup guide to your email" is a fundamentally different contact than a row in a purchased CSV. They have a reason to open your next message, because the last interaction was useful and they initiated it. When that email arrives and they open it, click it, maybe reply — those are the exact positive signals the 2026 filter rewards.

On the Agentkit side, that is what conversational lead capture produces: contacts attached to a real question and a real answer, captured at the moment of genuine interest rather than extracted from a list. It is available on every plan, including the free tier, because the value is not the volume of contacts — it is their behavioral quality once they hit your email program. A smaller list of people who wanted to be there outperforms a large list of strangers on every signal the filter now measures, and it does so without any clever copywriting.

The deeper point is that the old funnel had email at the top — blast a wide audience, hope a few engage. The 2026 funnel inverts it. Engagement comes first, on a channel where the interaction is real and immediate, and email becomes the follow-up to a relationship that already exists. You are not trying to manufacture engagement signals after the send. You are only ever emailing people who already generated them.

What to do about it

The behavioral shift turns into a concrete to-do list, and almost none of it is about copy.

Stop optimizing for the content filter. Spam-word checkers measure a thing the provider has largely stopped weighting. Keep your emails clean and authenticated, then stop tuning words and start tuning audience. The authentication baseline is still mandatory — SPF, DKIM, DMARC are the gate before any of this — but past that gate, behavior is the game.

Prune ruthlessly, by engagement. Suppress recipients who have not opened in 90 days. They are not harmless dead weight; they are an active source of negative signals. Sending to them to "stay top of mind" is teaching the filter your mail is ignored. Cutting them lifts the behavioral average of every send that follows.

Acquire for intent, not volume. Shift acquisition budget from list-building toward genuine opt-ins captured at moments of real interest — a conversation, a useful resource, a request the person actually made. The contacts cost more per name and are worth multiples more per name, because they generate the signals that protect your whole domain.

Measure replies and deletes, not just opens. Opens are now noisy — AI inboxes and privacy proxies auto-open mail, inflating the number. Replies and immediate-deletes are far better proxies for whether the filter thinks you are wanted. Track them, and treat a rising delete rate as the early warning it is.

The shift underneath the shift

It is tempting to read all this as one more deliverability tweak — a new filter to reverse-engineer, like every Gmail change before it. It is not. The filter stopped reading your words because words stopped being trustworthy, and it started reading behavior because behavior cannot be faked by a language model. That moves the whole problem out of the copywriter's hands and into the question of who is on your list and why they are there.

The senders who thrive in this environment are not the ones with the cleverest subject lines or the cleanest spam scores. They are the ones who only email people who genuinely want to hear from them — and who build that audience by having real interactions first, on a channel where engagement is immediate and earned, then following up by email to a relationship that already exists. The filter rewards wantedness. The most reliable way to look wanted is to actually be wanted, which is a strategy you execute long before you open your email tool.

Build your chatbot for free →

No credit card required.

Gratis aan de slagGeen creditcard nodig