Decay University · Part 3: Reputation: the score you can't see
Lesson 19 of 64
B2B email deliverability: when the receiver is a business, not Gmail
Corporate gateways and Microsoft 365 quarantine judge B2B mail by admin policy, not engagement. Why selling to businesses is a different filtering game.
Last updated 19 July 2026
Selling to businesses changes who judges your email. The consumer machinery from the last three lessons decides placement from behaviour, meaning what thousands of individual readers do with your mail. Corporate email decides placement from policy: rules an administrator wrote for the whole company, enforced by a secure email gateway or by Microsoft 365's tenant settings before your recipient gets any say. The engagement signals you have been learning to earn barely exist in this world, and a message can vanish into a quarantine the recipient has never once looked at.
Two different worlds
The previous lesson ended with a one-paragraph warning about Microsoft 365 and its tenant-level rules. This lesson is that paragraph grown to full size, because if your customers are businesses, this is the receiving world you actually sell into.
A consumer mailbox belongs to its user. Gmail filters the mail, the user can overrule Gmail by digging into the spam folder and clicking "not spam", and the filter learns from it. A work mailbox belongs to the employer. The company picks the filtering posture, and the employee usually can't override it and often can't even see it. Between you and that mailbox there is frequently an extra machine entirely: a secure email gateway, a filtering service the company routes all inbound mail through before its mail system ever sees a message. Proofpoint, Mimecast and Barracuda are the vendors you'll run into most; Cisco, Fortinet and a dozen smaller players sell here too.
The routing is visible from the outside, and reading it is a practitioner habit worth building today. A company using a gateway points its MX records (the DNS records from the DNS lesson that name which servers receive a domain's mail) at the gateway instead of at Microsoft or Google. Look up a customer's MX records before the relationship matters and you'll often find the vendor's name sitting right in the hostname. Thirty seconds of DNS tells you who will actually be judging your mail.
Policy outranks behaviour
Everything a gateway does flows from one fact: an administrator configures it for the whole organization at once. Allow-lists, block-lists, attachment rules, content policies, quarantine rules. When Gmail distrusts you, you inbox for some readers and folder for others, and the fraction moves with your reputation. When a gateway policy distrusts you, you are blocked or quarantined for every mailbox in the company, including the champion who loves your product and replies to everything you send. Her enthusiasm is not an input. Her admin's ruleset is.
This is why the per-user personalization from the previous lesson has so little purchase in B2B. There is still machine scoring inside these products, and Microsoft 365 runs a filtering stack with verdicts of its own, but the deciding layer sits above the individual. One rule, written once, outranks years of one recipient's goodwill.
The engagement data flowing back to you gets distorted as well. Gateways commonly fetch links and remote content to scan messages for threats before delivery, and that machine activity can fire the same tracking pixels your ESP counts as opens. B2B open rates therefore lie in the flattering direction: some of those "opens" are a security appliance doing its job. A strong open rate on a B2B list is weak evidence of anything.
The quarantine nobody reads
Microsoft 365 deserves its own section because so much of business email lives there. Alongside the junk folder, it has a separate holding pen called quarantine: a store outside the mailbox where the tenant's policies can send suspected spam, phishing, malware and other unwanted mail. Whether a suspicious message goes to the junk folder or to quarantine is the admin's choice in the tenant's anti-spam policies, not the recipient's.
The recipient may be told, or may not. Microsoft's quarantine notifications (the digest: a periodic email listing what got held, with review and release links) are only sent if the quarantine policy the admin applied has them turned on, and even then the cadence is every four hours, daily or weekly. Quarantined spam doesn't wait around either: the default anti-spam policy holds it for 15 days (policies can be set anywhere from 1 to 30), after which it is permanently deleted and unrecoverable. All of this is laid out in Microsoft's quarantine documentation, which is unusually readable and worth an hour of any B2B sender's life.
Put the pieces together and you get the signature B2B failure. Your message is accepted at the door, so your ESP reports it delivered. It's quarantined, so it's in neither the inbox nor the junk folder. The digest is off or unread, so the recipient never learns it exists. Two weeks later it deletes itself.
No bounce, no spam-folder copy, no trace, and eventually no evidence.
The human path
In consumer deliverability the road to the inbox runs through machines. In B2B it often runs through a person: the recipient's IT administrator, who can allow-list your sending domain in minutes and make every filtering question above moot for that one company. Two sentences to your contact ("could you ask IT to allow-list mail from ourdomain.com, and search quarantine for our last message?") outperform any amount of sender-side tuning, because they act directly on the layer that decides.
Your own side still has to be spotless, for an unromantic reason: gateways verify authentication too, and an admin asked to allow-list you will look your domain over before trusting it. Aligned SPF, DKIM and DMARC, a clean blocklist record and a consistent sending history are the credentials that keep that conversation short. For relationships that carry real revenue, ask for the allow-list when the relationship starts, not after something breaks.
What nobody outside can see
An honest limit, and it applies to every tool including ours: nobody outside a company can read its gateway policy or look inside its quarantine. Inbox Decay can verify what the gateway will examine about you, meaning the records, the alignment, the blocklist status and the compliance headers (the health check covers that side of the fence, free). What we cannot do, and what no vendor can do, is see that one customer's gateway rule quarantines your domain. From outside, a receiver-side block looks like silence, or at best a rejection bounce with the gateway's name in it. Anyone claiming to measure your "inbox placement" at corporate domains is guessing; the data to know it does not exist outside that tenant.
When their side changes and yours didn't
The decay mechanism in this lesson lives entirely on the receiver's side, which makes it the most disorienting one in the course so far. The pattern: a client's biggest customer switches gateway vendors, or a new admin tightens policy after a security review. The old gateway's history and allow-list entries don't carry over. Your invoices and proposals stop arriving at that one company, your dashboards say delivered, every other customer is fine, and nothing on your side changed, because the thing that changed was never on your side. The monitoring that catches this is the relationship itself: when replies from one important domain go quiet, treat the silence as a signal and re-run the human path, starting with their quarantine.
Back on your side of the fence, the machine that hands your mail to these gateways has a reputation of its own: shared vs dedicated IPs settles whose behaviour your sending address inherits.
Terms from this lesson
- secure email gateway - a filtering service a company routes all inbound mail through before its mail system sees it; the company's MX records point at the gateway.
- tenant - one organization's instance of a service like Microsoft 365, with its own admins and its own policies.
- quarantine (Microsoft 365) - a holding store outside the mailbox where tenant policies send suspected spam, phishing and malware; held mail expires and is permanently deleted.
- quarantine notification - the periodic digest email listing a user's quarantined messages, sent only if the applied quarantine policy enables it.
- allow-list - an admin-maintained list of senders whose mail bypasses some or all filtering for that organization.
- machine-generated opens - opens recorded when security software fetches links or images to scan a message, inflating B2B open metrics.
Check yourself
1. You're about to start emailing a new customer at a 500-person company. How do you find out who will actually filter that mail?
2. Your B2B list shows an unusually strong open rate. What does that prove about inbox placement?
3. A contact at a Microsoft 365 company says your message never arrived. No bounce came back and it isn't in their junk folder. Where else can it be, and what's the catch?
Scenario
You handle email for a payroll software company. Invoices and onboarding emails to one large manufacturing customer stopped drawing replies about three weeks ago. Your ESP shows every message delivered, there are no bounces, and every other customer responds normally. Your contact there swears she has received nothing.
What do you do first?